Dynamic Tagging for Corporate Data Security on Mixed Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing trend of personal and work devices blurring boundaries poses security risks as companies struggle to manage and protect corporate data on mixed-use devices, where personal and corporate data are not clearly separated, leading to potential data breaches and loss of control over sensitive information.

Innovation Solution

A system that employs a tagging component to attach knowledge tags to information resources, enabling access control by determining attributes and applying policies to restrict access based on the context, ensuring secure sharing between workspaces, even when data is transferred across different locations or devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees use personally owned devices to access corporate resources, then productivity increases and cost savings are achieved, but security risks and data protection challenges increase

Engineering Contradiction:
Improveemployee productivityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments data into corporate and personal data containers on mixed-use devices. Corporate data is isolated in a protected container that enforces access controls, while personal data remains accessible. This segmentation allows employees to use personal devices for productivity while maintaining security boundaries that prevent unauthorized access to corporate information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary data loss prevention system that mediates between corporate resources and personal devices. This intermediary layer monitors and controls data access, applying policies that allow legitimate business use while blocking potential security threats. The intermediary enables productivity by allowing authorized access while protecting against security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is made accessible across multiple devices and locations, then usability and collaboration improve, but control over sensitive information decreases

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata control management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements universal data protection policies that function across multiple devices, locations, and data types. A single policy framework applies to all corporate data regardless of where it is accessed or stored, simplifying control management while maintaining accessibility. The same protection mechanisms work on personal devices, corporate devices, cloud storage, and local systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system provides continuous feedback about data access, policy compliance, and security status across the organization. When data is accessed on any device, the system monitors the interaction and provides real-time feedback to enforce policies. This feedback mechanism maintains control over sensitive information while allowing broad accessibility, as users receive immediate guidance on what actions are permitted.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If devices are frequently upgraded and replaced, then technological capabilities improve, but data tracking and security control become more difficult

Engineering Contradiction:
Improvedevice upgrade capabilityVSAvoiddata tracking
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent applies data protection tags and security attributes to information before it leaves the corporate environment. These preliminary markings are embedded in the data itself, so when devices are upgraded or replaced, the tracking information travels with the data rather than being tied to specific hardware. This preliminary action ensures continuous data tracking regardless of device changes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates virtual copies of corporate data in protected containers on personal devices, rather than transferring actual ownership or physical control. When devices are upgraded, the data protection attributes are copied to the new device, maintaining security controls. The original data remains protected on corporate systems, providing redundancy and continuous trackability.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2791826B1Personal space (DATA) v. corporate space (DATA)
Publication Date: 2017.11.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2791826B1 patent drawingFigure 1
  • EP2791826B1 patent drawingFigure 2
  • EP2791826B1 patent drawingFigure 3

AI summary

Data management techniques are provided for handling information resources. A data management process can account for attributes of information resources by analyzing or interpreting the workspace location, source, channel and device associated with an information resource, and effectuating policies, based on the attributes. Rules govern the attribute determination and policies for access restriction to the information resource. The attributes and policies determined are tagged to the information resource and is dynamically updated based on the attributes related to the information resource within different workspaces, such as a corporate workspace and a personal workspace.