CN100477647C - E-mail management system and method - Google Patents

E-mail management system and method Download PDF

Info

Publication number
CN100477647C
CN100477647C CNB200410086828XA CN200410086828A CN100477647C CN 100477647 C CN100477647 C CN 100477647C CN B200410086828X A CNB200410086828X A CN B200410086828XA CN 200410086828 A CN200410086828 A CN 200410086828A CN 100477647 C CN100477647 C CN 100477647C
Authority
CN
China
Prior art keywords
attachment files
server
email
mail
document certificate
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CNB200410086828XA
Other languages
Chinese (zh)
Other versions
CN1767504A (en
Inventor
薛明
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CNB200410086828XA priority Critical patent/CN100477647C/en
Publication of CN1767504A publication Critical patent/CN1767504A/en
Application granted granted Critical
Publication of CN100477647C publication Critical patent/CN100477647C/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Abstract

This invention relates to an E-mail management system including: a file certificate management server used in generating related certificates for safe verification to the appendix of the E-mail to be transmitted, a customer end sending the E-mail with the appendix and related file certificates, a mail content check server used in verifying said appendix of the E-mail to be transmitted based on the certificate to confirm if the appendix is safe, a mail sending server forwarding the E-mail with the safety appendix to external networks and a safe gateway allowing the E-mail with the appendix verified to be safe by the content check server to pass only. This invention also discloses a management method.

