Context-Aware Data Access Control for BYOD Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing trend of Bring Your Own Device (BYOD) poses a risk of sensitive information being lost or misused due to the small size and portability of devices, which can be easily misplaced or stolen, leading to unauthorized access and data exposure.
Innovation Solution
Implementing a method and apparatus that utilize a security controller to context-switch between a user context and a secure context, controlling data accessibility based on location, user, and time through an identifier, which determines the appropriate data storage map, ensuring secure access and encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is made accessible on portable devices for employee use, then productivity and ease of operation are improved, but security and risk of unauthorized access deteriorate
Solution Approach 1:
The patent segments data storage into multiple distinct storage areas or partitions, each with different access permissions and security levels. This allows sensitive data to be separated from non-sensitive data, enabling employees to access only the data they need for their work while protecting critical information from unauthorized access.
Solution Approach 2:
The patent introduces an intermediary component (such as a security manager or access control mechanism) that mediates between the user and the data storage system. This intermediary enforces access policies based on user credentials, device state, and data classification, allowing legitimate access while blocking unauthorized access attempts.
2Ease of operation
If all data is made accessible to users, then ease of operation is improved, but loss of information and unauthorized access increase
Solution Approach 1:
The patent applies different access control policies and security measures to different portions of data based on their sensitivity and classification. Critical data receives stricter protection while non-critical data remains more accessible, optimizing both security and usability according to the specific needs of each data element.
Solution Approach 2:
The patent dynamically changes access parameters (such as permission levels, encryption keys, or access policies) based on contextual factors including user identity, device security state, location, and time. This allows the system to adapt access control in real-time, granting access when appropriate and blocking it when security risks are detected.
3Reliability
If data protection measures are strengthened, then security is improved, but device complexity and ease of operation worsen
Solution Approach 1:
The patent implements self-service security mechanisms that automatically perform security checks, policy enforcement, and access control decisions without requiring user intervention. The system autonomously manages security configurations, updates encryption keys, and enforces access policies, reducing the complexity burden on users while maintaining strong security.
Solution Approach 2:
The patent designs security components that perform multiple functions simultaneously, such as a security manager that handles authentication, authorization, encryption, and policy enforcement in a unified manner. This multi-functionality reduces the number of separate security mechanisms needed, thereby reducing overall system complexity while maintaining comprehensive security coverage.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer implemented method and apparatus for controlling the accessibility of data on a data storage (9) comprises obtaining an identifier, and determining dependent on the identifier, in a secure context (5) of a computer processor (1), whether to make data accessible in a user context (3). In the event that data is to be made accessible, access is provided to the data in the user context (3).