Device Status Token for Dynamic Data Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in preventing data leakage when mobile workers and external partners access corporate resources from unmanaged devices or unverified network locations, as completely blocking access can hinder functionality, while relaxed policies may lead to data security breaches.
Innovation Solution
A device management service token is used to detect the status of client devices and connections, enabling an applicable data protection policy to be determined and transmitted to client applications, which disables user interface controls such as downloading, synchronizing, or printing to prevent data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access to organizational data is completely blocked on unmanaged devices or unverified network locations, then data security is improved, but functionality and user access are worsened
Solution Approach 1:
The patent applies local quality by implementing different access control policies based on device type and network location. Managed devices receive full access permissions while unmanaged devices receive restricted access. This allows the system to tailor security measures to specific contexts rather than applying a uniform block, thus maintaining data security while preserving necessary user functionality.
Solution Approach 2:
The patent implements dynamic access control where permissions are adjusted in real-time based on device status and network location. The system dynamically evaluates whether a device is managed or unmanaged and whether the network location is verified, then dynamically applies appropriate restrictions. This dynamic approach allows users to access data when safe (improving ease of operation) while automatically blocking access when security risks are detected (maintaining data security).
2Ease of operation
If relaxed access policies are applied to unmanaged devices or unverified network locations, then user functionality is improved, but data leakage risk is worsened
Solution Approach 1:
The patent applies preliminary anti-action by proactively disabling download, sync, and print controls in the user interface before data leakage can occur. When an unmanaged device or unverified network location is detected, the system preemptively removes the ability to download, synchronize, or print organizational data. This prevents the harmful action of data leakage before it can happen, while still allowing users to view and interact with data in the application (maintaining functionality).
Solution Approach 2:
The patent introduces an intermediary layer of control between the user and the data operations. Instead of allowing direct access to download, sync, and print functions, the system inserts a security checkpoint that evaluates device and network status. This intermediary mechanism mediates between user functionality needs and security concerns, enabling viewing and interaction while blocking potentially harmful data extraction operations.
3Reliability
If download, sync, and print controls are disabled to prevent data leakage, then data security is improved, but user interface functionality is worsened
Solution Approach 1:
The patent applies parameter changes by dynamically modifying the state of user interface controls based on security context. When security risks are detected (unmanaged device or unverified network), the system changes the parameter state of download, sync, and print controls from enabled to disabled. This parameter change approach maintains data security while preserving the visual appearance and basic functionality of the user interface, affecting only specific operational parameters rather than the entire interface structure.
Data Source
AI summary
Technologies are provided for prevention of organizational data leakage across platforms based on device status. A device management service may include status information for a client device and/or a connection in a token provided to the client device and update the status in response to changes. An applicable data protection policy may be determined based on the detected status and optionally based on data being accessed. An instruction may be transmitted to a client application executed on the client device based on the applicable data protection policy thereby enforcing the data protection policy at the server. The instruction may cause a script executed at the client application to disable one or more user interface controls associated with functionality such as downloading, synchronizing, printing, etc. of the organizational data to prevent leakage of organizational data.