Description

EManager for Exchange and method
Technical field
The present invention relates to data communication technology field, in particular, the present invention relates to a kind of eManager for Exchange and method.
Background technology
In all Internet services, E-mail service is a most basic service.Along with the development of Intemet in the whole world, number of netizens constantly increases, the scale of E-mail service also constantly enlarges in the whole world, and Email has brought a lot of convenience for people's live and work, and becomes indispensable part in people's daily life, the work.
Usually, the system that prior art manages Email as shown in Figure 1, eManager for Exchange mainly comprises:
Client 10: to the entity of external network send Email, as the front end of email, ftp etc.
Outgoing mail server 11: to the server of outside forwarded Email.
Security gateway 12: special-purpose network communication apparatus, check whether message has correct mandate; No through traffic to undelegated message; The message of having authorized is normally transmitted.
The general user is to send to the outgoing mail server of internal network appointment to the external network send Email, and outgoing mail server just can be checked Mail Contents earlier like this, sends again.
If the user will be intercepted and captured by way of security gateway the time directly to the network-external send Email, have only usually Content inspection be safe mail security gateway just give by.
Wherein content of message being carried out validity checking is a technical barrier.General enterprise network forbids that all internal user uses the ftp service, but can't forbid the reception and the transmission of Email.And can use attachment files to carry a large amount of documents and picture in the Email.But in enterprises, in order to prevent that the enterprises personnel from unlawfully transmitting the confidential data of company to the external world by network, need restriction enterprises personnel to send the Email of described band attachment files to external network, therefore, how outgoing mail server is checked the attachment files of Email with regard to becoming the focus of Mail Contents inspection, with the legitimacy of checking attachment files content.
At present, the inspection of the Email that inside is sent with prevent that spam is similar to the interference of internal network, adopt pattern matching inspections technology usually, promptly in the function of outgoing mail server or security gateway adding mail inspection.Mail inspection is to utilize regular expression that the content of Email is carried out pattern matching, forbids the Email that sends thereby identify.
The content-based coupling of above-mentioned prior art has certain effect in the fail safe that guarantees Email content.But also there is following shortcoming:
At first, limited to the inspection effect of Email content.This is because this technology is mainly utilized this mathematical tool of regular expression, discerns the assemblage characteristic of certain character string.It checks that effect all is very limited to content of text, has said nothing of multimedia files such as pictures.
Secondly, processing speed is slow.Using the regular expression coupling that file is checked needs a large amount of computings, and needs many matched rules in order to reach certain inspection effect.So especially the speed of attachment files is slow for the checking Email content.
Summary of the invention
The technical problem that the present invention solves provides a kind of eManager for Exchange and the method that can verify the e-mail attachment file, so that the enterprises send Email is more safe and reliable.
For addressing the above problem, eManager for Exchange of the present invention comprises:
The document certificate management server is used to the attachment files of Email to be sent to generate the corresponding document certificate that is used for safety verification;
Client is used to send the Email and the corresponding document certificate of described band attachment files;
Mail Contents is checked server, is used for according to described document certificate the attachment files of described Email to be sent being verified, with the attachment files of confirming Email to be sent safety whether;
Outgoing mail server, be used for that the Email to be sent of described band attachment files and corresponding document certificate are handed to described Mail Contents and check that server carries out safety verification, and in checking by the Email of back to the described band attachment files of outside forwarded;
Security gateway, be used to tackle the e-mail message that client directly sends to external network, it is transmitted to described Mail Contents checks that server carries out safety verification, to checking that through described Mail Contents the Email of the band attachment files of server authentication safety then allows to pass through.
Wherein, described document certificate management server generates first authorization information of corresponding attachment files according to digest algorithm, and described first authorization information is kept in the corresponding document certificate;
Described Mail Contents checks that server calculates generation second authorization information according to described digest algorithm to attachment files, whether first authorization information in the more described then document certificate is identical with second authorization information that described calculating is obtained, with the attachment files of verifying described Email to be sent safety whether.
Wherein, described first authorization information and second authorization information comprise the level of confidentiality and the digital signature of attachment files.
