Conditional Access System for Secure Remote Application Data Deletion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote access to server-based applications poses security risks due to data remaining on public computers after user sessions, exacerbated by caching features in web browsers, with existing solutions being either user-dependent, unreliable, or limited in scope.

Innovation Solution

A conditional access system that downloads data-retention prevention code to remote access devices to automatically delete sensitive data from caches and directories, ensuring secure access to server-based applications by verifying the effectiveness of this code before granting access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual cache clearing is implemented, then data security is improved, but user convenience deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically detecting when a user session ends and autonomously clearing cache data without requiring user intervention. The conditional access application monitors session status and executes cache clearing operations automatically, eliminating the need for users to manually clear caches while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring automatic cache clearing mechanisms before security issues arise. The conditional access application is预先 installed and configured to automatically clear caches upon session termination, preventing potential security breaches before they can occur rather than requiring reactive manual clearing.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If server sends no-cache instructions, then data security is improved, but application functionality deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by implementing different cache management strategies for different applications and data types. Rather than universally disabling caching, the conditional access application selectively clears cache data based on session termination detection, allowing caching to benefit application performance while maintaining security for sensitive data.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamics by making cache management adaptive rather than static. The conditional access application dynamically adjusts cache behavior based on session status - allowing caching during active sessions for performance optimization, and automatically clearing caches when sessions terminate to maintain security.

Inventive Principle:
Principle #15Dynamics

3Reliability

If application-specific cache management is implemented, then data security is improved, but system complexity deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements universality by creating a multi-functional conditional access application that handles multiple security and management tasks through a single unified mechanism. The application detects session termination, manages cache clearing, and controls access across different applications and data types, eliminating the need for separate cache management systems for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The conditional access application serves as an intermediary layer between the user sessions and the cache system. It monitors session status and mediates cache operations, simplifying the overall system architecture by providing a single point of control rather than requiring complex integration between multiple application-specific cache management systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If automatic cache clearing is implemented, then data security is improved, but data retention capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata retention
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements periodic action by clearing cache data periodically based on session termination events rather than continuously or at fixed time intervals. The conditional access application detects when user sessions end and triggers cache clearing at these periodic moments, maintaining security while preserving cache data during active sessions for optimal performance.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS7801964B2System and method for providing conditional access to server-based applications from remote access devices
Publication Date: 2010.09.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7801964B2 patent drawing
  • US7801964B2 patent drawing
  • US7801964B2 patent drawing

AI summary

Systems and methods are provided for providing users at remote access devices with conditional access to server-based applications. Requests for access to server-based applications (e.g., requests to launch or obtain data associated with the server-based applications) by remote access devices may be prevented or allowed based on device compliance with one or more policies including whether data-retention prevention code can be downloaded to and operational on the remote access devices. The data-retention prevention code may be used to both determine whether data can be automatically deleted from a cache or file directory at the remote access device and to delete potentially retention-sensitive data once the data is downloaded to the remote access device from the server-based application.