Guest Account for Lost Device Recovery and Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting lost or stolen data processing systems, such as laptops or cellular telephones, lack effective mechanisms to securely locate, recover, or erase data, and often rely on encryption or remotely controlled erase mechanisms that may not sufficiently deter unauthorized access.
Innovation Solution
Implementing a guest account feature that allows network access and enables actions like determining the device's location, erasing data, or displaying a return message, while preventing unauthorized access, using a dual-partition storage system with a recovery partition for data restoration and encryption for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption of storage devices is used to protect data, then data security is improved, but unauthorized access cannot be prevented and system recovery becomes difficult
Solution Approach 1:
The storage device is divided into multiple partitions: a first partition containing the operating system and user data, and a second partition containing a guest account with recovery capabilities. This segmentation allows the system to maintain encryption for data protection while providing a separate recovery pathway that bypasses encryption barriers.
Solution Approach 2:
A guest account is introduced as an intermediary mechanism that can access the system independently of the encrypted user account. This guest account serves as a mediator that can perform recovery operations, locate the system, or erase data without requiring decryption of the main user partition.
2Reliability
If remote erase mechanisms are implemented, then data protection is improved, but system location tracking and recovery capabilities are limited
Solution Approach 1:
The guest account is designed with multi-functionality, capable of performing multiple actions including determining system location, erasing data, displaying return messages, and capturing user images. This universal approach replaces the need for separate specialized mechanisms for each protection and recovery function.
Solution Approach 2:
The system implements feedback mechanisms where the guest account can determine and transmit location information to the authorized user, and can capture images of users attempting to access the system. This feedback loop enables the authorized user to make informed decisions about whether to erase data or attempt recovery.
3Adaptability or versatility
If a guest account with network access is enabled, then system location and recovery actions are improved, but unauthorized access risk increases
Solution Approach 1:
The guest account is configured with specific localized permissions and restrictions. It has network access enabled for location tracking and receiving commands, but its ability to access or modify data on the first partition is restricted. This local quality approach allows the guest account to perform necessary recovery functions while minimizing unauthorized access risk.
Solution Approach 2:
The system preemptively addresses unauthorized access risks by implementing security measures within the guest account configuration. These include restricted data access permissions, encrypted communication channels for network access, and the ability to lock out other user accounts after a specified period, thereby preventing potential harm before it can occur.
Data Source
AI summary
In one embodiment, a data processing system includes a guest account that is configured to assist in the protection and recovery of the data processing system when it is lost or stolen. In one embodiment, the guest account can allow Internet access and can include a web browser to allow the guest, who might be a thief, to use the system to browse the Internet. While such use occurs, the system can perform actions specified by an authorized user of the system, and such actions can include determining a location of the system and transmitting the location to the authorized user, erasing data on the system, displaying a message, capturing an image, etc.