Wherein, described outgoing mail server also comprises the user right testing fixture, after Mail Contents checks that server authentication is passed through, check further according to default user right tabulation whether the user of the Email that sends the band attachment files has authority to send described attachment files, and allow the user of corresponding authority to send corresponding attachment files.
In addition, also comprise the mandate send server, be used for sending to security gateway according to the e-mail message of verifying the band attachment files that the permission of an agreement with safety sends;
Described security gateway is verified the legitimacy of message according to a checking agreement, and will be verified that the Email of the band attachment files that passes through sends.
Correspondingly, E-mail management method of the present invention comprises step:
A, document certificate management server generate the corresponding document certificate that is used for safety verification to sent the attachment files of Email;
B, client are transmitted to outgoing mail server with the Email and the corresponding document certificate of described band attachment files;
C, outgoing mail server are transmitted to Mail Contents inspection server with the Email to be sent and the corresponding document certificate of described band attachment files;
D, Mail Contents check that server verifies the attachment files of described Email to be sent according to described document certificate, and whether the attachment files of judging described Email to be sent safety, if safety, execution in step e then, otherwise carry out f;
E, outgoing mail server send the Email of described safe band attachment files by security gateway;
F, outgoing mail server forbid sending the Email of described band attachment files.
Wherein, step a document certificate management server generates first authorization information of corresponding attachment files according to digest algorithm, and described first authorization information is kept in the corresponding document certificate of described attachment files;
The described Mail Contents of steps d checks that server calculates generation second authorization information according to described digest algorithm to attachment files, whether first authorization information in the more described then document certificate is identical with described second authorization information, if it is identical, judge that then attachment files is safe, otherwise, judge that attachment files is dangerous.
Wherein, described first authorization information and second authorization information comprise the level of confidentiality and the digital signature of attachment files;
Step a specifically comprises:
A1, document certificate management server calculate first summary data according to digest algorithm to attachment files content and level of confidentiality, the private key of the described first summary data using system is encrypted obtained first digital signature;
A2, in document certificate, preserve and comprise the level of confidentiality of this attachment files and first authorization information of described first digital signature;
Steps d specifically comprises:
D1, Mail Contents check that server obtains the level of confidentiality of attachment files from document certificate, and calculate second summary data of attachment files and level of confidentiality according to described digest algorithm;
The PKI of d2, using system is decrypted first digital signature in the document certificate, obtains first summary data of original and level of confidentiality;
If d3, more described first summary data and described second summary data consistent, judge that then attachment files is complete and level of confidentiality is correct, and checking is passed through; Otherwise, judge that attachment files or level of confidentiality are modified, checking is not passed through.
Wherein, step e also comprises: after Mail Contents checks that server authentication is passed through, outgoing mail server checks further according to default user right tabulation whether the user of the Email that sends the band attachment files has authority to send described attachment files, if the user has corresponding authority, then the Email of the band attachment files that this user is sent is forwarded to external network by security gateway, otherwise, do not allow the user to send the Email of this band attachment files.
In addition, step e also comprises:
Authorize send server to send to security gateway according to the e-mail message of verifying the band attachment files that the permission of an agreement with safety sends;
Described security gateway is verified the legitimacy of message according to a checking agreement, and will be verified that the Email of the band attachment files that passes through sends.
Compared with prior art, the present invention has the following advantages:
At first, the present invention generates corresponding document certificate to the attachment files that can send, and described document certificate sent with attachment files, and then check that at Mail Contents server checks whether safety of attachment files according to described document certificate, thereby realize inspection to the Email that sends the band attachment files, for attachment files no matter be content of text, still multimedia file such as picture can corresponding spanned file certificate, therefore, check surface is wider compared to existing technology, and effect is also more obvious.
