Mobile Data Tagging for Secure Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate data leakage occurs when employees use personal mobile communication devices for both corporate and personal activities, as existing systems lack effective mechanisms to restrict the transmission of corporate data over insecure channels.
Innovation Solution
Implementing a data tagging system on mobile communication devices that associates corporate data with a service identifier, restricting transmission to secure corporate channels only, and prompting users to select secure services for data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If employees use a single mobile device for both corporate and personal communication, then device utilization efficiency is improved, but corporate data security deteriorates
Solution Approach 1:
The system segments data into corporate and personal categories by tagging data with service identifiers. Corporate data received through corporate services or created by corporate applications is automatically tagged, allowing the device to handle both corporate and personal communication while maintaining security through identification and restriction of corporate data transmission channels.
2Object-affected harmful factors
If corporate data transmission is restricted to secure channels only, then data security is improved, but transmission flexibility deteriorates
Solution Approach 1:
The system dynamically determines transmission restrictions based on the service identifier associated with each data item. When a user attempts to transmit tagged data, the system checks whether the target service is authorized for that data type and adjusts transmission permissions in real-time, allowing flexible yet secure data sharing across different services.
3Measurement precision
If automatic tagging of corporate data is implemented, then data identification accuracy is improved, but system complexity deteriorates
Solution Approach 1:
The system performs preliminary tagging of corporate data at the point of receipt or creation by automatically associating service identifiers with data items. This preliminary classification eliminates the need for manual identification later and enables automatic enforcement of transmission restrictions, maintaining high identification accuracy while managing complexity through automation.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
Data received at, or created on, a device may be tagged as corporate dependent upon a service over which the data is received or an application in which the data is created. When a user attempts to insert tagged data into a data item that is to be transmitted by the device, the insertion may be prevented. Similarly, the transmission of tagged data may be restricted to only occur on a secure service.