Trusted Communication Network via Outbound Email Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current email filtering technologies are ineffective in authenticating email senders, leading to issues with spam, phishing, and network pollution, causing damage to enterprise reputation and productivity losses due to false positives, denial-of-service attacks, and insecure email transmission.

Innovation Solution

A system that includes a processing node to authenticate and filter inbound and outbound messages, using trusted source indicia and reputation metrics to ensure only authorized messages are sent, and a hosted DNS server for authentication, along with a method to detect and quarantine threats, and manage bounce messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content filtering is used to identify harmful email messages, then network security is improved, but false positives increase and legitimate messages are filtered out

Engineering Contradiction:
Improvenetwork securityVSAvoidfiltering accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

Instead of filtering inbound email to identify threats, the system filters outbound email from each enterprise. This inversion changes the perspective from defensive filtering to proactive threat prevention, allowing enterprises to control what leaves their network while reducing false positives that occur when filtering incoming messages.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system segments email filtering responsibility by enterprise, with each enterprise filtering its own outbound email independently. This segmentation allows customized filtering policies for each organization and reduces the burden of centralized filtering, improving both security and accuracy.

Inventive Principle:
Principle #1Segmentation

2Reliability

If frequent firewall and software updates are implemented, then network protection is improved, but operational complexity and costs increase

Engineering Contradiction:
Improvenetwork protectionVSAvoidsystem management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary filtering of outbound email before it leaves the enterprise network. By preventing threats at the source, there is no need for continuous updates of inbound filtering mechanisms, reducing the frequency and complexity of maintenance while maintaining strong protection.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If spoofed email addresses are allowed, then email delivery flexibility is improved, but authentication reliability deteriorates

Engineering Contradiction:
Improveemail delivery flexibilityVSAvoidsender authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system introduces an intermediary authentication mechanism where outbound email is verified against a whitelist of authorized senders before leaving the enterprise network. This intermediary layer maintains delivery flexibility for legitimate emails while blocking spoofed addresses, solving the contradiction between flexibility and authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If aggressive spam filtering is applied, then network security is improved, but productivity decreases due to false positives

Engineering Contradiction:
Improvenetwork securityVSAvoidemail delivery efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By inverting the filtering direction to outbound email, the system achieves aggressive security measures without impacting inbound email productivity. Legitimate incoming emails are not subject to false positive filtering, while outbound threats are prevented at their source, maintaining both security and productivity.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS9160755B2Trusted communication network
Publication Date: 2015.10.13 GDX NETWORK
  • US9160755B2 patent drawing
  • US9160755B2 patent drawing
  • US9160755B2 patent drawing

AI summary

A system includes a processing node configured to send authorized inbound messages to registered enterprise networks. An authorized message is a message that includes trusted source indicia. Trusted source indicia indicates that the message was sent by one or more of the processing node or an authenticated message transfer node associated with one of the registered enterprise networks. The system may further include an administration node configured to maintain registration of a plurality of message transfer nodes associated with the enterprise networks. A method includes receiving outbound messages from an authenticated message transfer node of an enterprise network, screening the messages for threats to determine whether to send the messages to associated recipients, applying a first message identifier to each message, wherein the first message identifier can be used to track the message and, for each message, sending the message to the associated recipient if no threats are detected in the message.