Secondly, the present invention checks that to the attachment files of Email processing speed is fast.Owing to adopt digest algorithm during checking e-mail attachment legitimacy, spanned file certificate such as rivest, shamir, adelman for example, only need to calculate summary data and once to the digital signature deciphering, these computings all be non-iterate disposable, therefore, adopt the need of canonical computing to iterate for the coupling with many rules with respect to prior art, processing speed of the present invention is faster, and efficient is higher.
Description of drawings
Fig. 1 is the structural representation of prior art eManager for Exchange;
Fig. 2 is that the embodiment of eManager for Exchange of the present invention forms schematic diagram;
Fig. 3 is that the present invention utilizes document certificate to carry out the principle schematic of attachment files checking;
Fig. 4 is the schematic diagram of spanned file certificate of the present invention;
Fig. 5 is that second embodiment of eManager for Exchange of the present invention forms schematic diagram;
Fig. 6 is the flow chart of E-mail management method of the present invention.
Embodiment
With reference to figure 2, this figure is that first embodiment of eManager for Exchange of the present invention forms schematic diagram.
EManager for Exchange comprises in the present embodiment: document certificate management server 20, client 21, Mail Contents are checked server 22, outgoing mail server 23 and security gateway 24, describe respectively below:
Document certificate management server 20
The management server of document certificate described in the present embodiment 20 is used to the attachment files of Email to be sent to generate the corresponding document certificate that is used for safety verification.
Usually the legitimacy of determining the e-mail attachment file mainly comprises following two aspects:
(1) whether the content of attachment files comprises confidential information.
(2) whether the transmission of attachment files can be authorized to.
Determined the security classification of the attachment files that can send in the present embodiment by the manager of system, promptly clearly whether this attachment files is inner secret, could disclose.After the level of confidentiality evaluation, with reference to figure 3, just attachment files and level of confidentiality thereof can be submitted to document certificate management server 20 together, generate the corresponding document certificate of this attachment files safety verification by the document certificate management server.
Client 21
Same as the prior art, client described in the present embodiment 21 is mainly used in Email and the corresponding document certificate that sends described band attachment files, and concrete, described client 21 can be the front end of email, ftp etc.;
Mail Contents is checked server 22
Described Mail Contents checks that server 22 is used for according to described document certificate the attachment files of described Email to be sent being verified, with the attachment files of confirming Email to be sent safety whether, concrete, refer again to Fig. 3, among the present invention for the band attachment files Email, by will sending with document certificate with the Email of attachment files in client 21, then, check that at Mail Contents server 22 can carry out safety verification according to document certificate, thereby avoided prior art to verify the shortcoming that processing speed is slower according to matching principle.
Outgoing mail server 23
Same as the prior art, outgoing mail server described in the present embodiment 23 has the mail forwarding capability, can give external network with e-mail forward, outgoing mail server described in the present embodiment 23 is before Forwarding Email, also will hand to described Mail Contents and check that server 22 carries out safety verification with the Email to be sent of attachment files and corresponding document certificate, only after checking is passed through just to the Email of the described band attachment files of outside forwarded.
Need to prove, for the attachment files inspection is the Email of safety, can check further also whether the user who sends this Email has authority to send, for this reason, outgoing mail server described in the present invention 23 also can comprise the user right testing fixture, after Mail Contents checks that server 22 checkings are passed through, check further according to default user right tabulation whether the user of the Email that sends the band attachment files has authority to send described attachment files, and allow the user of corresponding authority to send corresponding attachment files.
During specific implementation, inspection to user right can be checked server 22 realizations at Mail Contents equally, promptly check server 22 default user right tabulations at Mail Contents, be checked through attachment files for after safe then, further check according to described default user right tabulation whether the user who sends this Email has authority to send, if have, then determining can be with this e-mail forward to external network, otherwise, should forbid that this mail sends, should be noted that above-mentioned inspection to user right also can at first carry out, here only be illustrative, rather than limit the invention to this kind execution mode.
Security gateway 24
Same as the prior art, security gateway described in the present embodiment 24 is mainly used in the e-mail message that interception client 21 directly sends to external network, it is transmitted to described Mail Contents checks that server 22 carries out safety verification, the Email that is verified as safe band attachment files through described Mail Contents inspection server 22 is then allowed to pass through.
Following illustrated in greater detail document certificate management server 20 how spanned file certificate and Mail Contents checks that server 22 carries out the principle of safety verification according to described document certificate.
