Cloud-Endpoint Data Deletion for Unsecured Location Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data loss prevention technologies face challenges in securely managing sensitive information, particularly in ensuring its deletion from devices when accessed in unsecure locations, and resource-intensive encryption methods are not always viable.
Innovation Solution
A cloud-endpoint model with automatic data deletion is implemented, where sensitive data is stored in the cloud and deleted after a certain time interval if not used, with periodic checks using GPS or gateway IP addresses to determine secure locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored on endpoint devices for user access, then data availability is improved, but data security deteriorates due to risk of loss, theft, or unauthorized access
Solution Approach 1:
The system performs preliminary actions by automatically deleting sensitive data from endpoint devices after a predetermined time interval without user intervention. The deletion process is initiated in advance based on policy rules, ensuring that data is removed before potential security breaches occur. This resolves the contradiction by maintaining data availability during the authorized time period while automatically eliminating security risks afterward.
Solution Approach 2:
The data loss prevention system operates autonomously by self-managing the deletion process without requiring continuous user input or manual monitoring. The system automatically detects when data should be deleted based on stored policies, initiates deletion processes, and monitors compliance, thereby resolving the contradiction between maintaining data accessibility and ensuring security through automated management.
2Object-affected harmful factors
If data deletion is performed immediately after access, then data security is improved, but user convenience deteriorates due to loss of access to previously downloaded data
Solution Approach 1:
The system dynamically adjusts data retention based on time-based policies rather than applying static permanent storage or immediate deletion. Data is retained during the authorized access period and automatically deleted afterward, creating a dynamic lifecycle that balances security requirements with user convenience. This resolves the contradiction by providing flexible time-bound access rather than permanent availability or immediate removal.
3Reliability
If policy-based data scanning and encryption are implemented, then data loss prevention is improved, but system resource consumption increases
Solution Approach 1:
The system extracts the core function of data loss prevention from complex continuous scanning and encryption processes, isolating it to a simpler time-based deletion mechanism. By removing the need for ongoing resource-intensive monitoring and encryption, the system maintains effective data loss prevention through automated deletion while significantly reducing resource consumption. This resolves the contradiction by simplifying the prevention mechanism while maintaining its effectiveness.
Data Source
AI summary
A data access policy is configured and stored on a computing device, including a list of secure gateway IP addresses and optionally secure geographic regions. A time parameter defines how long a digital file will remain not in use before deletion and a degree parameter defines how fast the file will be deleted. Once a digital file is downloaded to the computing device the device is checked periodically to determine whether or not it is in a secure location. If not in a secure location then a data deletion process is initiated which begins by checking whether or not the digital file is currently being used on the computing device. If the file is being used, then no deletion is performed. If the file is not in use (or has not been used after a certain amount of time) then the file is deleted. The file may be deleted gradually.


