Cloud-Endpoint Data Deletion for Unsecured Location Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention technologies face challenges in securely managing sensitive information, particularly in ensuring its deletion from devices when accessed in unsecure locations, and resource-intensive encryption methods are not always viable.

Innovation Solution

A cloud-endpoint model with automatic data deletion is implemented, where sensitive data is stored in the cloud and deleted after a certain time interval if not used, with periodic checks using GPS or gateway IP addresses to determine secure locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored on endpoint devices for user access, then data availability is improved, but data security deteriorates due to risk of loss, theft, or unauthorized access

Engineering Contradiction:
Improvedata availabilityVSAvoiddata security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by automatically deleting sensitive data from endpoint devices after a predetermined time interval without user intervention. The deletion process is initiated in advance based on policy rules, ensuring that data is removed before potential security breaches occur. This resolves the contradiction by maintaining data availability during the authorized time period while automatically eliminating security risks afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data loss prevention system operates autonomously by self-managing the deletion process without requiring continuous user input or manual monitoring. The system automatically detects when data should be deleted based on stored policies, initiates deletion processes, and monitors compliance, thereby resolving the contradiction between maintaining data accessibility and ensuring security through automated management.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If data deletion is performed immediately after access, then data security is improved, but user convenience deteriorates due to loss of access to previously downloaded data

Engineering Contradiction:
Improvedata securityVSAvoiduser access convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically adjusts data retention based on time-based policies rather than applying static permanent storage or immediate deletion. Data is retained during the authorized access period and automatically deleted afterward, creating a dynamic lifecycle that balances security requirements with user convenience. This resolves the contradiction by providing flexible time-bound access rather than permanent availability or immediate removal.

Inventive Principle:
Principle #15Dynamics

3Reliability

If policy-based data scanning and encryption are implemented, then data loss prevention is improved, but system resource consumption increases

Engineering Contradiction:
Improvedata loss preventionVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system extracts the core function of data loss prevention from complex continuous scanning and encryption processes, isolating it to a simpler time-based deletion mechanism. By removing the need for ongoing resource-intensive monitoring and encryption, the system maintains effective data loss prevention through automated deletion while significantly reducing resource consumption. This resolves the contradiction by simplifying the prevention mechanism while maintaining its effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8805956B1Data leakage prevention in cloud-endpoint model
Publication Date: 2014.08.12 TREND MICRO INC
  • US8805956B1 patent drawing
  • US8805956B1 patent drawing
  • US8805956B1 patent drawing

AI summary

A data access policy is configured and stored on a computing device, including a list of secure gateway IP addresses and optionally secure geographic regions. A time parameter defines how long a digital file will remain not in use before deletion and a degree parameter defines how fast the file will be deleted. Once a digital file is downloaded to the computing device the device is checked periodically to determine whether or not it is in a secure location. If not in a secure location then a data deletion process is initiated which begins by checking whether or not the digital file is currently being used on the computing device. If the file is being used, then no deletion is performed. If the file is not in use (or has not been used after a certain amount of time) then the file is deleted. The file may be deleted gradually.