The management server of document certificate described in the present invention 20 can generate the authorization information of corresponding attachment files (for ease of difference according to various digest algorithms, here be called first authorization information), and described first authorization information is kept in the corresponding document certificate, corresponding therewith, described Mail Contents checks that server 22 calculates generation second authorization information according to described digest algorithm to attachment files equally, whether first authorization information in the more described then document certificate is identical with second authorization information that described calculating is obtained, if it is identical, judge that then attachment files is complete, be not modified, can determine it is safe; If inequality, can judge that then attachment files is imperfect, dangerous, should forbid sending this mail, whether the attachment files that can realize verifying described Email to be sent so fast safety.
For example, digest algorithm described in the present invention can adopt asymmetric key algorithm (NA, Non-symmetric Algorithm), with reference to figure 4, this figure is the schematic diagram that utilizes rivest, shamir, adelman spanned file certificate, and asymmetric key algorithm is a class cryptographic algorithm, and this algorithm provides two keys, use any one to encrypt, can only use another to be decrypted.Wherein PKI is can disclosed key in the rivest, shamir, adelman, private key then is the key by the individual subscriber keeping, during encryption message is carried out a kind of Hash computing, obtain the data of one section regular length, these data have comprised the feature of message, usually become summary data, the recipient can check message whether modification took place according to summary data; In order to prevent that summary data is forged, the summary data employing private key of message is encrypted simultaneously, its result is exactly a digital signature.Recipient's deciphering that uses public-key when the checking summary data is correct, also can be sure of the identity of message transmitting party.File certificate management server 20 generates attachment files corresponding file certificate according to described asymmetric key algorithm in advance in the present embodiment, then document certificate and the file that generates is placed in the online database together, the user user who needs access file (being about to file sends as annex) authorized, so that can obtain file and corresponding document certificate when needed.
Same, Mail Contents is checked when 22 pairs of attachment files of server are verified in the present embodiment, thereby with PKI the digital signature in the document certificate is decrypted and obtains original data summarization, then the attachment files that will verify is calculated summary data, the summary data that obtains with the digital signature deciphering compares, if consistent, just illustrate that former data do not change, i.e. attachment files safety; Otherwise illustrate that data content is modified, attachment files is dangerous, should forbid that the user sends the Email of described attachment files.
Like this, just can judge the integrality of file and the correctness of level of confidentiality by checking to document certificate.Can also comprise other attribute in the document certificate among the present invention: as filename, file description information etc., so that the management of document certificate and use.
Need to prove, the Email of transmitting for outgoing mail server 23 among the present invention also can further be verified to improve the fail safe of system, please refer to Fig. 5, this figure is that second embodiment of eManager for Exchange of the present invention forms schematic diagram, the present embodiment place different with first embodiment is to have increased mandate send server 25, and described mandate send server 25 is used for sending to security gateway 24 according to the e-mail message of verifying the band attachment files that the permission of an agreement with safety sends; A checking agreement is a kind of secure transfer protocol that carries the authentication of message word in message, the recipient can be according to the inspection to authenticator, the legitimacy of the integrality of confirmation message and transmit leg identity, during actual the realization, the e-mail message that 22 inspections are passed through for Mail Contents inspection server also can take other modes to encapsulate, and no longer is elaborated here.
Like this, security gateway 24 is verified the legitimacy of message according to a checking agreement, and will be verified that the Email of the band attachment files that passes through sends.
Authorize send server 25 also can give outgoing mail server 23 described in the present invention, forward the e-mail message of described encapsulation to security gateway 24 by outgoing mail server 23 and send according to the e-mail message of a checking protocol encapsulation.
Need to prove that during specific implementation, described mandate send server 25 and Mail Contents check that server all can be used as the functional module realization that outgoing mail server 23 strengthens, and are not limited to above-mentioned execution mode.
The following describes the present invention's E-mail management method on the other hand.
With reference to figure 6, this figure is the embodiment flow chart of E-mail management method of the present invention, mainly may further comprise the steps:
Step 30, the document certificate management server generates the corresponding document certificate that is used for safety verification to sent the attachment files of Email, as described above, during specific implementation, the document certificate management server can generate first authorization information of corresponding attachment files according to digest algorithm, and described first authorization information is kept in the corresponding document certificate of described attachment files;
