Data-Specific Security Policies for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile computing devices pose security threats as they often access both personal and enterprise data, with existing security policies being overly restrictive, affecting usability and not allowing for granular control over specific data types.

Innovation Solution

Implementing security policies that are applied specifically to individual data types, allowing for varying password requirements, selective caching, temporary storage, and pre-defined conditions for data access and erasure, enabling users to set access policies for personal data without compromising enterprise security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all-or-nothing security policies are applied to entire devices, then enterprise data security is improved, but personal data usability deteriorates

Engineering Contradiction:
Improveenterprise data securityVSAvoidpersonal data usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments security policies from device-wide applications to data-specific applications. Instead of applying security policies to the entire mobile device, the system divides policies into data-specific segments that can be independently applied to different data types (enterprise data vs. personal data). This allows enterprise data to have strict security policies while personal data maintains easier access, resolving the contradiction between security and usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security characteristics to different data types within the same device. Enterprise data receives high-security characteristics (authentication requirements, encryption), while personal data receives lower-security characteristics (easier access). This localized approach to security quality allows the system to maintain strong enterprise security without compromising personal data usability.

Inventive Principle:
Principle #3Local quality

2Reliability

If strict security policies are enforced on mobile devices, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity policy complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reduces device complexity by segmenting security policies into manageable, data-specific units rather than implementing complex device-wide policies. Each data type has its own simplified policy definition, making the overall system easier to manage and configure while maintaining strong security where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service by allowing users to define and configure their own data-specific security policies without requiring complex centralized management. Users can independently set authentication requirements and access controls for different data types, reducing the complexity burden on both the device and administrators.

Inventive Principle:
Principle #25Self-service

3Reliability

If data access is restricted to secure networks only, then security is improved, but adaptability deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddata access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing different network security requirements for different data types. Enterprise data can be configured to require secure network connections (enterprise intranet, VPN), while personal data allows access from any network (including unsecure public Wi-Fi). This localized approach maintains security for sensitive data while providing adaptability for personal usage scenarios.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements dynamics by allowing network security requirements to be dynamically configured per data type rather than being fixed device-wide. Users can adjust network access policies based on their current needs and environment, enabling the system to adapt between strict security modes (for enterprise data) and flexible access modes (for personal data).

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2756445B1Securing data usage in computing devices
Publication Date: 2019.04.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2756445B1 patent drawingFigure 1
  • EP2756445B1 patent drawingFigure 2
  • EP2756445B1 patent drawingFigure 3

AI summary

Policies are applied to specific data rather than to an entire computing device that contains the specific data. Access to the specific data is controlled by the policies utilizing various password or other authentication credential requirements, selective data caching, data transmission, temporary data storage, and/or pre-defined conditions under which the specific data is to be erased or rendered inaccessible. Policies may be defined by an administrator and pushed to a mobile computing device, whereat the policies are enforced.