Coerced Encryption for Connected Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for coercing users to encrypt sensitive data on personal computing devices are inefficient and unreliable, as disk encryption is often optional and may be manually configured or disabled, leading to limited compliance and increased risk of data breaches due to lost or stolen devices.

Innovation Solution

Implementing a method that requires disk encryption on personal computing devices before allowing synchronization updates, by determining the encryption status of the device and withholding updates if encryption is not enabled, and providing user interfaces for administrators and users to configure and enforce disk encryption policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If disk encryption is made optional and manually configured, then ease of operation is improved, but reliability of data protection deteriorates

Engineering Contradiction:
Improveease of configurationVSAvoidcompliance with encryption policy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system automatically configures disk encryption on portable computing devices without requiring manual user intervention. The encryption software is deployed and activated automatically, with the system self-managing the encryption configuration, key management, and policy enforcement across the device fleet.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors the encryption status of portable computing devices and provides feedback to administrators about compliance levels. The system can detect when encryption is disabled or devices are lost, and automatically responds by revoking access or alerting administrators to maintain policy compliance.

Inventive Principle:
Principle #23Feedback

2Manufacturing precision

If manual configuration of disk encryption is required, then manufacturing precision is improved, but productivity deteriorates

Engineering Contradiction:
Improveencryption configuration accuracyVSAvoiddevice deployment efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system pre-configures encryption settings and policies before devices are deployed to users. Encryption is automatically activated and configured during device provisioning, eliminating the need for post-deployment manual configuration and ensuring consistent encryption implementation across all devices from the outset.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically handles the entire encryption configuration process including key generation, policy application, and device enrollment without requiring IT administrator intervention for each individual device, thereby maintaining configuration accuracy while dramatically improving deployment speed.

Inventive Principle:
Principle #25Self-service

3Reliability

If disk encryption is enforced through IT department manual configuration, then reliability of data protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata protection enforcementVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system provides a unified encryption management platform that handles multiple functions including device enrollment, policy configuration, key management, status monitoring, and compliance enforcement through a single automated system, eliminating the need for separate manual processes and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3606012B1Coerced encryption on connected devices
Publication Date: 2022.03.09 DROPBOX INC
  • EP3606012B1 patent drawingFigure 1
  • EP3606012B1 patent drawingFigure 2
  • EP3606012B1 patent drawingFigure 3

AI summary

Techniques for coercing users to encrypt synchronized content stored at their personal computing devices. In some aspects, one or more computing devices receive, from a personal computing device, an indication of whether data stored in at least a portion of a storage device of the personal computing device is protected by disk encryption. In response to determining, based on the indication, that the portion of the storage device is not protected by encryption, synchronization data for synchronizing a copy of one or more synchronized content items stored in the portion of the storage device with another copy of the synchronized content items stored at one or more server computing devices is withheld from the personal computing device until disk encryption on the personal computing device is enabled so as to coerce the user to enable disk encryption on the personal computing device.