Step 31, client is transmitted to outgoing mail server with the Email and the corresponding document certificate of described band attachment files;
Step 32, outgoing mail server is transmitted to Mail Contents inspection server with the Email to be sent and the corresponding document certificate of described band attachment files, all to forward Mail Contents to for the Email of being with attachment files and check that server carries out safety verification, directly send to the Email of security gateway for client, also need forward Mail Contents to and check that server carries out safety verification, be safe to guarantee attachment files;
Step 33, Mail Contents checks that server verifies the attachment files of described Email to be sent according to described document certificate, whether the attachment files of judging described Email to be sent safety, when specifically judging, described Mail Contents checks that server calculates generation second authorization information according to described digest algorithm to attachment files, whether first authorization information in the more described then document certificate is identical with second authorization information that described calculating is obtained, if it is identical, judge that then attachment files is complete, be not modified, can determine it is safe; If inequality, can judge that then attachment files is imperfect, dangerous; Further, if be judged as safety, then execution in step 34, otherwise execution in step 35;
Step 34, outgoing mail server sends the Email of described safe band attachment files by security gateway;
Step 35, outgoing mail server forbid sending the Email of described band attachment files.
Describe the generation of document certificate below in detail and how to carry out the attachment files safety inspection according to document certificate.
With reference to above stated specification, adoptable digest algorithm comprises technology well known in the art such as rivest, shamir, adelman among the present invention, first authorization information described in the document certificate and second authorization information include the digital signature of attachment files and the level of confidentiality of attachment files, it also is the example explanation with the rivest, shamir, adelman, the spanned file certificate specifically comprises following flow process: at first, the document certificate management server calculates first summary data according to digest algorithm to attachment files content and level of confidentiality, the private key of the described first summary data using system is encrypted obtained first digital signature; Then, preserve the document certificate of first authorization information of the level of confidentiality comprise this attachment files and described first digital signature;
Specifically comprise following flow process when accordingly, carrying out safety verification according to the document certificate of above-mentioned generation:
At first, Mail Contents checks that server obtains the level of confidentiality of attachment files from document certificate, and calculates second summary data of attachment files and level of confidentiality according to described digest algorithm;
Then, Mail Contents checks that the PKI of the further using system of server is decrypted first digital signature in the document certificate, obtains first summary data of original and level of confidentiality;
At last, Mail Contents is checked more described first summary data of server and described second summary data, if consistent, judges that then attachment files is complete and level of confidentiality is correct, and checking is passed through; Otherwise, judge that attachment files or level of confidentiality are modified, checking is not passed through.
Need to prove, present embodiment step 34 outgoing mail server by gateway before outside forwarded Email, promptly after Mail Contents checks that server authentication is passed through, outgoing mail server checks further according to default user right tabulation whether the user of the Email that sends the band attachment files has authority to send described attachment files, if the user has corresponding authority, then the Email of the band attachment files that this user is sent is forwarded to external network by security gateway, otherwise, do not allow the user to send the Email of this band attachment files.
And for the system of authorizing send server is set, also can also can further verify the legitimacy of message at security gateway, promptly authorizing send server according to the predetermined authentication agreement, for example a checking agreement sends to security gateway with the e-mail message of the band attachment files of the permission transmission of safety;
Described security gateway carries out legitimate verification according to corresponding indentification protocol, for example for the message of security gateway according to a checking protocol encapsulation, verify according to a checking agreement equally, the Email of the band attachment files that checking is passed through can be forwarded in the external network, specifically can no longer carefully state here with reference to above stated specification.
The above only is a preferred implementation of the present invention; should be pointed out that for those skilled in the art, under the prerequisite that does not break away from the principle of the invention; can also make some improvements and modifications, these improvements and modifications also should be considered as protection scope of the present invention.

