Conditional Data Sharing via Device Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data synchronization and sharing systems lack adequate security measures to protect sensitive data, potentially compromising its security by allowing devices with inadequate security to access shared data.

Innovation Solution

A method and system that assess the security level of client devices before allowing access to sensitive data, conditionally sharing data based on the device's security level, by identifying sensitive data and determining the security level of the device through analysis of its operating system and file synchronization and sharing application security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data synchronization and sharing systems allow access to shared data without security assessment, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improveease of data accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs security level assessment of client devices before allowing access to sensitive data. The security evaluation is conducted in advance by analyzing device security measures, operating system security settings, and application-level security configurations, thereby preventing unauthorized access while maintaining smooth operation for authenticated users

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security assessment of client devices is implemented before data sharing, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity assessment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server acts as an intermediary that performs security assessment on behalf of the data sharing system. The server evaluates client device security levels by analyzing security measures, operating system configurations, and application settings, then makes informed decisions about data access permissions, thereby simplifying the overall system architecture while maintaining strong security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security level assessment is performed on all devices, then data security is improved, but productivity decreases

Engineering Contradiction:
Improvedata securityVSAvoiddata sharing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different security assessment strategies based on the sensitivity of the data being shared. High-security assessments are performed only for sensitive data types, while less stringent or no assessment is applied to non-sensitive data, thereby maintaining high security for critical information while preserving overall system productivity

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10785227B2Implementing data security within a synchronization and sharing environment
Publication Date: 2020.09.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10785227B2 patent drawing
  • US10785227B2 patent drawing
  • US10785227B2 patent drawing

AI summary

A computer-implemented method according to one embodiment includes receiving a request to share predetermined data with a device, identifying the predetermined data as sensitive, calculating a current security level for the device, and conditionally sharing the predetermined data with the device, based on the current security level for the device.