Mobile Data Loss Prevention via Context-Aware Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data loss prevention solutions fail to effectively prevent unauthorized access and data loss when sensitive data is synchronized with mobile devices, especially on insecure networks, due to lack of security agents and extensibility mechanisms in mobile clients.

Innovation Solution

A system that identifies secure documents on mobile devices based on context rules, authenticates users, and sends encrypted data to authorized applications, ensuring only authorized operations can be performed on sensitive data, thereby preventing unauthorized access and data loss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is synchronized with mobile devices for remote access, then user accessibility and mobility are improved, but security control and data loss prevention capabilities deteriorate

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by encrypting sensitive data before synchronization to the mobile device. The data is encrypted on the enterprise server using strong encryption algorithms, and only authorized applications on the mobile device can decrypt and access the data. This preliminary encryption action ensures that even if the mobile device is compromised, the sensitive data remains protected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer between the mobile device and the sensitive data. This includes security agents that run on the mobile device to enforce security policies, and a security gateway that mediates between the mobile device and the enterprise server. The intermediary components monitor and control access to sensitive data, preventing unauthorized operations while allowing legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional DLP solutions monitor and block sensitive data on enterprise networks, then data loss prevention is improved, but mobile device security capabilities deteriorate due to lack of security agents

Engineering Contradiction:
Improvedata loss preventionVSAvoidmobile device security capabilities
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the DLP functionality into multiple components: enterprise server-side encryption and policy enforcement, mobile device security agents, and application-level security integration. This segmentation allows the complex DLP functionality to be distributed across different layers, with the mobile device receiving only the necessary lightweight security components while the enterprise server handles the heavy lifting of policy management and encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal security framework that can be deployed across multiple platforms and devices. The security architecture is designed to work with various mobile operating systems and applications through standardized interfaces and protocols. This multi-functional approach allows the same security solution to protect sensitive data across different mobile devices, applications, and network environments without requiring device-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If sensitive data is made accessible on mobile devices, then remote work capability is improved, but vulnerability to unauthorized access and data loss increases

Engineering Contradiction:
Improveremote work capabilityVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing security measures before data synchronization occurs. Data is encrypted on the enterprise server before being transmitted to the mobile device, and security policies are pre-configured to prevent unauthorized access. This preliminary protective action ensures that even if the mobile device is accessed by unauthorized users or lost, the sensitive data remains protected because the security controls are already in place before the data leaves the enterprise environment.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9268958B1Preventing the loss of sensitive data synchronized with a mobile device
Publication Date: 2016.02.23 CA TECH INC
  • US9268958B1 patent drawing
  • US9268958B1 patent drawing
  • US9268958B1 patent drawing

AI summary

A mobile device identifies a secure document that contains one or more context rules that correspond to the secure document. The mobile device determines whether a user is authorized to access the secure document based on the one or more context rules. The mobile device identifies an original document format for the secure document if the user is authorized to access the secure document and identifies an authorized application installed on the mobile device for accessing the secure document using the original document format. The authorized application corresponds to the original document format of the secure document. The mobile device sends the secure document to the authorized application.