Guest Account for Lost Device Recovery and Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting lost or stolen data processing systems, such as laptops or cellular telephones, lack effective mechanisms to securely locate, recover, or erase data, and often rely on encryption or remotely controlled erase mechanisms that may not sufficiently deter unauthorized access.

Innovation Solution

Implementing a guest account feature that allows network access and enables actions like determining the device's location, erasing data, or displaying a return message, while preventing unauthorized access, using a dual-partition storage system with a recovery partition for data restoration and encryption for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption of storage devices is used to protect data, then data security is improved, but unauthorized access cannot be prevented and system recovery becomes difficult

Engineering Contradiction:
Improvedata securityVSAvoidsystem recovery
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The storage device is divided into multiple partitions: a first partition containing the operating system and user data, and a second partition containing a guest account with recovery capabilities. This segmentation allows the system to maintain encryption for data protection while providing a separate recovery pathway that bypasses encryption barriers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A guest account is introduced as an intermediary mechanism that can access the system independently of the encrypted user account. This guest account serves as a mediator that can perform recovery operations, locate the system, or erase data without requiring decryption of the main user partition.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote erase mechanisms are implemented, then data protection is improved, but system location tracking and recovery capabilities are limited

Engineering Contradiction:
Improvedata protectionVSAvoidrecovery capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The guest account is designed with multi-functionality, capable of performing multiple actions including determining system location, erasing data, displaying return messages, and capturing user images. This universal approach replaces the need for separate specialized mechanisms for each protection and recovery function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements feedback mechanisms where the guest account can determine and transmit location information to the authorized user, and can capture images of users attempting to access the system. This feedback loop enables the authorized user to make informed decisions about whether to erase data or attempt recovery.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If a guest account with network access is enabled, then system location and recovery actions are improved, but unauthorized access risk increases

Engineering Contradiction:
Improverecovery actionsVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The guest account is configured with specific localized permissions and restrictions. It has network access enabled for location tracking and receiving commands, but its ability to access or modify data on the first partition is restricted. This local quality approach allows the guest account to perform necessary recovery functions while minimizing unauthorized access risk.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system preemptively addresses unauthorized access risks by implementing security measures within the guest account configuration. These include restricted data access permissions, encrypted communication channels for network access, and the ability to lock out other user accounts after a specified period, thereby preventing potential harm before it can occur.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10395068B2User account for system protection or recovery
Publication Date: 2019.08.27 APPLE INC
  • US10395068B2 patent drawing
  • US10395068B2 patent drawing
  • US10395068B2 patent drawing

AI summary

In one embodiment, a data processing system includes a guest account that is configured to assist in the protection and recovery of the data processing system when it is lost or stolen. In one embodiment, the guest account can allow Internet access and can include a web browser to allow the guest, who might be a thief, to use the system to browse the Internet. While such use occurs, the system can perform actions specified by an authorized user of the system, and such actions can include determining a location of the system and transmitting the location to the authorized user, erasing data on the system, displaying a message, capturing an image, etc.