Rich Content Scanning for Non-Service Email Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Email systems do not allow non-registered users to send messages on behalf of registered users, leading to security risks as replies or forwards from open relay servers may not undergo anti-spam, anti-malware scanning, or encryption, compromising the sender's mailbox and making registered users' accounts susceptible to malware and spam.

Innovation Solution

Embedding information associated with the original registered sender in the email message, allowing the email system to verify the sender's registration status upon reply or forward, providing rich scanning and encryption only if the original message was sent by a registered user, and denying requests from non-registered users if the sender is not registered.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If open relay servers are used to allow non-registered users to send emails, then email communication accessibility is improved, but security scanning and filtering capabilities deteriorate

Engineering Contradiction:
Improveemail communication accessibilityVSAvoidsecurity scanning capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism that checks whether the original message was sent by a registered user. This intermediary layer allows the system to selectively apply rich scanning to replies from non-registered users, mediating between the need for accessibility and security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different scanning qualities to different message sources. Replies from registered users receive full rich scanning, while replies from non-registered users receive scanning only if the original message was from a registered user. This local differentiation resolves the contradiction by applying security measures selectively rather than universally

Inventive Principle:
Principle #3Local quality

2Reliability

If rich scanning is applied to all messages from non-registered users, then security is improved, but system complexity increases

Engineering Contradiction:
Improvemailbox securityVSAvoidscanning system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary verification to determine if the original message was sent by a registered user before applying rich scanning to replies. This preliminary action avoids unnecessary scanning of messages that don't require it, maintaining security while reducing system complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies rich scanning selectively rather than universally. Only replies to messages from registered users sent via the email system undergo rich scanning, while other messages use standard scanning. This partial application of the scanning mechanism achieves adequate security without the full complexity burden

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3100417B1Rich content scanning for non-service accounts for email delivery
Publication Date: 2020.08.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3100417B1 patent drawingFigure 1
  • EP3100417B1 patent drawingFigure 2
  • EP3100417B1 patent drawingFigure 3A

AI summary

Various embodiments are generally directed to techniques and apparatuses to facilitate message communication between registered entities of an email system and other non-registered entities. In one embodiment, a transport component executes on a logic circuit to receive a request to perform a function on an encrypted message. Information embedded in the request is identified to determine if the original request was sent by a registered entity. The embedded information is authenticated with information contained in an authentication information store associated with the original request and if the information is authenticated, the requested function is executed. In addition, if the requested function by the non-registered entity is to send an email message, rich scanning is performed on the email message to ensure the safety thereof.