Information Lock Box for Mobile Device Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data protection systems fail to ensure that sensitive information on mobile devices is only accessible and modifiable within a known geographic location, leaving it vulnerable when the device is stolen or disconnected from a trusted network.

Innovation Solution

The Information Lock Box system employs a file-system driver, service component, and user interface to encrypt and hide sensitive information on mobile devices, using network connectivity as a trigger to lock down access. It uses encryption algorithms like DES, AES-128, AES-256, and asymmetric key encryption, and is transparent to users, ensuring sensitive data remains protected when the device is not connected to a trusted network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive information is stored on mobile devices for portability and access, then information accessibility is improved, but information security deteriorates when devices are stolen or disconnected from trusted networks

Engineering Contradiction:
Improveinformation accessibilityVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic encryption key management where the encryption state of sensitive files changes based on network connectivity status. When connected to a trusted network, files are decrypted and accessible; when disconnected or on untrusted networks, files are automatically re-encrypted and inaccessible. This dynamic state transition resolves the contradiction by making security adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an intermediary encryption layer managed by a file system driver that sits between the user and sensitive files. This intermediary automatically applies encryption/decryption based on network trust status without user intervention, mediating between the need for accessibility and the requirement for security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional data loss prevention systems scan and identify sensitive information to prevent writing to removable media, then data protection is improved, but the system cannot ensure sensitive information is only viewed and modified within known geographic locations

Engineering Contradiction:
Improvedata protectionVSAvoidgeographic location control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends data protection beyond traditional removable media control to include network-based geographic/location control. The same encryption mechanism works both for preventing writes to removable media and for controlling access based on network trust status, making the system multi-functional and adaptable to different protection scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the control parameter from physical media type to network connectivity status. Instead of solely controlling based on whether media is removable, the system now controls encryption state based on network trust parameters, enabling geographic/location-based security controls through network awareness.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If sensitive information is encrypted to protect security, then information security is improved, but user access to the information deteriorates

Engineering Contradiction:
Improveinformation securityVSAvoiduser access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service encryption/decryption through automatic network status monitoring. The system automatically detects when the device connects to or disconnects from trusted networks and autonomously applies or removes encryption without requiring user action. This resolves the contradiction by making encryption transparent and automated rather than manual.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback loop where the system continuously monitors network connectivity status and automatically adjusts encryption state in response. This closed-loop control ensures security is maintained only when necessary (when disconnected from trusted networks) while automatically restoring access when connected, eliminating the need for manual encryption/decryption decisions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9378379B1Method and apparatus for the protection of information in a device upon separation from a network
Publication Date: 2016.06.28 BANK OF AMERICA CORP
  • US9378379B1 patent drawing
  • US9378379B1 patent drawing
  • US9378379B1 patent drawing

AI summary

Systems, methods and consumer-readable media for providing an system implementing an information lock box. Sensitive files may be identified by the system prior to engagement of the protection system. One method according to the invention may preferably include hiding and/or encrypting sensitive files upon detecting changes of the network status. The information lock box may utilize a file-system driver to control access to files. The system may communicate with administrative serve and communicating messages to a user.