Claims (10)

1, a kind of eManager for Exchange is characterized in that, comprising:
The document certificate management server is used to the attachment files of Email to be sent to generate the corresponding document certificate that is used for safety verification;
Client is used to send the Email and the corresponding document certificate of described band attachment files;
Mail Contents is checked server, is used for according to described document certificate the attachment files of described Email to be sent being verified, with the attachment files of confirming Email to be sent safety whether;
Outgoing mail server, be used for that the Email to be sent of described band attachment files and corresponding document certificate are handed to described Mail Contents and check that server carries out safety verification, and in checking by after by the Email of security gateway to the described band attachment files of outside forwarded;
Security gateway, be used to tackle the e-mail message that client directly sends to external network, it is transmitted to described Mail Contents checks that server carries out safety verification, to checking that through described Mail Contents the Email of the band attachment files of server authentication safety then allows to pass through.
2, eManager for Exchange according to claim 1 is characterized in that, described document certificate management server generates first authorization information of corresponding attachment files according to digest algorithm, and described first authorization information is kept in the corresponding document certificate;
Described Mail Contents checks that server calculates generation second authorization information according to described digest algorithm to attachment files, whether first authorization information in the more described then document certificate is identical with second authorization information that described calculating is obtained, when identical, the attachment files that then can verify described Email to be sent is a safety, then is dangerous when inequality.
3, eManager for Exchange according to claim 2 is characterized in that, described first authorization information and second authorization information comprise the level of confidentiality and the digital signature of attachment files.
4, according to each described eManager for Exchange in the claim 1 to 3, it is characterized in that, described outgoing mail server also comprises the user right testing fixture, after Mail Contents checks that server authentication is passed through, check further according to default user right tabulation whether the user of the Email that sends the band attachment files has authority to send described attachment files, and allow the user of corresponding authority to send corresponding attachment files.
5, eManager for Exchange according to claim 4, it is characterized in that, also comprise the mandate send server, be used for sending to security gateway through outgoing mail server according to the e-mail message of verifying the band attachment files that the permission of an agreement with safety sends;
Described security gateway is verified the legitimacy of message according to a checking agreement, and will be verified that the Email of the band attachment files that passes through sends.
6, a kind of E-mail management method is characterized in that, comprises step:
A, document certificate management server generate the corresponding document certificate that is used for safety verification to sent the attachment files of Email;
B, client are transmitted to outgoing mail server with the Email and the corresponding document certificate of described band attachment files;
C, outgoing mail server are transmitted to Mail Contents inspection server with the Email to be sent and the corresponding document certificate of described band attachment files;
D, Mail Contents check that server verifies the attachment files of described Email to be sent according to described document certificate, and whether the attachment files of judging described Email to be sent safety, if safety, execution in step e then, otherwise execution in step f;
E, outgoing mail server send the Email of described safe band attachment files by security gateway;
F, outgoing mail server forbid sending the Email of described band attachment files.
7, E-mail management method according to claim 6, it is characterized in that, step a document certificate management server generates first authorization information of corresponding attachment files according to digest algorithm, and described first authorization information is kept in the corresponding document certificate of described attachment files;
The described Mail Contents of steps d checks that server calculates generation second authorization information according to described digest algorithm to attachment files, whether first authorization information in the more described then document certificate is identical with described second authorization information, if it is identical, judge that then attachment files is safe, otherwise, judge that attachment files is dangerous.
8, E-mail management method according to claim 7 is characterized in that, described first authorization information and second authorization information comprise the level of confidentiality and the digital signature of attachment files;
Step a specifically comprises:
A1, document certificate management server calculate first summary data according to digest algorithm to attachment files content and level of confidentiality, the private key of the described first summary data using system is encrypted obtained first digital signature;
A2, in document certificate, preserve and comprise the level of confidentiality of this attachment files and first authorization information of described first digital signature;
Steps d specifically comprises:
D1, Mail Contents check that server obtains the level of confidentiality of attachment files from document certificate, and calculate second summary data of attachment files and level of confidentiality according to described digest algorithm;
The PKI of d2, using system is decrypted first digital signature in the document certificate, obtains described first summary data;
If d3, more described first summary data and described second summary data consistent, judge that then attachment files is complete and level of confidentiality is correct, and checking is passed through; Otherwise, judge that attachment files or level of confidentiality are modified, checking is not passed through.
9, according to each described E-mail management method in the claim 6 to 8, it is characterized in that, step e also comprises: after Mail Contents checks that server authentication is passed through, outgoing mail server checks further according to default user right tabulation whether the user of the Email that sends the band attachment files has authority to send described attachment files, if the user has corresponding authority, then the Email of the band attachment files that this user is sent is forwarded to external network by security gateway, otherwise, do not allow the user to send the Email of this band attachment files.
10, E-mail management method according to claim 9 is characterized in that, step e also comprises:
Authorize send server to be transmitted to security gateway through outgoing mail server according to the e-mail message of verifying the band attachment files that the permission of an agreement with safety sends;
Described security gateway is verified the legitimacy of message according to a checking agreement, and will be verified that the Email of the band attachment files that passes through sends.
CNB200410086828XA 2004-10-28 2004-10-28 E-mail management system and method Expired - Fee Related CN100477647C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB200410086828XA CN100477647C (en) 2004-10-28 2004-10-28 E-mail management system and method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB200410086828XA CN100477647C (en) 2004-10-28 2004-10-28 E-mail management system and method

