Device Access Token Management for BYOD Data Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for terminating access to company networks from personal devices are overly restrictive and destructive, often resulting in loss of personal data when an employee leaves or loses their device, as they require wiping or factory resetting, which is undesirable and lacks flexibility.

Innovation Solution

A system and method for registering, authenticating, and authorizing computing devices to access network resources using a server that generates tokens with a time-to-live, allowing for secure and flexible management of access without deleting personal data, enabling administrators to disable specific applications or devices without modifying device data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods (remote wipe or factory reset) are used to terminate access to company networks from personal devices, then security is improved, but personal data is lost

Engineering Contradiction:
ImprovesecurityVSAvoidpersonal data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the device into company-managed portions and personal portions. The company can only manage and secure its own data and applications, while personal data remains separate and protected from company management actions. This is achieved through containerization or virtualization techniques that create isolated environments for company resources on personal devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary management layer that sits between the company's network resources and the personal device. This intermediary enables secure access control and data protection without requiring direct manipulation of the personal device's entire filesystem, thus preventing unnecessary data loss while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote wipe or factory reset is performed to secure company networks, then access control is improved, but device usability is worsened

Engineering Contradiction:
Improveaccess controlVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

By segmenting company resources from personal data, the patent enables selective management actions. The company can disable or remove only company-related applications and data without affecting personal data or device functionality, thus maintaining access control while preserving device usability for personal purposes.

Inventive Principle:
Principle #1Segmentation

3Reliability

If company data is separated from personal data on personal devices, then data protection is improved, but device complexity is worsened

Engineering Contradiction:
Improvedata protectionVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs universal containerization or virtualization technologies that can be applied across different device types and operating systems. These technologies provide automated data separation and management capabilities without requiring complex custom implementations for each device, thus achieving data protection while minimizing the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10897464B2Device registration, authentication, and authorization system and method
Publication Date: 2021.01.19 LEVEL 3 COMMUNICATIONS LLC
  • US10897464B2 patent drawing
  • US10897464B2 patent drawing
  • US10897464B2 patent drawing

AI summary

A system includes one or more processors to receive a registration request, the registration request comprising a representation of a username and a password, verify the username and the password and transmit a one-time-use password, receive the one-time-use password and first device identifier information from a mobile computing device, receive an access request from the mobile computing device comprising the representation of the username and the password, second device identifier information, and application key information, verify the username, the password, the second device identifier information, and the application key information, and transmit a token to the mobile computing device, and receive a resource request from the mobile computing device comprising the token and third device identifier information.