Temporary Whitelist Entries for Email Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated whitelisting techniques in email systems often result in large, unmanageable lists with non-legitimate entries, as they simply add all sent parties to the whitelist, leading to unnecessary resource consumption and security processing.

Innovation Solution

A whitelist manager creates temporary entries based on initial legitimacy evidence, converting them to permanent only if sufficient evidence is gathered within a set period, thereby managing and refining whitelists dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If simple automated whitelisting mechanisms add all sent parties to the whitelist, then the whitelist population increases automatically, but the whitelist becomes large and unmanageable with non-legitimate entries

Engineering Contradiction:
Improveautomated whitelistingVSAvoidwhitelist management
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The whitelist is segmented into temporary entries and permanent entries. Temporary entries are automatically created for sent parties but expire after a set period unless converted to permanent through sufficient legitimate communication evidence. This segmentation allows automated population while maintaining manageability through expiration and conversion mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary whitelisting by creating temporary entries immediately when a user sends an email, before full legitimacy is established. This preliminary action enables quick automation while the subsequent monitoring period validates legitimacy, preventing premature permanent inclusion of non-legitimate parties.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If simple automated whitelisting mechanisms are applied at gateway or domain level, then automation coverage increases, but the complexity and difficulty of managing these whitelists worsens significantly

Engineering Contradiction:
Improvegateway-level automated whitelistingVSAvoidwhitelist management complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The whitelist management system becomes dynamic through automatic expiration of temporary entries and automated conversion to permanent entries based on monitored communication patterns. At gateway level, this dynamic behavior reduces manual management complexity while maintaining high automation coverage across multiple users and domains.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system monitors email traffic between users and recipients during the temporary entry period, using this feedback to determine whether to convert temporary entries to permanent ones. At gateway level, this feedback mechanism automatically refines whitelists across multiple users, reducing overall management complexity while maintaining security.

Inventive Principle:
Principle #23Feedback

3Reliability

If email security screening is applied to all incoming emails, then security checking is thorough, but time and computing resources are consumed unnecessarily for legitimate emails

Engineering Contradiction:
Improvesecurity checkingVSAvoidemail processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security assessment by creating temporary whitelist entries for sent parties, allowing their subsequent emails to bypass full security screening. This preliminary action reduces time and resource consumption for emails from parties the user has initiated contact with, while the temporary nature ensures security remains intact until legitimacy is confirmed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial security screening by exempting emails from temporary whitelist entries from full security processing. This partial action reduces unnecessary resource consumption for potentially legitimate emails while maintaining thorough security checking for non-whitelisted emails, achieving a balance between security and efficiency.

Inventive Principle:
Principle #16Partial or excessive action

4Extent of automation

If temporary whitelist entries are created for all sent parties, then automated whitelist population increases, but resource consumption increases due to tracking email traffic during the time period

Engineering Contradiction:
Improveautomatic whitelist populationVSAvoidcomputing resources for tracking
Core Design Contradiction:
Extent of automationVSUse of energy by moving object

Solution Approach 1:

The system performs partial tracking by monitoring only the email traffic relevant to determining legitimacy conversion during the temporary entry period. This partial monitoring approach enables automatic whitelist population while consuming fewer computing resources compared to comprehensive tracking of all email activities, achieving a balance between automation and resource efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8112485B1Time and threshold based whitelisting
Publication Date: 2012.02.07 GEN DIGITAL INC
  • US8112485B1 patent drawing
  • US8112485B1 patent drawing
  • US8112485B1 patent drawing

AI summary

In response to a user sending an electronic mail message to a recipient, a whitelist manager creates a temporary whitelist entry for the recipient on the user's whitelist. The temporary whitelist entry is set to expire after a set period of time. During the period of time that the temporary whitelist entry is in effect, electronic mail messages from the recipient are passed to the user without being subject to security screening. The whitelist manager keeps track of email traffic between the user and the recipient during this time period. If the nature of this email traffic is sufficient to establish that the recipient is legitimate, the whitelist manager converts the temporary entry to a permanent one. Otherwise, the whitelist manager disables the temporary entry, after which email from the recipient to the user is subject to normal security processing.