Selective Enterprise Data Backup and Wipe Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In an enterprise setting, there is a risk of unauthorized access to confidential data when old client devices are discarded or replaced, as enterprise data is not adequately controlled, leading to potential exposure of sensitive information.

Innovation Solution

A system that enables a client device to perform a backup of enterprise data and subsequently wipe it, with the backup communicated to a computing environment over a network, ensuring that only enterprise data associated with predefined criteria is removed, while personal data is retained.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If enterprise data is stored locally on mobile devices for enterprise application use, then data accessibility and application functionality are improved, but security risk increases when devices are discarded or replaced

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments data into enterprise data and personal data, applying different management policies to each. Enterprise data is subject to backup and wipe operations, while personal data is preserved, allowing selective control over data lifecycle

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs backup of enterprise data to a server before wiping it from the device. This preliminary action ensures data is secured elsewhere before removal, eliminating security risks while maintaining accessibility during the backup process

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If all data is wiped from old devices during replacement, then security risk is reduced, but loss of enterprise data occurs without proper backup

Engineering Contradiction:
Improvesecurity riskVSAvoidenterprise data loss
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system performs backup of enterprise data to a server before wiping it from the device. This preliminary action ensures data is secured elsewhere before removal, eliminating security risks while maintaining accessibility during the backup process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback mechanisms to confirm backup completion and data integrity before wipe operations proceed. This ensures enterprise data is successfully transferred and verified before permanent removal from the device

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If enterprise data is selectively wiped while retaining personal data, then data privacy is improved, but device complexity increases

Engineering Contradiction:
Improvedata privacy protectionVSAvoiddata management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system segments data into enterprise data and personal data, applying different management policies to each. Enterprise data is subject to backup and wipe operations, while personal data is preserved, allowing selective control over data lifecycle

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism (device management service) that automatically identifies and separates enterprise data from personal data based on predefined criteria, simplifying the complexity of selective data management

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10956383B2Device backup and wipe
Publication Date: 2021.03.23 OMNISSA LLC
  • US10956383B2 patent drawing
  • US10956383B2 patent drawing
  • US10956383B2 patent drawing

AI summary

Disclosed are various embodiments for performing a backup a device and/or performing a wipe or removal of data from a device enrolled with a device management service. In various embodiments, a wipe request is generated by a management service and transmitted to a client device. The wipe request includes commands to backup enterprise data for a particular application, verify that the management service has received the enterprise data, and remove the enterprise data from the client device. The management service determines that the enterprise data is received from the client device and transmits a confirmation that the management service has received the enterprise data. The confirmation causes the client device to remove the enterprise data from the client device.