Device Status Token for Dynamic Data Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in preventing data leakage when mobile workers and external partners access corporate resources from unmanaged devices or unverified network locations, as completely blocking access can hinder functionality, while relaxed policies may lead to data security breaches.

Innovation Solution

A device management service token is used to detect the status of client devices and connections, enabling an applicable data protection policy to be determined and transmitted to client applications, which disables user interface controls such as downloading, synchronizing, or printing to prevent data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to organizational data is completely blocked on unmanaged devices or unverified network locations, then data security is improved, but functionality and user access are worsened

Engineering Contradiction:
Improvedata securityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing different access control policies based on device type and network location. Managed devices receive full access permissions while unmanaged devices receive restricted access. This allows the system to tailor security measures to specific contexts rather than applying a uniform block, thus maintaining data security while preserving necessary user functionality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic access control where permissions are adjusted in real-time based on device status and network location. The system dynamically evaluates whether a device is managed or unmanaged and whether the network location is verified, then dynamically applies appropriate restrictions. This dynamic approach allows users to access data when safe (improving ease of operation) while automatically blocking access when security risks are detected (maintaining data security).

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If relaxed access policies are applied to unmanaged devices or unverified network locations, then user functionality is improved, but data leakage risk is worsened

Engineering Contradiction:
Improveuser functionalityVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by proactively disabling download, sync, and print controls in the user interface before data leakage can occur. When an unmanaged device or unverified network location is detected, the system preemptively removes the ability to download, synchronize, or print organizational data. This prevents the harmful action of data leakage before it can happen, while still allowing users to view and interact with data in the application (maintaining functionality).

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary layer of control between the user and the data operations. Instead of allowing direct access to download, sync, and print functions, the system inserts a security checkpoint that evaluates device and network status. This intermediary mechanism mediates between user functionality needs and security concerns, enabling viewing and interaction while blocking potentially harmful data extraction operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If download, sync, and print controls are disabled to prevent data leakage, then data security is improved, but user interface functionality is worsened

Engineering Contradiction:
Improvedata securityVSAvoiduser interface functionality
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by dynamically modifying the state of user interface controls based on security context. When security risks are detected (unmanaged device or unverified network), the system changes the parameter state of download, sync, and print controls from enabled to disabled. This parameter change approach maintains data security while preserving the visual appearance and basic functionality of the user interface, affecting only specific operational parameters rather than the entire interface structure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11625469B2Prevention of organizational data leakage across platforms based on device status
Publication Date: 2023.04.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11625469B2 patent drawing
  • US11625469B2 patent drawing
  • US11625469B2 patent drawing

AI summary

Technologies are provided for prevention of organizational data leakage across platforms based on device status. A device management service may include status information for a client device and/or a connection in a token provided to the client device and update the status in response to changes. An applicable data protection policy may be determined based on the detected status and optionally based on data being accessed. An instruction may be transmitted to a client application executed on the client device based on the applicable data protection policy thereby enforcing the data protection policy at the server. The instruction may cause a script executed at the client application to disable one or more user interface controls associated with functionality such as downloading, synchronizing, printing, etc. of the organizational data to prevent leakage of organizational data.