Mobile Enterprise Data Security via Network Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securing enterprise data on mobile devices used by employees, as personal devices may expose sensitive information when not under the enterprise's control, and existing encryption/decryption tools on these devices can lead to unintentional data exposure.

Innovation Solution

Implementing a system where enterprise data on mobile devices is stored encrypted and can only be decrypted when the device is connected to the enterprise network, using an encryption/decryption application accessible only through the network, ensuring that data remains secure when the device is not in use for business purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption/decryption tools are installed on the mobile computing device, then enterprise data can be accessed when needed, but the data remains at risk of exposure because users can unintentionally decrypt and make data available

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The decryption functionality is extracted from the mobile computing device and relocated to the enterprise network server. The encrypted data remains on the mobile device, but the capability to decrypt it is removed from the device and placed exclusively on the enterprise network, eliminating the security risk of local decryption while preserving access capability when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The enterprise network server acts as an intermediary between the encrypted data on the mobile device and the decryption process. Instead of the mobile device directly decrypting data, it must communicate with the enterprise network server which performs the decryption and returns the decrypted data, thereby controlling and monitoring the decryption process centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If employees use their own mobile computing devices to access enterprise data, then productivity is enhanced, but the enterprise loses control over the device and data security is compromised

Engineering Contradiction:
Improveworkforce productivityVSAvoiddata security control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the enterprise data into encrypted form that can be stored on personal devices, while keeping the decryption capability segmented and controlled exclusively on the enterprise network. This allows employees to use personal devices freely for productivity while the enterprise maintains control over the actual data security through centralized decryption management.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If enterprise data is stored on personal mobile devices, then data accessibility is improved, but the risk of exposure increases when devices are used outside work environments

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The decryption capability is extracted from the mobile device and placed exclusively on the enterprise network server. This allows encrypted data to be stored on personal devices for accessibility, but the actual data remains protected because the device alone cannot decrypt it without enterprise network involvement.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10044685B2Securing enterprise data on mobile devices
Publication Date: 2018.08.07 WORKDAY INC
  • US10044685B2 patent drawing
  • US10044685B2 patent drawing
  • US10044685B2 patent drawing

AI summary

Embodiments include method, systems and computer program products for securing enterprise data in a mobile computing environment. Aspects include receiving, by an application disposed on a mobile computing device, a request to access the enterprise data stored on the mobile computing device in an encrypted format and determining whether the mobile computing device is in communication with an enterprise network. Based on determining that the mobile computing device is in communication with the enterprise network, aspects include transmitting a decryption request to an encryption application disposed on the enterprise network, receiving the enterprise data in an unencrypted format from the enterprise network and granting access to the enterprise data in an unencrypted format to the application. Based on a determination that the mobile computing device is not communication with the enterprise network, aspects also include denying the request to access the enterprise data.