Perimeter Email Filtering via Hashed User Preferences
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Perimeter networks in large networks face increased vulnerability to attacks and inefficiencies in content filtering, leading to exposure of sensitive information and false positives in email routing, necessitating enhanced security and user-specific filtering mechanisms.
Innovation Solution
Implementing a system that extracts user-specific messaging preferences from the trusted network, hashes them for secure transmission, and uses these preferences to control content filtering at the perimeter network, allowing secure communication and filtering without exposing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user-specific messaging preferences are extracted and stored on the perimeter network, then content filtering effectiveness is improved, but security risk increases due to exposure of sensitive information
Solution Approach 1:
The patent extracts only the necessary messaging preferences (sender addresses, domains, contact information) from the trusted network and stores them on the perimeter network servers. This selective extraction allows the content filtering application to access user-specific preferences without exposing the entire directory service database, thereby improving filtering effectiveness while limiting security risk to only the essential data elements needed for filtering operations.
Solution Approach 2:
The patent introduces a content filtering application as an intermediary layer between the trusted network and the perimeter network. This application retrieves messaging preferences from the trusted network, processes them, and applies them for filtering incoming messages. The intermediary architecture allows preferences to be used for filtering without directly exposing the trusted network's directory service to the perimeter network, thus maintaining security while enabling effective content filtering.
2Productivity
If global content filtering is relaxed to reduce false positives, then desirable e-mail delivery is improved, but the number of undesirable e-mails increases
Solution Approach 1:
The patent implements user-specific messaging preferences that allow different filtering rules for different users and senders. Instead of applying a single global filtering policy, the system can identify messages from trusted senders (listed in user preferences) and allow them through without strict filtering, while maintaining aggressive filtering for unknown senders. This local customization of filtering quality reduces false positives for desirable emails while maintaining protection against undesirable emails.
Solution Approach 2:
The patent pre-populates the content filtering application with user messaging preferences (safe sender lists, contact information, approved domains) before filtering operations begin. These preferences are extracted from the trusted network and stored on the perimeter network in advance. When messages arrive, the filtering application can immediately compare them against the pre-loaded preferences, allowing rapid identification of trusted messages without needing to relax global filtering settings, thus reducing false positives while maintaining security.
Data Source
AI summary
Propagating messaging preferences of one or more users from a recipient mailbox to a perimeter network administering e-mail content blocking and routing. A content filtering application located outside a trusted network receives messaging preferences information from within the trusted network regarding the mail recipients. This messaging preferences information may be utilized to allow certain pre-authorized messages from particular senders to bypass content filtering. Moreover, the messaging preferences information may be hashed to further protect the information on the perimeter network and to speed in review and comparison of the messaging preferences information. In addition, other types of user-specific information may be propagated to the perimeter network for use with other applications other than messaging.


