Trust Broker for B2B Secure Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional business-to-business secure mail systems require cumbersome key distributions and explicit configurations for each organization, leading to inefficient scalability as companies need to manage separate security mechanisms for hundreds of organizations.

Innovation Solution

Organizations federate with a trust broker once to request tokens for decrypting messages protected by other federated organizations, using a trust broker to manage encryption and decryption processes, allowing for secure communication without individual key configurations for each partner.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional key distribution and explicit configurations are used for each organization, then secure communication is achieved, but device complexity and management overhead increase significantly

Engineering Contradiction:
Improvesecure communicationVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trust broker as an intermediary component that mediates between organizations seeking secure communication. The trust broker generates and manages encryption keys, creating encrypted communication channels without requiring direct key exchange between participating organizations. This intermediary approach maintains security while eliminating the complexity of manual key distribution and configuration management for each organization pair.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate security mechanisms are set up for each organization, then secure communication is established, but scalability deteriorates as the number of organizations increases

Engineering Contradiction:
Improvesecure communicationVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The trust broker is designed as a universal system that serves multiple organizations simultaneously. A single trust broker instance can generate and manage encryption keys for numerous organization pairs, providing secure communication capabilities across the entire network rather than requiring dedicated security mechanisms for each individual organization pair. This universal approach enables linear scaling rather than exponential growth in complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If individual key pairs are configured for each organization pair, then secure messaging is achieved, but time and resources required for key management increase

Engineering Contradiction:
Improvesecure messagingVSAvoidkey distribution time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The trust broker performs preliminary key generation and distribution actions before actual communication occurs. When organizations register with the trust broker, encryption key pairs are generated in advance and stored securely. When communication is needed, the pre-generated keys are quickly retrieved and used, eliminating the time-consuming process of real-time key exchange and configuration that would otherwise be required for each messaging pair.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8447976B2Business to business secure mail
Publication Date: 2013.05.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8447976B2 patent drawing
  • US8447976B2 patent drawing
  • US8447976B2 patent drawing

AI summary

Business to business secure mail may be provided. Consistent with embodiments of the invention, a protected message may be received. The recipient may request a token from a trust broker, submit the token to an authorization server associated with the sender, receive a user license from the authorization server; and decrypt the protected message using the user license. The protected message may restrict actions that may be taken by the recipient, such as forwarding to other users.