Encoding data in message headers
Among other things, we describe techniques for carrying encoded data in a header field of an email message wherein the encoded data is homomorphically encrypted such that the encoded data is only interpretable by one or more authorized recipients and operable by any recipient. A recipient of such an email message (which may be the sender or another recipient) can derive an action to be carried out from the homomorphically-encrypted encoded data.
1 . A computer implemented method for archive-less messaging, the method comprising:
at a first electronic communication system, transmitting via a communication system a first email message that includes a Message-ID field including encoded data relating to information in the first email message, wherein the encoded data stores a result of a security or threat assessment performed on the information by the first electronic communication system; and
at a second electronic communication system, receiving via the communication system a second email message that includes an In-Reply-To field containing the encoded data from the first email message including the result of the security or threat assessment such that the result of the security or threat assessment is persisted across the communication system and the second electronic communication system has the result of the security or threat assessment without needing to repeat the action on the information and without the result being stored in a separate archive.
2 . The method of claim 1 , wherein the second electronic communication system and the first electronic communication system are the same electronic communication system.
3 . The method of claim 1 , wherein the second electronic communication system and the first electronic communication system are different electronic communication systems.
4 . The method of claim 1 , wherein the security or threat assessment includes at least one of assessment for a possible impersonation attempt, assessment of sender reputation, assessment of compliance issues, or assessment for personally identifiable information or other sensitive information.
5 . The method of claim 4 , wherein the second electronic communication system presents a warning to a user related to the result of the security or threat assessment.
6 . The method of claim 5 , wherein the security warning is presented when the user attempts to reply to the second email message.
7 . The method of claim 1 , wherein the encoded data is encrypted and wherein the second electronic communication system decrypts the encoded data.
8 . The method of claim 1 , wherein the first electronic communication system performs the security or threat assessment in a stateless manner.
9 . The method of claim 1 , wherein the first electronic communication system or the second electronic communication system comprises an email client or an email server.
10 . An electronic communication system for archive-less messaging, the system comprising:
one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform processes comprising:
at a first electronic communication system, transmitting via a communication system a first email message that includes a Message-ID field including encoded data relating to information in the first email message, wherein the encoded data stores a result of a security or threat assessment performed on the information by the first electronic communication system; and
at a second electronic communication system, receiving via the communication system a second email message that includes an In-Reply-To field containing the encoded data from the first email message including the result of the security or threat assessment such that the result of the security or threat assessment is persisted across the communication system and the second electronic communication system has the result of the security or threat assessment without needing to repeat the action on the information and without the result being stored in a separate archive.
11 . The system of claim 10 , wherein the second electronic communication system and the first electronic communication system are the same electronic communication system.
12 . The system of claim 10 , wherein the second electronic communication system and the first electronic communication system are different electronic communication systems.
13 . The system of claim 10 , wherein the security or threat assessment includes at least one of assessment for a possible impersonation attempt, assessment of sender reputation, assessment of compliance issues, or assessment for personally identifiable information or other sensitive information.
14 . The system of claim 13 , wherein the second electronic communication system presents a warning to a user related to the result of the security or threat assessment.
15 . The system of claim 14 , wherein the security warning is presented when the user attempts to reply to the second email message.
16 . The system of claim 10 , wherein the encoded data is encrypted and wherein the second electronic communication system decrypts the encoded data.
17 . The system of claim 10 , wherein the first electronic communication system performs the security or threat assessment in a stateless manner.
18 . The system of claim 10 , wherein the first electronic communication system or the second electronic communication system comprises an email client or an email server.
19 . A computer program product comprising at least one tangible, non-transitory computer-readable storage medium having embodied therein computer program instructions for archive-less messaging which, when executed on at least one processor of an electronic communication system, performs processes comprising:
transmitting via a communication system a first email message that includes a Message-ID field including encoded data relating to information in the first email message, wherein the encoded data stores a result of a security or threat assessment performed on the information by the electronic communication system; and
receiving from a second electronic communication system via the communication system a second email message that includes an In-Reply-To field containing encoded data including a result of a security or threat assessment performed on information in the second email message, wherein the results of the security or threat assessments are persisted across the communication system and the electronic communication system has the result of the security or threat assessment performed on the information in the second email message without needing to repeat the action on the information and without the result being stored in a separate archive.
20 . The computer program product of claim 19 , wherein the security or threat assessments include at least one of assessment for a possible impersonation attempt, assessment of sender reputation, assessment of compliance issues, or assessment for personally identifiable information or other sensitive information.