Publications (2)

Publication Number Publication Date
CN1767504A CN1767504A (en) 2006-05-03
CN100477647C true CN100477647C (en) 2009-04-08

Family

ID=36743116

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB200410086828XA Expired - Fee Related CN100477647C (en) 2004-10-28 2004-10-28 E-mail management system and method

Country Status (1)

Country Link
CN (1) CN100477647C (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102055722A (en) * 2009-10-28 2011-05-11 上海中标软件有限公司 Implementation method for ensuring secure storage of electronic mails

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8117651B2 (en) * 2004-04-27 2012-02-14 Apple Inc. Method and system for authenticating an accessory
US7823214B2 (en) 2005-01-07 2010-10-26 Apple Inc. Accessory authentication for electronic devices
CN101848085B (en) * 2009-03-25 2013-12-18 华为技术有限公司 Communication system, verification device, and verification and signature method for message identity
CN102622686A (en) 2011-01-30 2012-08-01 国际商业机器公司 Method for managing email and system
CN103368815B (en) * 2012-03-29 2017-11-28 富泰华工业(深圳)有限公司 E-mail sending system and method based on data security
CN104301326A (en) * 2014-10-28 2015-01-21 网易(杭州)网络有限公司 Mail verification method and device
CN109120510B (en) * 2018-08-01 2022-03-08 北京奇虎科技有限公司 Authority control based mail sending method, device and system
CN112995016B (en) * 2019-12-17 2022-09-23 北京懿医云科技有限公司 Mail processing method and system, mail proxy gateway, medium and electronic equipment
CN113014531B (en) * 2019-12-20 2022-11-29 中标软件有限公司 Method for encrypting and transmitting e-mail data

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"企业邮件安全过滤网关的研究". 朱骏.浙江大学硕士学位论文. 2003
"企业邮件安全过滤网关的研究". 朱骏.浙江大学硕士学位论文. 2003 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102055722A (en) * 2009-10-28 2011-05-11 上海中标软件有限公司 Implementation method for ensuring secure storage of electronic mails
CN102055722B (en) * 2009-10-28 2014-01-15 中标软件有限公司 Implementation method for ensuring secure storage of electronic mails

Also Published As

Publication number Publication date
CN1767504A (en) 2006-05-03

Similar Documents

Publication Publication Date Title
US10511579B2 (en) Confidential mail with tracking and authentication
AU2002230823B2 (en) Method and system for obtaining digital signatures
EP1782213B1 (en) Secure messaging system with derived keys
EP1842313B1 (en) Method and system of managing and filtering electronic messages using cryptographic techniques
EP1583319B1 (en) Authenticated exchange of public information using electronic mail
US20060206433A1 (en) Secure and authenticated delivery of data from an automated meter reading system
CN108566395A (en) A kind of document transmission method, apparatus and system based on block chain
CN100566250C (en) A kind of point to point network identity identifying method
JP2010522488A (en) Secure electronic messaging system requiring key retrieval to distribute decryption key
CN104243494B (en) A kind of data processing method
US20070288746A1 (en) Method of providing key containers
JP4783340B2 (en) Protecting data traffic in a mobile network environment
US20030145200A1 (en) System and method for authenticating data transmissions from a digital scanner
JP2022521525A (en) Cryptographic method for validating data
CN100477647C (en) E-mail management system and method
CN1829150B (en) Gateway identification device and method based on CPK
Hirsch et al. Security and Privacy Considerations for the OASIS Security Assertion Markup Language (SAML) V2. 0
Al-Hammadi et al. Certified exchange of electronic mail (CEEM)
Prabhu et al. Security in computer networks and distributed systems
CN108696539B (en) Information service agent method for safety, fairness and privacy protection
EP3346659B1 (en) Communication method for electronic communication system in open environment
Piper Encryption
Qingping et al. Probe into E-commerce security technology
JP2005217665A (en) Communications system, transmitter, receiver and communication method
TW201513627A (en) Undeniable method using fair third party to provide message delivery

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.

CP03 Change of name, title or address
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20090408

Termination date: 20201028

CF01 Termination of patent right due to non-payment of annual fee