Secure Email Messaging via Content Segmentation and Remote Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for secure email transmission are complex and costly due to the need for Public Key Infrastructure (PKI), require additional software and encryption knowledge, and are hindered by content checking gateways that decrypt messages, making them impractical for widespread adoption.

Innovation Solution

A method and system that splits an email message into a residue and a secure portion, where the secure portion is stored externally and accessed using an authentication code, allowing the message to traverse content checking gateways without additional software or manual tasks, using standard email and communication means like SMS or web browsers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If S/MIME compliant email software and public key infrastructure are used for secure email transmission, then security is improved, but device complexity and ease of operation deteriorate due to additional software requirements and complex encryption knowledge

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic operations and secure storage functions from the end-user device and relocates them to a remote server. The client device only handles message composition and submission, while the server performs encryption, key management, and secure storage, eliminating the need for complex local software and cryptographic knowledge.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote server as an intermediary between the sender and recipient. This server acts as a trusted third party that manages the cryptographic infrastructure, including generating key pairs, encrypting messages, and securely storing encrypted content, thereby simplifying the client devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If public key infrastructure is implemented for secure email, then security is improved, but ease of operation worsens due to the need for certificate enrollment and trust establishment

Engineering Contradiction:
ImprovesecurityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements automatic key pair generation and certificate management on the remote server without requiring user intervention for enrollment. The system automatically provisions cryptographic credentials and manages trust relationships, eliminating manual certificate enrollment processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The remote server performs all cryptographic setup, key generation, and trust establishment actions in advance before any message transmission occurs. This preliminary configuration eliminates the need for real-time certificate enrollment and trust verification during message exchange.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If message content is encrypted for security, then security is improved, but ease of operation worsens due to gateway decryption requirements and content checking

Engineering Contradiction:
ImprovesecurityVSAvoidmessage delivery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the email system into distinct functional components: the message transport layer that handles unencrypted transmission through gateways, and the secure access layer that handles encrypted content retrieval. This segmentation allows unencrypted headers and routing information to pass through gateways while the encrypted body remains protected.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the encrypted message content from the standard email transmission path and relocates it to a separate secure storage system. The email gateway only processes unencrypted metadata and routing information, while the encrypted payload is accessed separately through authenticated retrieval, bypassing gateway decryption requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If recipient authentication is implemented via pre-agreed passwords, then security is improved, but productivity deteriorates due to manual tasks required for each recipient

Engineering Contradiction:
ImprovesecurityVSAvoidmessage scaling
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The remote server automatically performs recipient authentication and authorization without requiring manual password management by the sender. The system self-manages credential verification and access control, enabling automated secure message delivery to multiple recipients simultaneously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The remote server provides universal authentication and encryption services that work with all recipients through a single integrated system. This multi-functional platform handles key generation, message encryption, secure storage, and authentication for unlimited recipients, eliminating the need for individual manual setup for each recipient.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8166299B2Secure messaging
Publication Date: 2012.04.24 SECURENVOY
  • US8166299B2 patent drawing
  • US8166299B2 patent drawing
  • US8166299B2 patent drawing

AI summary

A messaging method and system sends secure emails (14) by the email originator (10) removing the portion of the email (14) which is confidential (24) from the body of the email (14). The removed portion (24) is sent to a secure storage site (30). The residue (20) of the email (14) is sent to the intended recipient (12), together with a notification (22) that the confidential portion (24) is at the secure site (30). Secure storage site 30 then sends a SMS text message (38) to the recipient's mobile phone (44) which has an authentication code (38) which the recipient (12) uses to establish identity and retrieve the confidential portion (24) of the email message (14) from the secure store (30). The secure store (30) emails the originator with notification (60) when the recipient (12) retrieves the secure portion (24) of the email message (14).