Local Sensitive Data Security via Risk Scoring and App Similarity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively secure sensitive user data stored locally by web applications from unauthorized access while maintaining user convenience, as current security measures are often cumbersome and poorly implemented.
Innovation Solution
A system comprising a user device with a processor and memory, configured to identify sensitive data, determine a risk exposure score, and apply a security policy to restrict access based on similarity between applications, ensuring secure storage and access control for sensitive user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If sensitive user data is stored locally by applications to improve efficiency and user experience, then productivity and ease of operation are improved, but security and protection from unauthorized access deteriorate
Solution Approach 1:
The system segments access control by identifying and classifying different types of sensitive data (e.g., login credentials, financial information, health data) and applying distinct security policies to each segment based on its sensitivity level and the relationship between applications, thereby enabling efficient local storage while maintaining targeted security protection
Solution Approach 2:
The system introduces a security manager as an intermediary component that mediates between applications and sensitive data. This security manager evaluates access requests by determining risk exposure scores and assessing application relationships, acting as a gatekeeper that allows convenient data access while preventing unauthorized access
2Reliability
If security policies are applied to restrict access to sensitive data, then data security is improved, but ease of operation and user convenience deteriorate
Solution Approach 1:
The system implements self-service security where the security manager automatically evaluates access requests, determines risk exposure scores, and enforces security policies without requiring user intervention. The system autonomously assesses application relationships and makes access decisions, maintaining strong security while eliminating the need for users to manually configure security settings
Solution Approach 2:
The system dynamically changes security parameters based on the risk exposure score and application relationship assessment. Access policies are adjusted parameterically based on the specific data type, the requesting application's relationship to the data-owning application, and the calculated risk level, allowing flexible security that adapts to different scenarios without affecting user convenience
3Reliability
If access control mechanisms are implemented to prevent unauthorized access, then security is improved, but device complexity increases
Solution Approach 1:
The security manager serves as a universal access control mechanism that handles multiple types of sensitive data (login credentials, financial information, health data, etc.) through a single unified system. It provides multi-functional capabilities including risk assessment, application relationship evaluation, and policy enforcement, reducing overall system complexity by consolidating security functions
Data Source
AI summary
An apparatus, related devices and methods, having a memory element operable to store instructions; and a processor operable to execute the instructions, such that the apparatus is configured to identify sensitive user data stored in the memory by a first application, determine a risk exposure score for the sensitive user data, apply, based on a determination that the risk exposure score is above a threshold, a security policy to restrict access to the sensitive user data, receive a request from a second application to access the sensitive user data, determine whether the first application and the second application are similar applications, and allow access based on a determination that the first application and the second application are similar applications.


