Secure Email Processing with Real-Time Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing email security systems, such as PGP and S/MIME, are vulnerable to impersonation and forgery attacks due to the potential use of forged public keys and certificates, which can lead to unauthorized access and data falsification.

Innovation Solution

A system and method for secure message processing that involves a wireless communication environment where messages are encrypted and authenticated using a combination of S/MIME or PGP security schemes, with additional verification steps involving Certificate Authorities and real-time certificate verification using LDAP and OCSP protocols to ensure the authenticity of public keys and certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time certificate verification using LDAP and OCSP protocols is implemented, then security against impersonation and forgery attacks is improved, but system complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary certificate verification by checking certificates against Certificate Revocation Lists (CRLs) before message processing. This preliminary action ensures that revoked certificates are identified and blocked in advance, preventing impersonation and forgery attacks without requiring complex real-time verification for every message.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces Certificate Authorities (CAs) as intermediary entities that issue and manage digital certificates. These CAs serve as trusted third parties that verify identities and issue certificates, simplifying the verification process for end users while maintaining high security standards through centralized certificate management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time certificate verification is performed for every message, then authentication reliability is improved, but message processing speed decreases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidmessage processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary certificate verification by checking certificates against Certificate Revocation Lists (CRLs) before message processing. This preliminary action ensures that revoked certificates are identified and blocked in advance, preventing impersonation and forgery attacks without requiring complex real-time verification for every message.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements selective verification where full certificate validation is performed only when necessary (e.g., for new certificates or suspicious messages), while routine messages use simplified verification methods. This partial action approach maintains authentication reliability for critical cases while preserving message processing speed for常规 communications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8607334B2System and method for secure message processing
Publication Date: 2013.12.10 MALIKIE INNOVATIONS LTD
  • US8607334B2 patent drawing
  • US8607334B2 patent drawing
  • US8607334B2 patent drawing

AI summary

Systems and methods for secure e-mail message processing. A device is configured to receive a secure electronic message. The message may then be processed to determine whether the sender's address provided in the message is indicative of the sender's address provided in a sender's security-related certificate. A message's recipient can be notified based upon the determination.