Intelligent Security System for Selective Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate data stored on mobile devices is at risk due to insufficient encryption, making it vulnerable to hacker attacks and non-compliant with regulatory requirements, while existing security measures can cause system instability and are difficult to manage centrally.
Innovation Solution
A method and system for intelligent encryption and filtering that dynamically updates security rules, securely stores user credentials, and encrypts data based on specific attributes and file operations, allowing for fine-grain control and centralized management without affecting system stability or requiring OS encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted to protect sensitive information, then security is improved, but system stability deteriorates due to potential corruption of encrypted OS or program files
Solution Approach 1:
The patent applies encryption selectively to specific data files containing sensitive information rather than encrypting the entire operating system or all program files. This localized approach protects sensitive data while avoiding corruption risks to critical system files, thereby maintaining system stability while improving data security.
Solution Approach 2:
The patent segments data into protected (sensitive) and unprotected (non-sensitive) categories, applying encryption only to the sensitive portion. This segmentation allows the system to secure critical information without compromising the stability of non-sensitive system operations.
2Reliability
If encryption is applied to all data files, then security is improved, but productivity deteriorates due to system instability and boot failures
Solution Approach 1:
The patent implements encryption only for specific sensitive data files rather than all files, preventing system instability that would cause boot failures and ensuring continuous productivity while maintaining security for critical information.
3Ease of operation
If user credentials are stored in customary locations for easy access, then ease of operation is improved, but security deteriorates due to vulnerability to theft and unauthorized access
Solution Approach 1:
The patent extracts user credentials from their customary storage location and stores them in a secure, protected location. The credentials are restored to the customary location only when needed by applications, minimizing exposure time and protecting against theft while maintaining operational functionality.
Solution Approach 2:
The patent preliminarily secures credentials in a protected state before they are needed, and only restores them temporarily when required. This preliminary protective measure ensures security is maintained while allowing access when necessary.
4Reliability
If encryption parameters are changed to improve security, then security is improved, but ease of operation deteriorates due to difficulty in physical access to each device
Solution Approach 1:
The patent implements a centralized management system that can remotely update encryption parameters across multiple devices simultaneously. This universal approach allows security parameters to be changed system-wide without requiring physical access to each individual device, maintaining both security and ease of operation.
Solution Approach 2:
The patent employs a centralized management system that receives feedback from multiple devices and can push parameter updates remotely. This feedback mechanism enables efficient parameter management across the device fleet without requiring physical access to each device.
Data Source
AI summary
Included in the present disclosure are a system, method and program of instructions operable to protect vital information by combining information about a user and what they are allowed to see with information about essential files that need to be protected on an information handling system. Using intelligent security rules, essential information may be encrypted without encrypting the entire operating system or application files. According to aspects of the present disclosure, shared data, user data, temporary files, paging files, the password hash that is stored in the registry, and data stored on removable media may be protected.


