Mobile Content Security via Encrypted Intermediary Node
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device technologies lack effective mechanisms to prevent unauthorized access and data leakage of enterprise content, such as email attachments, by allowing untrusted applications to access and store sensitive data.
Innovation Solution
Implementing a security enforcement node that encrypts content in transit and provides decryption keys only to authorized applications, while modifying file types to ensure only authorized apps can access and store the content, using a security management platform and trusted management agents to manage access and storage securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If external applications are allowed to access and store email attachments, then application versatility and user convenience are improved, but data security and control are worsened
Solution Approach 1:
The patent introduces a security enforcement node as an intermediary between the email application and external applications. This node acts as a gatekeeper that receives attachment access requests, verifies application authorization, and controls data flow. The intermediary prevents untrusted applications from directly accessing attachments while still allowing authorized applications to do so, thus resolving the contradiction between versatility and security.
Solution Approach 2:
The system performs preliminary authorization checks before allowing external applications to access attachments. The security enforcement node pre-approves or blocks applications based on their trust status and authorization level. This preliminary action ensures that only authorized applications can access sensitive data, preventing data leakage before it can occur while maintaining application versatility.
2Ease of operation
If content is downloaded to mobile device storage, then application functionality is improved, but control over data location and security is worsened
Solution Approach 1:
The security enforcement node serves as an intermediary that manages content download and storage operations. It monitors where content is stored, ensures authorized applications can access it, and maintains control over data location. This intermediary approach enables easy content accessibility while preserving reliable data control through centralized security management.
Solution Approach 2:
The system implements feedback mechanisms where the security enforcement node continuously monitors application access patterns and storage operations. It provides real-time control and adjustment of access permissions based on observed behavior, ensuring that content accessibility is maintained while data control and security are preserved through adaptive response to usage patterns.
Data Source
AI summary
Preventing enterprise or other protected content data from “leaking” from being under secure management on a device, for example by virtue of being viewed using an untrusted app on the device, is disclosed. An indication is received that a content to be provided to a first mobile application on a mobile device is to be protected against unauthorized access at the mobile device using unauthorized applications other than the first mobile application. The content is encrypted while in transit to the mobile device, using a key associated with a second mobile application authorized to be used to access the content at the mobile device.


