Mobile Content Security via Encrypted Intermediary Node

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device technologies lack effective mechanisms to prevent unauthorized access and data leakage of enterprise content, such as email attachments, by allowing untrusted applications to access and store sensitive data.

Innovation Solution

Implementing a security enforcement node that encrypts content in transit and provides decryption keys only to authorized applications, while modifying file types to ensure only authorized apps can access and store the content, using a security management platform and trusted management agents to manage access and storage securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If external applications are allowed to access and store email attachments, then application versatility and user convenience are improved, but data security and control are worsened

Engineering Contradiction:
Improveapplication accessibilityVSAvoiddata leakage
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security enforcement node as an intermediary between the email application and external applications. This node acts as a gatekeeper that receives attachment access requests, verifies application authorization, and controls data flow. The intermediary prevents untrusted applications from directly accessing attachments while still allowing authorized applications to do so, thus resolving the contradiction between versatility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization checks before allowing external applications to access attachments. The security enforcement node pre-approves or blocks applications based on their trust status and authorization level. This preliminary action ensures that only authorized applications can access sensitive data, preventing data leakage before it can occur while maintaining application versatility.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If content is downloaded to mobile device storage, then application functionality is improved, but control over data location and security is worsened

Engineering Contradiction:
Improvecontent accessibilityVSAvoiddata control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security enforcement node serves as an intermediary that manages content download and storage operations. It monitors where content is stored, ensures authorized applications can access it, and maintains control over data location. This intermediary approach enables easy content accessibility while preserving reliable data control through centralized security management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the security enforcement node continuously monitors application access patterns and storage operations. It provides real-time control and adjustment of access permissions based on observed behavior, ensuring that content accessibility is maintained while data control and security are preserved through adaptive response to usage patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9349018B1Preventing content data leak on mobile devices
Publication Date: 2016.05.24 IVANTI INC
  • US9349018B1 patent drawing
  • US9349018B1 patent drawing
  • US9349018B1 patent drawing

AI summary

Preventing enterprise or other protected content data from “leaking” from being under secure management on a device, for example by virtue of being viewed using an untrusted app on the device, is disclosed. An indication is received that a content to be provided to a first mobile application on a mobile device is to be protected against unauthorized access at the mobile device using unauthorized applications other than the first mobile application. The content is encrypted while in transit to the mobile device, using a key associated with a second mobile application authorized to be used to access the content at the mobile device.