EP2057808A2 - Secure multi-identity management methods for a centralized messaging service - Google Patents
Secure multi-identity management methods for a centralized messaging serviceInfo
- Publication number
- EP2057808A2 EP2057808A2 EP07805756A EP07805756A EP2057808A2 EP 2057808 A2 EP2057808 A2 EP 2057808A2 EP 07805756 A EP07805756 A EP 07805756A EP 07805756 A EP07805756 A EP 07805756A EP 2057808 A2 EP2057808 A2 EP 2057808A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- message
- user
- server
- identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000007726 management method Methods 0.000 title claims abstract description 27
- 238000000034 method Methods 0.000 claims abstract description 6
- 238000012545 processing Methods 0.000 claims description 21
- 230000003993 interaction Effects 0.000 claims description 15
- 238000003860 storage Methods 0.000 claims description 5
- 238000004891 communication Methods 0.000 claims description 4
- 238000004519 manufacturing process Methods 0.000 claims description 3
- 230000000694 effects Effects 0.000 claims description 2
- 238000013101 initial test Methods 0.000 claims description 2
- 238000000926 separation method Methods 0.000 claims description 2
- 238000010200 validation analysis Methods 0.000 claims description 2
- 230000002035 prolonged effect Effects 0.000 claims 1
- 230000000295 complement effect Effects 0.000 abstract 1
- 238000005516 engineering process Methods 0.000 description 3
- 238000012546 transfer Methods 0.000 description 2
- 230000008901 benefit Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 238000009826 distribution Methods 0.000 description 1
- 238000012423 maintenance Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/21—Monitoring or handling of messages
- H04L51/214—Monitoring or handling of messages using selective forwarding
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/21—Monitoring or handling of messages
- H04L51/234—Monitoring or handling of messages for tracking messages
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/48—Message addressing, e.g. address format or anonymous messages, aliases
Definitions
- the present invention relates to net security problems, and particularly those concerning the privacy of the actors of a messaging system, and relies on already existing technologies with the aid of privacy and identity protection systems able to hide associations between identity and subscription from the recipients of messages. Index of acronyms
- DNS - Domain Name Server net service attending to the resolutions of the textual domain addresses in their numerical counterparts; moreover, it provides details of mail servers associated to textual domains; i
- IMAP or IMAPS - Internet Message Access Protocol net service for the users to gain access to a database containing electronic-mail messages associated to that particular user
- SMTP or SMTPS - Simple Mail Transfer Protocol net protocol to address and transmit e-mail messages
- HTTP/HTTPS - Hyper Text Transfer Protocol Net protocol allowing data to be transferred from a service unit to an applicant.
- the secure release provides additionally the encryption of the transit data.
- Electronic-mail systems are based upon concepts which are similar to the traditional mail systems as far as the routing aspect is concerned.
- a subject is identified by an univocal address which is specified by him/her as sender upon sending a message. Such address allows the geographic delivery area of any mail message addressed to him/her to be identified.
- the mail service of the sender adds suitable notes (headings) to the message indicating the transit of the same through the mail office concerned.
- headings indicate the geographic position of the area where the subject has gone to hand over the message to the mail service.
- a sender may have several addresses, but if the latter are managed by the same mail facility, they can be traced back to the same geographic area.
- e-mail systems also include the ; fight address of the computer, (or computer net) compiling and sending the message in the headings, thus causing considerable privacy problems.
- Some e-mail service providers cancel the information relative to the right address of the computer (or computer net)-from which the messages are sent. ⁇ . ⁇ — -, ⁇ ;,; This operation is little r -useful and can be easily detectedj ⁇ y ; tiie recipients of the e-mail messages. Under these circumstances it is possible for the recipient to [detect not only that the e-mail provider is still the same but also the geographic coordinates of origin and destination are still the same apart of the presumed nationality of an e-mail address.
- the invention aims at providing an e-mail platform able to carry out:
- an object of the present invention is to provide a platform using known means and technology within technology and protocol of Internet to operate with a net facility of easy maintenance and prompt feasibility.
- the e-mail platform consists of several servers that manage the several aspects of the system. From the operation point of view the several logic units are able to exchange with one another data regarding the state of the message and to forward the message to the following logic unit by mailing or to the final destination by delivery.
- the net system is integrated and cooperate with the already existing security systems.
