Tenant Security Verification for Inbound Email Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional database systems lack effective security measures to protect users and organizations from potential security threats in communications, particularly in on-demand database services where multiple tenants share resources, making it challenging to implement configurable and efficient security protocols.

Innovation Solution

Implementing security verification mechanisms that apply multiple security processes to incoming communications, such as SPF, Sender ID, DomainKeys, and DKIM protocols, to obtain return codes and determine whether to process or reject communications based on these results, allowing tenants to selectively apply security measures, especially for inbound emails.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security processes are applied to communications in on-demand database services, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security verification system is segmented into multiple independent security processes (SPF, Sender ID, DomainKeys, DKIM) that can be applied separately to communications. Each security protocol operates as an independent module that returns a pass/fail code, allowing the system to maintain high security reliability through comprehensive checking while managing complexity by organizing checks into discrete, manageable segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security verification mechanism is designed as a universal system that can handle multiple types of communications (emails, messages) and apply multiple security protocols through a single integrated interface. The system provides a unified security layer that works across different communication types and tenant configurations, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If configurable security measures are implemented for tenants, then security adaptability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity adaptabilityVSAvoidease of operation
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The security verification system operates autonomously by automatically applying multiple security protocols (SPF, Sender ID, DomainKeys, DKIM) to incoming communications without requiring manual configuration or intervention from tenants. The system self-manages the complex security checking processes, returns verification codes, and makes processing decisions based on predefined criteria, thereby providing high security adaptability while maintaining ease of operation through automation.

Inventive Principle:
Principle #25Self-service

3Reliability

If security verification is applied to all communications, then security coverage is improved, but processing time increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security verification system applies security checks selectively rather than uniformly to all communications. Based on the type of communication, tenant configuration, and risk assessment, the system may apply one or more security protocols (SPF, Sender ID, DomainKeys, DKIM) as needed. This partial action approach ensures comprehensive security coverage for high-risk communications while reducing processing time for low-risk messages that require minimal verification.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230262067A1Security verification of communications to tenants of a shared system
Publication Date: 2023.08.17 SALESFORCE INC
  • US20230262067A1 patent drawing
  • US20230262067A1 patent drawing
  • US20230262067A1 patent drawing

AI summary

In accordance with embodiments, there are provided mechanisms and methods for security verification of communications to tenants of an on-demand database service. These mechanisms and methods for security verification of communications to tenants of an on-demand database service can enable embodiments to allow tenants to selectively implement security measures with respect to inbound communications, etc. The ability of embodiments to provide such feature may allow tenants to efficiently and effectively implement security measures for in-bound emails.