Data-Specific Security Policies for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile computing devices pose security threats as they often access both personal and enterprise data, with existing security policies being overly restrictive, affecting usability and not allowing for granular control over specific data types.
Innovation Solution
Implementing security policies that are applied specifically to individual data types, allowing for varying password requirements, selective caching, temporary storage, and pre-defined conditions for data access and erasure, enabling users to set access policies for personal data without compromising enterprise security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all-or-nothing security policies are applied to entire devices, then enterprise data security is improved, but personal data usability deteriorates
Solution Approach 1:
The patent segments security policies from device-wide applications to data-specific applications. Instead of applying security policies to the entire mobile device, the system divides policies into data-specific segments that can be independently applied to different data types (enterprise data vs. personal data). This allows enterprise data to have strict security policies while personal data maintains easier access, resolving the contradiction between security and usability.
Solution Approach 2:
The patent implements local quality by applying different security characteristics to different data types within the same device. Enterprise data receives high-security characteristics (authentication requirements, encryption), while personal data receives lower-security characteristics (easier access). This localized approach to security quality allows the system to maintain strong enterprise security without compromising personal data usability.
2Reliability
If strict security policies are enforced on mobile devices, then data security is improved, but device complexity increases
Solution Approach 1:
The patent reduces device complexity by segmenting security policies into manageable, data-specific units rather than implementing complex device-wide policies. Each data type has its own simplified policy definition, making the overall system easier to manage and configure while maintaining strong security where needed.
Solution Approach 2:
The system enables self-service by allowing users to define and configure their own data-specific security policies without requiring complex centralized management. Users can independently set authentication requirements and access controls for different data types, reducing the complexity burden on both the device and administrators.
3Reliability
If data access is restricted to secure networks only, then security is improved, but adaptability deteriorates
Solution Approach 1:
The patent applies local quality by implementing different network security requirements for different data types. Enterprise data can be configured to require secure network connections (enterprise intranet, VPN), while personal data allows access from any network (including unsecure public Wi-Fi). This localized approach maintains security for sensitive data while providing adaptability for personal usage scenarios.
Solution Approach 2:
The system implements dynamics by allowing network security requirements to be dynamically configured per data type rather than being fixed device-wide. Users can adjust network access policies based on their current needs and environment, enabling the system to adapt between strict security modes (for enterprise data) and flexible access modes (for personal data).
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Policies are applied to specific data rather than to an entire computing device that contains the specific data. Access to the specific data is controlled by the policies utilizing various password or other authentication credential requirements, selective data caching, data transmission, temporary data storage, and/or pre-defined conditions under which the specific data is to be erased or rendered inaccessible. Policies may be defined by an administrator and pushed to a mobile computing device, whereat the policies are enforced.