Tunnel Server Rewrites User Agent Strings for Device-Specific EWS Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing mobile devices lack device-specific control over access to e-mail servers, particularly for EWS-based servers that do not utilize unique request identifiers, limiting administrators' ability to grant or deny access based on device compliance and enrollment statuses.
Innovation Solution
A system that includes a management server and a tunnel server to provide device identification information, allowing for the customization of user agent strings and secure access through a VPN, enabling device-specific access to EWS-based e-mail servers by rewriting default user agent strings with custom ones, which can be managed on allow or block lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If EWS-based e-mail servers use default user agent strings for client identification, then compatibility with standard e-mail clients is maintained, but device-specific access control cannot be implemented
Solution Approach 1:
The patent introduces a management server as an intermediary between the e-mail client and the e-mail server. This management server acts as a mediator that intercepts communication requests, assigns custom user agent strings to devices, and translates them into recognizable formats for the e-mail server, thereby enabling device-specific control without modifying the standard EWS protocol or e-mail server behavior
Solution Approach 2:
The patent changes the user agent string parameter from a static, protocol-defined value to a dynamic, device-specific value. By modifying the user agent string to include unique device identifiers while maintaining the basic EWS client format, the system enables device-level identification and access control without breaking compatibility with the existing e-mail server infrastructure
2Adaptability or versatility
If custom user agent strings are implemented for device identification, then device-specific control is enabled, but compatibility with existing e-mail servers may be compromised
Solution Approach 1:
The system performs preliminary actions by pre-configuring custom user agent strings with device identifiers before the actual e-mail communication occurs. The management server assigns these customized user agent strings to devices in advance, ensuring that when devices connect to the e-mail server, they present identifiable information without requiring any modifications to the e-mail server itself
Solution Approach 2:
The patent creates a universal solution that works across multiple device types and e-mail clients by using a standardized format for custom user agent strings. The management server handles the complexity of device-specific identification universally, allowing different devices (smartphones, tablets, laptops) to be identified and controlled through the same mechanism without requiring device-specific implementations
Data Source
AI summary
Systems and methods herein can provide device-specific access to an e-mail server, including an EWS-based e-mail server. In an example, a management server controlled by a system administrator provides device identification information to a user device and to a tunnel server. The management server also provides a custom request identifier to the tunnel server, and provides instructions to the e-mail server to allow access for requests including that custom request identifier. The tunnel server receives a request from the user device, rewrites the request to include the custom request identifier, and passes the request to the e-mail server.


