Mobile File Classification Using Contextual Scoring for Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IT departments face challenges in balancing strict computer security policies for both company-owned and personally owned mobile devices, which can lead to unintended deletion or encryption of both personal and work-related data when unauthorized access occurs, as existing methods fail to effectively distinguish between the two types of data.
Innovation Solution
A computer program product that extracts contextual information such as network and geographic data to generate scores for files, classifying them as personal or work-related data, and secures work-related files by deleting or encrypting them based on predefined security policies when unauthorized access is detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strict computer security policies are enforced on personally owned devices, then company data security is improved, but personal data may be inadvertently deleted or encrypted
Solution Approach 1:
The patent segments data into distinct categories (personal data vs. company data) and applies different security policies to each segment. The system creates separate data containers or profiles that allow selective enforcement of security policies, enabling company security requirements to be met without affecting personal data.
Solution Approach 2:
The patent implements local quality by applying different security measures to different portions of data on the same device. Company data receives strict security policies (encryption, remote wipe capability), while personal data is excluded from these policies. The system identifies and tags data based on its origin and purpose, then applies appropriate security controls locally to each data type.
2Reliability
If company owned devices are issued to employees, then data security control is improved, but device cost and management complexity increase
Solution Approach 1:
The patent makes security management universal by implementing a platform that works across both company-owned and personally-owned devices. The same security policies, data classification mechanisms, and protection measures can be applied regardless of device ownership, eliminating the need for separate management systems and reducing overall complexity.
Solution Approach 2:
The patent introduces an intermediary layer (security management software or mobile device management system) that sits between the employee, the device, and the company's security requirements. This intermediary automatically enforces security policies, classifies data, and manages device compliance without requiring direct complex intervention from IT departments.
3Object-affected harmful factors
If password failure policies wipe all data, then unauthorized access prevention is improved, but legitimate user data loss occurs
Solution Approach 1:
The patent segments stored data into protected company data and unprotected personal data based on metadata tags or classification markers. When password failure policies trigger a wipe command, the system selectively targets only the company data segments for deletion or encryption while leaving personal data segments intact, thus preventing legitimate user data loss.
Solution Approach 2:
The patent performs preliminary classification and tagging of data before security incidents occur. By pre-identifying and marking company data versus personal data, the system is prepared to execute selective data protection actions when unauthorized access is detected, avoiding the need to wipe all data and preventing legitimate user data loss.
Data Source
AI summary
A client computer extracts contextual information associated with a file that is created. The client computer generates scores for the file by utilizing the contextual information that is extracted. The client computer assigns a value to the file, based on an aggregation of the scores that are generated. The client computer monitors activities on the client computer, wherein the activities trigger an event on the client computer. The client computer determines whether the event is in violation of one or more computer security policies on a server computer, wherein the one or more computer security policies require work-related files to be deleted or encrypted. The client computer classifies the file as personal data or work-related business data. The client computer secures the file, if the file is classified as work-related business data.


