Mobile Device Sensitive Data Threshold Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for minimizing data loss risk on mobile devices, such as encryption and remote wipe, are inadequate as they either compromise usability or have limitations like requiring network connectivity and timely PIN entry, and none effectively manage sensitive data based on device context and user needs.

Innovation Solution

A method that dynamically manages sensitive data on mobile devices by determining the sensitivity of data items and adjusting the amount of sensitive information based on the device's context and user needs, using a threshold value to ensure data security without compromising usability, involving redaction and removal of data items to maintain policy compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If all relevant documents are made accessible on the mobile device, then usability is improved, but the risk of data loss increases

Engineering Contradiction:
ImproveusabilityVSAvoiddata loss risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into different sensitivity levels (e.g., public, internal, confidential, restricted) and applies different security policies to each segment. This allows users to access appropriate data on mobile devices while preventing exposure of highly sensitive information, thus resolving the contradiction between usability and data loss risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements context-aware security where the amount and type of sensitive data allowed on the device dynamically adjusts based on the security context (e.g., device encryption status, network connectivity, location). This enables full data access in secure contexts while limiting access in risky contexts, balancing usability and security.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If encryption is applied to protect sensitive information, then data security is improved, but usability deteriorates due to frequent PIN entry requirements

Engineering Contradiction:
Improvedata securityVSAvoidusability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements dynamic encryption policies where the encryption state changes based on context. For example, data may be encrypted at rest but decrypted for viewing in secure contexts, or encryption requirements are adjusted based on the sensitivity level and current security posture, reducing unnecessary PIN entries while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes encryption parameters (such as key strength, timeout duration, or encryption scope) based on data sensitivity levels and contextual factors. Less sensitive data may use weaker encryption with longer timeouts, while highly sensitive data maintains strong encryption, optimizing the balance between security and usability.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If remote wipe is implemented to prevent unauthorized access, then data security is improved, but reliability decreases due to network dependency and timing constraints

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsecurity effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent implements preliminary security measures such as automatic device locking after suspicious activity, pre-configured secure deletion of specific data types, or proactive data removal based on predicted risk scenarios. This reduces reliance on reactive remote wipe and improves security effectiveness even when network connectivity is unavailable.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8560722B2System and method to govern sensitive data exchange with mobile devices based on threshold sensitivity values
Publication Date: 2013.10.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8560722B2 patent drawing
  • US8560722B2 patent drawing
  • US8560722B2 patent drawing

AI summary

Techniques for limiting the risk of loss of sensitive data from a mobile device are provided. In one aspect, a method for managing sensitive data on a mobile device is provided. The method includes the following steps. A sensitivity of a data item to be transferred to the mobile device is determined. It is determined whether an aggregate sensitivity of data items already present on the mobile device plus the data item to be transferred exceeds a current threshold sensitivity value for the mobile device. If the aggregate sensitivity exceeds the current threshold sensitivity value, measures are employed to ensure the aggregate sensitivity remains below the current threshold sensitivity value for the mobile device. Otherwise the data item is transferred to the mobile device.