Hypertext Link Verification In Encrypted E-Mail For Mobile Devices
A method, device and computer readable memory are provided for verifying hypertext links in an encrypted e-mail message to be sent to a mobile device to remove links that may contain malicious programs, link to a phishing website, or potentially comprise security of the mobile device or expose the user to unsafe sites or content. The hypertext links are extracted by decrypting the encrypted e-mail message. The hypertext links from the decrypted e-mail message are extracted and for each link the status is determined to verify the link. Actions can then be performed based upon the determined status of respective extracted hypertext links.
1 . A method of verifying hypertext links in an encrypted e-mail message to be sent to a mobile device comprising:
decrypting the encrypted e-mail message comprising at least one hypertext link;
extracting the at least one hypertext link from the decrypted e-mail message;
for each of the at least one extracted hypertext links, determining at a server a status of the extracted hypertext link; and
performing one or more actions based upon the determined status of respective extracted hypertext links.
2 . The method of claim 1 , wherein the decrypting of the encrypted e-mail message and extracting hypertext links is performed by the mobile device, the method further comprising sending the extracted links to the server.
3 . The method of claim 2 , wherein the one or more actions comprise sending the determined statuses of the one or more extracted hypertext links to the mobile device.
4 . The method of claim 1 , wherein the decrypting of the encrypted e-mail message and extracting hypertext links is done by the server, the method further comprising:
requesting a session key used to encrypt the e-mail message from the mobile device; and
receiving the requested session key at the server.
5 . The method of claim 4 , wherein the one or more actions comprise sending the determined statuses of the one or more extracted hypertext links to the mobile device with the encrypted e-mail message.
6 . The method of claim 4 , wherein each of the determined link statuses comprise an indication of the link being a verified link or an unverified link.
7 . The method of claim 6 , wherein the one or more actions comprise replacing or removing any unverified link with an indication that the link has been removed.
8 . The method of claim 4 , wherein the encrypted e-mail message is further signed by a sender of the e-mail, the method further comprising:
authenticating the sender of the signed e-mail message.
9 . The method of claim 8 , wherein the one or more actions comprise sending the determined statuses of the one or more extracted hypertext links to the mobile device with the encrypted e-mail message.
10 . The method of claim 8 , wherein the one or more actions comprises:
replacing any hypertext link determined to an unverified link with an indication that the link has been removed to generate a clean e-mail message text; and
sending the clean e-mail message text to the mobile device with the encrypted e-mail message.
11 . The method of claim 8 , wherein the one or more actions comprises:
replacing any hypertext link determined to an unverified link with an indication that the link has been removed to generate a clean e-mail message text; and
sending the clean e-mail message text to the mobile device with an indication of whether the authentication performed at the server was successful.
12 . The method of claim 1 , wherein the one or more actions comprise one or more of:
replacing an unverified link with an indication that the link has been removed;
adding a status indicator to the e-mail message based on the determined statuses of the one or more extracted hypertext links;
adding an indicator to the message preventing the mobile device from opening any links in a browser and/or preventing the mobile device from copying the link into a browser;
rejecting the encrypted e-mail message; and
marking the encrypted e-mail message as unforwardable preventing the mobile device from replying to the e-mail message or forwarding the e-mail message.
13 . The method of claim 1 , wherein determining the status of each extracted hypertext link comprises performing one or more verification techniques selected from the group comprising:
verifying that a universal resource locator (URL) matches a link text of the hypertext link for an embedded hypertext link;
verifying a certification status for a hypertext transfer protocol secure (HTTPS) hypertext link;
verifying that the hypertext link is a link to a location internal to a particular network;
verifying that the hypertext link is not on a black list; and
verifying that the hypertext link is on a white list.
14 . A device for verifying hypertext links in an encrypted e-mail message to be sent to a mobile device, the device comprising:
a memory for storing instructions; and
a processor for executing the stored instructions, the instructions when executed by the processor configuring the device to provide functionality for:
decrypting the encrypted e-mail message comprising at least one hypertext link;
extracting the at least one hypertext link from the decrypted e-mail message;
for each of the at least one extracted hypertext links, determining a status of the extracted hypertext link; and
performing one or more actions based upon the determined status of respective extracted hypertext links.
15 . The device of claim 14 , wherein the decrypting of the encrypted e-mail message and extracting hypertext links is performed by a mobile device, the functionality further for:
receiving the extracted links at the device; and
sending the determined statuses of the one or more extracted hypertext links to the mobile device.
16 . The device of claim 14 , wherein the functionality is further for:
requesting a session key used to encrypt the e-mail message from the mobile device; and
receiving the requested session key;
decrypting the encrypted e-mail message; and
extracting hypertext links from the decrypted e-mail message.
17 . The device of claim 16 , wherein the one or more actions comprise sending the determined statuses of the one or more extracted hypertext links to the mobile device with the encrypted e-mail message.
18 . The device of claim 16 , wherein each of the determined link statuses comprise an indication of if the link is a verified link or an unverified link.
19 . The device of claim 16 , wherein the encrypted e-mail message is further signed by a sender of the e-mail, the functionality further for authenticating the sender of the signed e-mail message.
20 . The device of claim 19 , wherein the one or more actions comprise sending the determined statuses of the one or more extracted hypertext links to the mobile device with the encrypted e-mail message.
21 . The device of claim 19 , wherein the one or more actions comprises:
replacing any hypertext link determined to an unverified link with an indication that the link has been removed to generate a clean e-mail message text; and
sending the clean e-mail message text to the mobile device with the encrypted e-mail message.
22 . The device of claim 19 , wherein the one or more actions comprises:
replacing any hypertext link determined to an unverified link with an indication that the link has been removed to generate a clean e-mail message text; and
sending the clean e-mail message text to the mobile device with an indication of whether the authentication of the signed e-mail message performed at the device was successful.
23 . The device of claim 14 , wherein the one or more actions comprise one or more of:
replacing an unverified link with an indication that the link has been removed;
adding a status indicator to the e-mail message based on the determined statuses of the one or more extracted hypertext links;
adding an indicator to the message preventing the mobile device from opening any links in a browser and/or preventing the mobile device from copying the link into a browser;
rejecting the encrypted e-mail message; and
marking the encrypted e-mail message as unforwardable preventing the mobile device from replying to the e-mail message or forwarding the e-mail message.
24 . The device of claim 14 , wherein determining the status of each extracted hypertext link comprises performing one or more verification techniques selected from the group comprising:
verifying that a universal resource locator (URL) matches a link text of the hypertext link for an embedded hypertext link;
verifying a certification status for a hypertext transfer protocol secure (HTTPS) hypertext link;
verifying that the hypertext link is a link to a location internal to a particular network;
verifying that the hypertext link is not on a black list; and
verifying that the hypertext link is on a white list.
25 . A computer readable memory containing instructions for verifying hypertext links in an encrypted e-mail message to be sent to a mobile device, the instructions when executed by a processor perform:
decrypting the encrypted e-mail message comprising at least one hypertext link;
extracting the at least one hypertext link from the decrypted e-mail message;
for each of the at least one extracted hypertext links, determining at a server a status of the extracted hypertext link; and
performing one or more actions based upon the determined status of respective extracted hypertext links.