Local Sensitive Data Security via Risk Scoring and App Similarity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively secure sensitive user data stored locally by web applications from unauthorized access while maintaining user convenience, as current security measures are often cumbersome and poorly implemented.

Innovation Solution

A system comprising a user device with a processor and memory, configured to identify sensitive data, determine a risk exposure score, and apply a security policy to restrict access based on similarity between applications, ensuring secure storage and access control for sensitive user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If sensitive user data is stored locally by applications to improve efficiency and user experience, then productivity and ease of operation are improved, but security and protection from unauthorized access deteriorate

Engineering Contradiction:
Improveapplication efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments access control by identifying and classifying different types of sensitive data (e.g., login credentials, financial information, health data) and applying distinct security policies to each segment based on its sensitivity level and the relationship between applications, thereby enabling efficient local storage while maintaining targeted security protection

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces a security manager as an intermediary component that mediates between applications and sensitive data. This security manager evaluates access requests by determining risk exposure scores and assessing application relationships, acting as a gatekeeper that allows convenient data access while preventing unauthorized access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policies are applied to restrict access to sensitive data, then data security is improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service security where the security manager automatically evaluates access requests, determines risk exposure scores, and enforces security policies without requiring user intervention. The system autonomously assesses application relationships and makes access decisions, maintaining strong security while eliminating the need for users to manually configure security settings

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes security parameters based on the risk exposure score and application relationship assessment. Access policies are adjusted parameterically based on the specific data type, the requesting application's relationship to the data-owning application, and the calculated risk level, allowing flexible security that adapts to different scenarios without affecting user convenience

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access control mechanisms are implemented to prevent unauthorized access, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security manager serves as a universal access control mechanism that handles multiple types of sensitive data (login credentials, financial information, health data, etc.) through a single unified system. It provides multi-functional capabilities including risk assessment, application relationship evaluation, and policy enforcement, reducing overall system complexity by consolidating security functions

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11610020B2Securing sensitive user data stored locally by an application
Publication Date: 2023.03.21 MCAFEE LLC
  • US11610020B2 patent drawing
  • US11610020B2 patent drawing
  • US11610020B2 patent drawing

AI summary

An apparatus, related devices and methods, having a memory element operable to store instructions; and a processor operable to execute the instructions, such that the apparatus is configured to identify sensitive user data stored in the memory by a first application, determine a risk exposure score for the sensitive user data, apply, based on a determination that the risk exposure score is above a threshold, a security policy to restrict access to the sensitive user data, receive a request from a second application to access the sensitive user data, determine whether the first application and the second application are similar applications, and allow access based on a determination that the first application and the second application are similar applications.