- such units allow the message to appear as originated by the server unit operating at a primary stage of interaction with the , user and processing SMTP or SMTPS outp ⁇ ts, and each domain can be arranged to, be outputted from any unit so that the origin of the e-mail message is masked and the user is uncoupled from the impersonated identity.
- the main advantage is certainly to add to the protection of the contents also the protection of the privacy of the user by decoupling him/her from the sending identity.
- the electronic mail is a largely widespread, studied communication standard which is the object of many technical embodiments solving already the problems of the protection of the contents and then an object of the present invention is to implement the identity.
- Every mail server allows two possible routing modes: the first one is the forced routing to a fixed destination of the message, the second one instead is the resolution of the destination of the message by direct request of DNS server responsible for the domain of belonging of the e-mail.
- the implementation of the first routing method is referred to as "forwarding”
- the implementation of the second routing method is referred to as "delivery”.
- the implementation consists of several servers managing the several aspects of the system and operating to ensure the confidentiality of the sensible data of the users.
- three 'categories of servers managing the several communication aspects are identified:
- - storage servers machines where user's messages are stored
- - backend servers machines responsible for protecting the confidentiality of the messages and implementing the geographic routing to the geographical servers;
- - geographical servers relay machines responsible for delivering the mail to the recipients simulating the local production of the message.
- Such systems are supported on the user's side by messaging applications responsible for managing the encryption of the contents in the user's machine to guarantee the confidentiality of the contents since before the reception of the contents by the system.
- the whole system is divided in logic units able to exchange data regarding the state of the message with one another and tp forward the message to the following logic unit by forwarding or to the final destination by delivery.
- I - The messages sent by the users through mail client are delivered to unit 1 (server operating at a primary stage of interaction with the user) which re-addresses the SMTP or SMTPS connections to the logic unit 3 and any IMAP or IMAPS connections to logic unit 2 and controls the authentication of the user as well as checks that the defined identity to send the message is accessible by that particular user.
- the user gains access through HTTPS protocol to logic unit 1 which re-addresses the connection to logic unit 2 (service server for user's processing) which is responsible for providing to client web the interface for sending e- mails and all of the activities of authentication and validation performed in the same way as unit 1.
- unit 3 service server for SMTP or SMTPS output processing
- unit 9 output filter service server
- unit 9 output filter service server
- the server provides for identifying the sender and reading from unit 6 (service server for administrative processing) the routing information , relative to the sender and according to this information forwards the message to that logic unit 7 (server operating at a primary stage of interaction with other outside management and delivery services and processing SMTP outputs) indicated among the available units as output point of the sender.
- Unit 7 is responsible for cancelling the routing headings inside the message as well as delivering to final destination.
- sender and recipient may agree a password for each message or the recipient may select a password or a permanently valid cryptographic key which will be used for all future messages received by him/her.
- sender and recipient may agree a password for each message or the recipient may select a password or a permanently valid cryptographic key which will be used for all future messages received by him/her.
- Messages directed to mail boxes managed by the present system are delivered from the servers of the sender systems to logic unit 8 (server operating at a primary stage of interaction with the system managing global e-mail and processing SMTP or SMTPS inputs).
- DNS server which is responsible for indicating to outside mail systems to address the e-mail to a particular unit 8 among those available according to the sites to which the domain is desired to belong is arranged for each domain managed by the system.
- These units are similar to units 7 and serve to keep the consistency among output and input points of the electronic mail and upon receiving the message forward it to unit 4 (input filter service server).
- Unit 4 controls that the input message has valid recipients inside the service and forwards the message to unit 10 (input filter service server). After the message is returned from unit 10 to unit 4 it is further forwarded to unit 5 (storage service server for IMAP or IMAPS access to e-mail) to be stored and made available for the users.
- unit 5 storage service server for IMAP or IMAPS access to e-mail
- Units 9, 10 include mail service filters responsible for managing on the base of user preferences the production of routing headings, to be added to output mail messages according to the identity specified upon sending and including information regarding the desired apparent origin of the message as well as information regarding the intermediate servers which processed the message.
