IP Library Granted Patent US 12,120,077
Granted Patent B2
US 12,120,077 · App. 16/867,780 · Granted Oct 15, 2024

Systems and methods for controlling email access

Inventor: Erich Stuntebeck (Johns Creek, GA)
Assignee: Omnissa, LLC
H04L51/212G06Q10/107H04L63/0428H04L63/08H04L63/10H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,120,077
App. No.
16/867,780
Granted
Oct 15, 2024
Kind
B2
Abstract

Embodiments of the disclosure relate to proxying at least one email resource from at least one email service to at least one client device, determining whether the email resources are accessible to the client devices via at least one unauthorized application on the client devices, and modifying the email resources to be inaccessible via the unauthorized applications on the client devices in response to a determination that the email resources are accessible via the unauthorized applications on the client devices.

Claims (50)

1. A method performed by an access control server to manage a client device's access to content associated with email messages provided by an email server, the access control server being configured to execute as a proxy between the email server and the client device for the email messages, the method comprising:

obtaining from the email server, an email message for transmission to the client device;

determining according to at least one resource rule including an access-type resource rule, to restrict the client device's access to the obtained email message based on a presence of an unauthorized application running on the client device that can access email messages transmitted to the client device;

in response to determining to restrict the client device's access, encrypting at least a portion of the obtained email message to generate a modified email message, the at least a portion of the obtained email message comprising a body of the obtained email message, wherein an authorized application on the client device has a cryptographic key for decrypting the modified email message, the cryptographic key being inaccessible to the unauthorized application; and

transmitting the modified email message to the client device.

2. The method of claim 1 , further comprising:

transmitting the cryptographic key to the authorized application to enable the authorized application to decrypt the modified email message.

3. The method of claim 1 , wherein the at least one resource rule includes a content-type resource rule, the method further comprising:

determining that text specified by the content-type resource rule is included in the obtained email message; and

based on determining that the specified text is included, transmitting the modified email message to the client device using a secure transmission protocol.

4. The method of claim 1 , wherein the at least one resource rule specifies as a credential for accessing the modified email message: a domain, a username, or an email address.

5. The method of claim 1 , wherein the at least a portion of the obtained email message further comprises an email attachment, the method further comprising:

encrypting the email attachment from the obtained email message to generate a modified attachment; and

including the modified attachment as an attachment to the modified email message transmitted to the client device.

6. The method of claim 1 , wherein the at least one resource rule includes a format-type resource rule specifying an encoding format, and wherein based on the format-type resource rule, the at least a portion of the obtained email message is encrypted according to the encoding format.

7. The method of claim 1 , wherein the at least one resource rule includes an attachment-type resource rule, the method further comprising:

based on the attachment-type resource rule, stripping an attachment from the obtained email message before generating the modified email message from the obtained email message.

8. A non-transitory computer-readable medium comprising a program which, when executed by a processor of an access control server that is configured to execute as a proxy between an email server and a client device that accesses content associated with email messages provided by the email server, causes the processor to at least:

obtain from the email server, an email message for transmission to the client device;

determine according to at least one resource rule including an access-type resource rule, to restrict the client device's access to the obtained email message based on a presence of an unauthorized application running on the client device that can access email messages transmitted to the client device;

in response to determining to restrict the client device's access, encrypt at least a portion of the obtained email message to generate a modified email message, the at least a portion of the obtained email message comprising a body of the obtained email message, wherein an authorized application on the client device has a cryptographic key for decrypting the modified email message, the cryptographic key being inaccessible to the unauthorized application; and

transmit the modified email message to the client device.

9. The non-transitory computer-readable medium of claim 8 , wherein the program, when executed by the processor, further causes the processor to at least:

transmit the cryptographic key to the authorized application to enable the authorized application to decrypt the modified email message.

10. The non-transitory computer-readable medium of claim 8 , wherein the at least one resource rule includes a content-type resource rule, and wherein the program, when executed by the processor, further causes the processor to at least:

determine that text specified by the content-type resource rule is included in the obtained email message; and

based on determining that the specified text is included, transmit the modified email message to the client device using a secure transmission protocol.

11. The non-transitory computer-readable medium of claim 8 , wherein the at least one resource rule specifies as a credential for accessing the modified email message: a domain, a username, or an email address.

12. The non-transitory computer-readable medium of claim 8 , wherein the at least a portion of the obtained email message further comprises an email attachment, and wherein the program, when executed by the processor, further causes the processor to at least:

encrypt the email attachment from the obtained email message to generate a modified attachment; and

include the modified attachment as an attachment to the modified email message transmitted to the client device.

13. The non-transitory computer-readable medium of claim 8 , wherein the at least one resource rule includes a format-type resource rule specifying an encoding format, and wherein based on the format-type resource rule, the at least a portion of the obtained email message is encrypted according to the encoding format.

14. The non-transitory computer-readable medium of claim 8 , wherein the at least one resource rule includes an attachment-type resource rule, and wherein the program, when executed by the processor, further causes the processor to at least:

based on the attachment-type resource rule, strip an attachment from the obtained email message before generating the modified email message from the obtained email message.

15. An access control server configured to execute as a proxy between an email server and a client device that accesses content associated with email messages provided by the email server, wherein the access control server includes a processor configured to execute instructions from a non-transitory computer-readable medium to at least:

obtain from the email server, an email message for transmission to the client device;

determine according to at least one resource rule including an access-type resource rule, to restrict the client device's access to the obtained email message based on a presence of an unauthorized application running on the client device that can access email messages transmitted to the client device;

in response to determining to restrict the client device's access, encrypt at least a portion of the obtained email message to generate a modified email message, the at least a portion of the obtained email message comprising a body of the obtained email message, wherein an authorized application on the client device has a cryptographic key for decrypting the modified email message, the cryptographic key being inaccessible to the unauthorized application; and

transmit the modified email message to the client device.

16. The access control server of claim 15 , wherein the processor is further configured to execute the instructions from the non-transitory computer-readable medium to at least:

transmit the cryptographic key to the authorized application to enable the authorized application to decrypt the modified email message.

17. The access control server of claim 15 , wherein the at least one resource rule includes a content-type resource rule, and wherein the processor is further configured to execute the instructions from the non-transitory computer-readable medium to at least:

determine that text specified by the content-type resource rule is included in the obtained email message; and

based on determining that the specified text is included, transmit the modified email message to the client device using a secure transmission protocol.

18. The access control server of claim 15 , wherein the at least a portion of the obtained email message further comprises an email attachment, and wherein the processor is further configured to execute the instructions from the non-transitory computer-readable medium to at least:

encrypt the email attachment from the obtained email message to generate a modified attachment; and

include the modified attachment as an attachment to the modified email message transmitted to the client device.

19. The access control server of claim 15 , wherein the at least one resource rule includes a format-type resource rule specifying an encoding format, and wherein based on the format-type resource rule, the at least a portion of the obtained email message is encrypted according to the encoding format.

20. The access control server of claim 15 , wherein the at least one resource rule includes an attachment-type resource rule, and wherein the processor is further configured to execute the instructions from the non-transitory computer-readable medium to at least:

based on the attachment-type resource rule, strip an attachment from the obtained email message before generating the modified email message from the obtained email message.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Cited By (1)
US 12,619,992