Location-Based Encryption for Mobile Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile Device Management (MDM) security policies restrict the execution of applications like camera and recording programs in restricted areas, hindering users' ability to perform tasks that require these functions, such as recording conference content or storing images.

Innovation Solution

A system and method that encrypts and stores files created in restricted areas based on location information, allowing decryption and execution when requested, using a mobile device with an RF communication unit, storage unit, and controller to manage security policies and keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MDM security policy restricts application execution in restricted areas, then security is improved, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by encrypting files at the time of creation in restricted areas and storing them with location-based encryption keys. When users need to access these files outside restricted areas, the decryption happens automatically based on location information, allowing convenient access without compromising security during the sensitive creation phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different security measures to different locations. Files created in restricted areas are encrypted with location-specific keys, while files created outside restricted areas use different encryption. This local differentiation allows users to access files conveniently in appropriate locations while maintaining security in restricted zones.

Inventive Principle:
Principle #3Local quality

2Reliability

If camera and recording applications are blocked in restricted areas, then security is improved, but functionality deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system allows camera and recording applications to execute in restricted areas by implementing preliminary encryption of the created files. The files are encrypted at creation using location-based keys, enabling the applications to function while ensuring that the output files are protected before leaving the restricted area.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces encryption as an intermediary mechanism between the application execution and file storage. The encryption process acts as a mediator that allows the application to create files in restricted areas while protecting the files through location-based encryption, thus enabling functionality without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If files are encrypted and stored based on location information, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically managing encryption and decryption based on location information. The mobile device automatically determines its location, selects the appropriate encryption key, and performs encryption/decryption operations without requiring manual user intervention or complex configuration, thereby reducing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The location-based encryption system serves multiple functions: it encrypts files during creation, stores them with location metadata, automatically decrypts them when needed, and manages security policies. This multi-functionality consolidates what could be separate complex systems into a unified approach, managing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9071621B2Security management system and method for location-based mobile device
Publication Date: 2015.06.30 SAMSUNG ELECTRONICS CO LTD
  • US9071621B2 patent drawing
  • US9071621B2 patent drawing
  • US9071621B2 patent drawing

AI summary

A method and a system of managing information security for a mobile device in a restricted area based on location information regarding the mobile device are provided. The method includes receiving, by the mobile device, a request for the execution of an application program in a restricted area from a server managing the restricted area, executing, by the mobile device, the application program requested for execution when the program was set to be executable according to a security policy set to the restricted area, encrypting, by the mobile device, a file, created according to the execution of the application program, based on location information regarding the mobile device, and storing the encrypted file.