- Input filter (unit 10) further provides advanced functions forming the core of the added value of the service and including among others:
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Information Transfer Between Computers (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| IT000425A ITRM20060425A1 (en) | 2006-08-04 | 2006-08-04 | TECHNIQUES OF SAFE MANAGEMENT MULTI IDENTITY FOR CENTRALIZED MESSAGING SERVICES |
| PCT/IT2007/000558 WO2008015721A2 (en) | 2006-08-04 | 2007-08-02 | Secure multi-identity management methods for a centralized messaging service |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2057808A2 true EP2057808A2 (en) | 2009-05-13 |
Family
ID=38761883
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP07805756A Withdrawn EP2057808A2 (en) | 2006-08-04 | 2007-08-02 | Secure multi-identity management methods for a centralized messaging service |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP2057808A2 (en) |
| IT (1) | ITRM20060425A1 (en) |
| WO (1) | WO2008015721A2 (en) |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2000051323A1 (en) * | 1999-02-26 | 2000-08-31 | Bellsouth Intellectual Property Corporation | Methods and systems to provide a message in a messaging system without revealing an identity of the sending party |
| US6374292B1 (en) * | 1999-07-20 | 2002-04-16 | Sun Microsystems, Inc. | Access control system for an ISP hosted shared email server |
| US20050188077A1 (en) * | 2004-02-19 | 2005-08-25 | Quintanilla Christopher A. | Method of tracking and authenticating e-mails |
| US20060026438A1 (en) * | 2004-07-29 | 2006-02-02 | Microsoft Corporation | Anonymous aliases for on-line communications |
-
2006
- 2006-08-04 IT IT000425A patent/ITRM20060425A1/en unknown
-
2007
- 2007-08-02 WO PCT/IT2007/000558 patent/WO2008015721A2/en not_active Ceased
- 2007-08-02 EP EP07805756A patent/EP2057808A2/en not_active Withdrawn
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2008015721A3 * |
Also Published As
| Publication number | Publication date |
|---|---|
| ITRM20060425A1 (en) | 2008-02-05 |
| WO2008015721A2 (en) | 2008-02-07 |
| WO2008015721A3 (en) | 2008-03-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN100466632C (en) | Method and apparatus for anonymous group messaging in a distributed messaging system | |
| EP1788770B1 (en) | A method for establishing a secure e-mail communication channel between a sender and a recipient | |
| US8280967B2 (en) | Virtual email method for preventing delivery of unsolicited and undesired electronic messages | |
| KR20120005364A (en) | Electronic address, and electronic document distribution system | |
| WO2004107700A1 (en) | System and method for secure communication | |
| US20040221048A1 (en) | Email archive system | |
| WO2001097432A2 (en) | Secure messaging system with return receipts | |
| CN1801694B (en) | Trusted Safe Senders List | |
| JP2003298658A (en) | Email content confirmation device and method | |
| US8484456B2 (en) | Trusted electronic messaging system | |
| KR20120078602A (en) | Intermediary node with distribution capability and communication network with federated metering capability | |
| KR100756308B1 (en) | Secure Peer-to-peer messaging invitation architecture | |
| US7512789B2 (en) | Mailing list server and mail transmission method thereof | |
| JP2017200031A (en) | Electronic mail system | |
| CA2921806A1 (en) | System and method for smtp and alternative email protocol interoperability | |
| CN104394064A (en) | Novel method and system for limiting forwarding in email transfer | |
| WO2005004422A1 (en) | Electronic mail transmission/reception system | |
| WO2000007355A2 (en) | Secure message management system | |
| KR100369282B1 (en) | An E-mail service system with anti-spam mail using virtual E-mail addresses and method therefor | |
| Cevenini et al. | A multiprovider, universal, E-mail service for the secure exchange of legally-binding multimedia documents | |
| WO2008015721A2 (en) | Secure multi-identity management methods for a centralized messaging service | |
| JP2000267954A (en) | E-mail cancellation method and method | |
| Oppliger | Providing certified mail services on the internet | |
| US10382211B1 (en) | Apparatus and method for automating secure email for multiple personas | |
| JP2016143188A (en) | Method for generating authenticated electronic contract by customer of communication business company |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20090304 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC MT NL PL PT RO SE SI SK TR |
|
| AX | Request for extension of the european patent |
Extension state: AL BA HR MK RS |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: PIETROSANTI, FABIO Inventor name: BOCCACCIA, LORENZO Inventor name: MORO, FEDERICO |
|
| DAX | Request for extension of the european patent (deleted) | ||
| 17Q | First examination report despatched |
Effective date: 20100623 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20101104 |