Encrypted File Containers with TTL Access Rules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network-based file backup and sharing services pose security and regulatory compliance issues due to the risk of sensitive data being stored on unsecured mobile devices, which can be stolen, misplaced, or accessed by unauthorized users, leading to potential data breaches and costly penalties.
Innovation Solution
The implementation of encrypted file system element containers that are stored on a user's device in an encrypted state, with access rules such as time-to-live (TTL) settings and permissions controlling access, ensuring that data remains secure and compliant with regulations by limiting access and automatically deleting sensitive information when no longer needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive data is stored on mobile devices for convenient access, then ease of operation is improved, but security and reliability deteriorate due to device theft or unauthorized access
Solution Approach 1:
The system segments data into individual file containers, each with its own encryption and access controls. This allows selective access to specific files rather than requiring access to the entire file system, improving security while maintaining convenience.
Solution Approach 2:
The patent introduces an intermediary encryption layer between the user and the data. Files are encrypted using cryptographic keys that can be controlled through permission sets, acting as a mediator that allows authorized access while preventing unauthorized access even if the device is compromised.
2Reliability
If data is encrypted and stored locally, then security is improved, but ease of operation deteriorates due to access complexity
Solution Approach 1:
The system implements self-service through automated permission validation and key management. The permission sets automatically enforce access rules without requiring manual intervention from administrators, and cryptographic keys are managed automatically through the defined permission structures.
Solution Approach 2:
The patent implements dynamic access control through permission sets that can be modified without re-encrypting the underlying data. Access permissions can be changed, revoked, or granted programmatically, allowing flexible management of encrypted data while maintaining security.
3Reliability
If access controls and permission sets are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The permission set structure serves multiple functions: it defines cryptographic key access, establishes file access permissions, and controls data lifecycle management. This universal permission framework reduces the need for separate complex control mechanisms for each function.
Solution Approach 2:
The system performs preliminary encryption and permission assignment when files are uploaded or created. Access controls are established in advance through permission sets before any access attempts occur, simplifying the access control implementation rather than adding complexity during access operations.
4Ease of operation
If files are downloaded to local devices, then ease of operation is improved, but harmful factors increase due to potential data breaches and compliance violations
Solution Approach 1:
The system applies preliminary anti-action by encrypting files before they are accessed or downloaded to local devices. The encryption prevents unauthorized access and potential data breaches, while the permission sets ensure that only authorized users can access the decrypted data, thereby preventing compliance violations.
Solution Approach 2:
The patent implements short-living cryptographic sessions and temporary access tokens that are invalidated after use or after a defined period. This approach limits the window of opportunity for data breaches and reduces the long-term security risks associated with stored credentials or persistent access tokens.
Data Source
AI summary
Disclosed in some examples are methods, systems, and machine readable mediums which provide for encrypted file system element containers which secure sensitive file system elements. The encrypted file system element containers are sent from a network based file storage system upon selection of file system elements for a network based file download and stored in a user's computing device in an encrypted state while the data is at rest. An application on the user's computing device may provide access to the file system elements (e.g., files, directories, and the like) inside the encrypted file system element containers according to a set of one or more access rules. Example access rules include a time-to-live (TTL) rule that deletes or causes the encrypted file system element containers to be inaccessible after a predetermined amount of time.


