Tunnel Server Rewrites User Agent Strings for Device-Specific EWS Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing mobile devices lack device-specific control over access to e-mail servers, particularly for EWS-based servers that do not utilize unique request identifiers, limiting administrators' ability to grant or deny access based on device compliance and enrollment statuses.

Innovation Solution

A system that includes a management server and a tunnel server to provide device identification information, allowing for the customization of user agent strings and secure access through a VPN, enabling device-specific access to EWS-based e-mail servers by rewriting default user agent strings with custom ones, which can be managed on allow or block lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If EWS-based e-mail servers use default user agent strings for client identification, then compatibility with standard e-mail clients is maintained, but device-specific access control cannot be implemented

Engineering Contradiction:
Improvedevice-specific access controlVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a management server as an intermediary between the e-mail client and the e-mail server. This management server acts as a mediator that intercepts communication requests, assigns custom user agent strings to devices, and translates them into recognizable formats for the e-mail server, thereby enabling device-specific control without modifying the standard EWS protocol or e-mail server behavior

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the user agent string parameter from a static, protocol-defined value to a dynamic, device-specific value. By modifying the user agent string to include unique device identifiers while maintaining the basic EWS client format, the system enables device-level identification and access control without breaking compatibility with the existing e-mail server infrastructure

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If custom user agent strings are implemented for device identification, then device-specific control is enabled, but compatibility with existing e-mail servers may be compromised

Engineering Contradiction:
Improvedevice identification capabilityVSAvoidserver compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by pre-configuring custom user agent strings with device identifiers before the actual e-mail communication occurs. The management server assigns these customized user agent strings to devices in advance, ensuring that when devices connect to the e-mail server, they present identifiable information without requiring any modifications to the e-mail server itself

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal solution that works across multiple device types and e-mail clients by using a standardized format for custom user agent strings. The management server handles the complexity of device-specific identification universally, allowing different devices (smartphones, tablets, laptops) to be identified and controlled through the same mechanism without requiring device-specific implementations

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10880307B2Systems for providing device-specific access to an e-mail server
Publication Date: 2020.12.29 OMNISSA LLC
  • US10880307B2 patent drawing
  • US10880307B2 patent drawing
  • US10880307B2 patent drawing

AI summary

Systems and methods herein can provide device-specific access to an e-mail server, including an EWS-based e-mail server. In an example, a management server controlled by a system administrator provides device identification information to a user device and to a tunnel server. The management server also provides a custom request identifier to the tunnel server, and provides instructions to the e-mail server to allow access for requests including that custom request identifier. The tunnel server receives a request from the user device, rewrites the request to include the custom request identifier, and passes the request to the e-mail server.