Context-Aware On-Device Data Protection via Key Deletion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection methods for mobile devices are inadequate as they require network access to prevent data theft or loss, and users may not be aware of risks in their environment, making them vulnerable to data leakage or unauthorized access.

Innovation Solution

A trusted software agent on the mobile device monitors sensor data and user interaction to determine the context, selectively encrypting data and deleting the decryption key when a negative context is detected, ensuring that even if data is accessed by adversaries, it remains inaccessible due to lack of decryption capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network-based remote wiping is used to protect data, then data can be protected when device is accessible through network, but data protection fails when device is disconnected from network

Engineering Contradiction:
Improvedata protection reliabilityVSAvoiddata protection effectiveness across different network conditions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by pre-configuring multiple data protection mechanisms (local encryption, key management, context monitoring) that are ready to execute autonomously without requiring network access. This allows the device to proactively protect data before network disconnection occurs, rather than relying on reactive remote wiping that fails offline.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device implements self-service data protection by autonomously monitoring its own context (location, sensors, usage patterns) and automatically executing protection actions (key deletion, data encryption) without external network commands. This self-sufficient approach ensures continuous protection regardless of network availability.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If user discretion is relied upon to prevent data leakage, then user awareness is required, but data protection fails when user is unaware of environmental risks

Engineering Contradiction:
Improveuser control over data protectionVSAvoiddata protection consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system continuously monitors device context (geolocation, sensors, usage patterns) and provides feedback to automatically adjust protection levels. This closed-loop approach replaces unreliable user discretion with automated decision-making based on real-time environmental assessment, ensuring consistent protection without requiring user awareness of risks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces the mechanical system of user judgment and manual intervention with an automated electronic system that monitors context and executes protection actions. This substitution eliminates human limitations (unawareness, distraction) while maintaining ease of operation through automatic execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If encryption keys are stored on device for data access, then data accessibility is improved, but data security deteriorates when device is compromised

Engineering Contradiction:
Improvedata accessibilityVSAvoidvulnerability to device compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts key storage and accessibility based on real-time context assessment. Keys are made accessible when context is safe (trusted location, proper authentication) and deleted or rendered inaccessible when context becomes negative (device theft detected, unauthorized access attempts). This dynamic approach balances accessibility and security adaptively.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the state of encryption keys from permanently stored to conditionally accessible based on context parameters (location, time, authentication status). When context parameters indicate risk, the key's accessibility parameter is changed by deleting it from the device, thereby altering the security state without affecting the encrypted data itself.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10528748B2Context-driven on-device data protection
Publication Date: 2020.01.07 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10528748B2 patent drawing
  • US10528748B2 patent drawing
  • US10528748B2 patent drawing

AI summary

An approach is provided that provides data protection in a mobile device. The approach monitors a set of sensor data at the mobile device to determine a current context of the mobile device. Sensor data can include data pertaining to the external environment as well as to the user's current interaction with the device. In response to determining a negative current context of the mobile device, the approach deletes an encryption/decryption key from the mobile device rendering the encrypted data on the device inaccessible to malevolent users and data thieves.