Location-Based Encryption for Mobile Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile Device Management (MDM) security policies restrict the execution of applications like camera and recording programs in restricted areas, hindering users' ability to perform tasks that require these functions, such as recording conference content or storing images.
Innovation Solution
A system and method that encrypts and stores files created in restricted areas based on location information, allowing decryption and execution when requested, using a mobile device with an RF communication unit, storage unit, and controller to manage security policies and keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MDM security policy restricts application execution in restricted areas, then security is improved, but user convenience deteriorates
Solution Approach 1:
The system performs preliminary actions by encrypting files at the time of creation in restricted areas and storing them with location-based encryption keys. When users need to access these files outside restricted areas, the decryption happens automatically based on location information, allowing convenient access without compromising security during the sensitive creation phase.
Solution Approach 2:
The patent applies different security measures to different locations. Files created in restricted areas are encrypted with location-specific keys, while files created outside restricted areas use different encryption. This local differentiation allows users to access files conveniently in appropriate locations while maintaining security in restricted zones.
2Reliability
If camera and recording applications are blocked in restricted areas, then security is improved, but functionality deteriorates
Solution Approach 1:
The system allows camera and recording applications to execute in restricted areas by implementing preliminary encryption of the created files. The files are encrypted at creation using location-based keys, enabling the applications to function while ensuring that the output files are protected before leaving the restricted area.
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism between the application execution and file storage. The encryption process acts as a mediator that allows the application to create files in restricted areas while protecting the files through location-based encryption, thus enabling functionality without compromising security.
3Reliability
If files are encrypted and stored based on location information, then security is improved, but system complexity increases
Solution Approach 1:
The system implements self-service by automatically managing encryption and decryption based on location information. The mobile device automatically determines its location, selects the appropriate encryption key, and performs encryption/decryption operations without requiring manual user intervention or complex configuration, thereby reducing the perceived complexity for users.
Solution Approach 2:
The location-based encryption system serves multiple functions: it encrypts files during creation, stores them with location metadata, automatically decrypts them when needed, and manages security policies. This multi-functionality consolidates what could be separate complex systems into a unified approach, managing overall system complexity.
Data Source
AI summary
A method and a system of managing information security for a mobile device in a restricted area based on location information regarding the mobile device are provided. The method includes receiving, by the mobile device, a request for the execution of an application program in a restricted area from a server managing the restricted area, executing, by the mobile device, the application program requested for execution when the program was set to be executable according to a security policy set to the restricted area, encrypting, by the mobile device, a file, created according to the execution of the application program, based on location information regarding the mobile device, and storing the encrypted file.


