Contextual Data Protection via Boot State Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional device data protection techniques are not foolproof, as they rely on user authentication and encryption, which can be overcome by unauthorized access, leaving sensitive data vulnerable when the user is forced to disclose their password or when the device is stolen unexpectedly, with no immediate way to protect the data from further access.

Innovation Solution

A computing device automatically enters a data protection mode based on detected user input and behaviors during boot-up, login, or shut-down states, rendering sensitive data invisible and inaccessible in a manner not apparent to the user, using contextual triggers such as biometric signals, location, or user input patterns to initiate data protection measures like soft or hard deletion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional user authentication and encryption mechanisms are used to protect sensitive data, then data security is improved, but the system becomes vulnerable when users are forced to disclose passwords or when devices are stolen unexpectedly

Engineering Contradiction:
Improvedata securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by automatically detecting theft scenarios during boot-up, login, or shut-down states and preemptively deleting sensitive data before unauthorized access can occur. The contextual trigger monitor identifies theft indicators (such as unauthorized access attempts, abnormal usage patterns, or location changes) and activates the data protection enactor to delete sensitive data in advance, eliminating the need for user intervention during critical moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service by automatically monitoring its own operational states and autonomously executing data protection measures without requiring user awareness or action. The contextual trigger monitor continuously observes system behavior, and when theft indicators are detected, the data protection enactor independently executes deletion operations on sensitive data, allowing the system to protect itself without user involvement during the critical theft scenario.

Inventive Principle:
Principle #25Self-service

2Reliability

If users manually delete sensitive data when theft is anticipated, then data protection is achieved, but the user lacks sufficient time to interact with the device and delete data when stolen unexpectedly

Engineering Contradiction:
Improvedata protectionVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically detecting theft scenarios during boot-up, login, or shut-down states and preemptively deleting sensitive data before unauthorized access can occur. The contextual trigger monitor identifies theft indicators (such as unauthorized access attempts, abnormal usage patterns, or location changes) and activates the data protection enactor to delete sensitive data in advance, eliminating the need for user intervention during critical moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service by automatically monitoring its own operational states and autonomously executing data protection measures without requiring user awareness or action. The contextual trigger monitor continuously observes system behavior, and when theft indicators are detected, the data protection enactor independently executes deletion operations on sensitive data, allowing the system to protect itself without user involvement during the critical theft scenario.

Inventive Principle:
Principle #25Self-service

3Reliability

If the system automatically monitors user input and behaviors to detect theft scenarios, then data protection responsiveness is improved, but device complexity increases

Engineering Contradiction:
Improvedata protection activationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves multi-functionality by integrating the contextual trigger monitor and data protection enactor into existing operational states (boot-up, login, shut-down). These components leverage existing system processes and user input mechanisms to detect theft scenarios, rather than adding entirely separate monitoring systems. The same user input detection infrastructure used for normal authentication is reused for theft detection, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system applies local quality by focusing monitoring and protection efforts specifically on sensitive data and critical operational states. Rather than monitoring all device operations uniformly, the contextual trigger monitor concentrates on detecting theft indicators during specific phases (boot-up, login, shut-down) and for specific data types (sensitive data). This targeted approach reduces the complexity burden while maintaining effective data protection.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10846425B2Data protection based on user input during device boot-up, user login, and device shut-down states
Publication Date: 2020.11.24 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10846425B2 patent drawing
  • US10846425B2 patent drawing
  • US10846425B2 patent drawing

AI summary

A computing device is described herein that automatically enters a data protection mode in response to the detected presence or absence of certain user input and/or user input behaviors during a device boot-up state, a user login state, or a device shut-down state. When the device enters the data protection mode, sensitive data stored on the device is automatically rendered invisible and/or inaccessible to a user thereof. The sensitive data may be rendered invisible and/or inaccessible in a manner that is not likely to be apparent to the user of the computing device.