Mobile Email Protection via Gateway Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices pose unique challenges for computer security due to limited computing resources and increased exposure to threats when synchronizing with corporate networks, making it difficult to deploy effective security measures and protect corporate data.

Innovation Solution

A mobile email protection system that parses network traffic, scans for protected and prohibited content using compliance templates, and enforces security policies to prevent unauthorized data transfer between mobile devices and messaging servers, employing a reverse-proxy configuration and integrating a DLP engine, antivirus, and encryption module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security agents are deployed on mobile devices to perform computer security functions, then security protection capability is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway server as an intermediary between mobile devices and the corporate network. The gateway server performs security scanning, filtering, and protocol translation functions that would otherwise require resource-intensive agents on mobile devices. This mediator handles the complex security operations centrally, allowing mobile devices to maintain simplicity while still achieving comprehensive security protection through the gateway's mediation layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If mobile devices are allowed to synchronize with corporate networks outside the corporate network perimeter, then employee mobility and productivity are improved, but exposure to security threats increases

Engineering Contradiction:
Improveemployee mobilityVSAvoidsecurity threat exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The gateway server serves as a secure intermediary that enables mobile devices to access corporate networks from external locations without directly exposing the corporate network to external threats. The gateway performs protocol translation and security filtering, allowing legitimate email synchronization while blocking malicious traffic, thus maintaining employee mobility while mitigating security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security scanning and filtering of email content before it reaches the corporate messaging server. By pre-scanning emails for prohibited content and protected information at the gateway layer, the system prevents potential security threats from entering the corporate network, enabling safe external access without compromising security.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If email synchronization is allowed between mobile devices and messaging servers, then data accessibility and productivity are improved, but risk of data loss and unauthorized transfer increases

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata loss risk
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The gateway server performs preliminary scanning of email content before synchronization occurs. It identifies protected content using compliance templates and prohibited content using security policies, and takes preventive actions (blocking, filtering, or alerting) before the email reaches the messaging server or mobile device. This preliminary security check enables data accessibility while preventing data loss and unauthorized transfers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the gateway server continuously monitors email synchronization traffic, scans for security issues, and dynamically adjusts filtering rules based on detected threats and compliance requirements. This feedback loop ensures that data accessibility is maintained while systematically preventing data loss through continuous security monitoring and adaptive response.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9049169B1Mobile email protection for private computer networks
Publication Date: 2015.06.02 TREND MICRO INC
  • US9049169B1 patent drawing
  • US9049169B1 patent drawing
  • US9049169B1 patent drawing

AI summary

Email synchronization between a mobile device and a messaging server may be performed through a mobile email protection system. The mobile email protection system may parse network traffic for the email synchronization to retrieve an email element of an email. The mobile email protection system may scan the email element for protected content indicated in preconfigured compliance templates. The mobile email protection system may also scan the email element for prohibited content to prevent the prohibited content from being received by the messaging server.