Portable Device Data Destruction via Communication Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security methods, such as user IDs and passwords, and data encryption, are inadequate in preventing unauthorized access to sensitive information on lost or stolen devices, and data erasure techniques leave behind recoverable vestiges of data.
Innovation Solution
A system and method that employs a client, central controller server, and communications link to detect compromised devices, implement security rules for encryption and data destruction, and initiate automatic data erasure processes, including prioritized overwrite and physical device disablement, to protect sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data encryption is used to protect sensitive information, then data confidentiality is improved, but security keys may be discovered by computer driven trial and error processes
Solution Approach 1:
The system performs preliminary actions by proactively detecting device compromise through monitoring communication patterns and automatically initiating data destruction before unauthorized access can occur. The agent continuously monitors for loss or theft conditions and pre-emptively destroys data according to security rules, eliminating the need to rely solely on encryption key strength against brute force attacks.
Solution Approach 2:
The invention extracts the security decision-making function from the central server and embeds it in a local agent on the portable device. This agent independently evaluates security conditions and executes data destruction without requiring server communication, removing the vulnerability point where centralized key management could be compromised.
2Reliability
If data erasure is performed to protect information, then data accessibility is reduced, but sophisticated tools may detect variations in storage media that can be used to reconstruct the previously stored data
Solution Approach 1:
The system changes the parameters of data destruction by implementing multiple overwrite passes with different patterns (e.g., multiple iterations of writing zeros, ones, and random data) rather than single-pass erasure. This transforms the physical state of the storage media to eliminate detectable variations that sophisticated reconstruction tools might exploit.
Solution Approach 2:
The agent performs preliminary data destruction actions automatically when compromise is detected, before an attacker can attempt reconstruction. The system pre-emptively overwrites data multiple times according to configured security rules, ensuring that even sophisticated forensic tools cannot recover information.
3Reliability
If automatic data destruction is implemented on compromised devices, then data security is improved, but device complexity increases with agents and monitoring systems
Solution Approach 1:
The portable device becomes self-service capable by embedding an agent that autonomously monitors security conditions, evaluates compromise status, and executes data destruction without requiring external server intervention. The device serves its own security needs independently, reducing the operational complexity of the overall system architecture.
Solution Approach 2:
The embedded agent performs multiple functions including monitoring communication patterns, detecting compromise conditions, evaluating security rules, and executing data destruction. This multi-functional approach consolidates what would otherwise require separate systems, managing complexity through functional integration.
4Measurement precision
If communication monitoring is used to detect compromised devices, then detection accuracy is improved, but loss of time occurs during communication intervals
Solution Approach 1:
The system implements periodic communication monitoring at defined intervals, balancing detection accuracy with time loss. The agent checks for server communication periodically according to configured intervals, providing systematic monitoring without requiring constant connection, thus managing the trade-off between detection precision and time efficiency.
Data Source
AI summary
A data security system and method protects stored data from unauthorized access. According to one aspect of the invention, a client computing device communicates periodically with a server. If communications is note established between the client and the server for a selected activation interval and a subsequent grace period, the data is determined to be lost and, programmed security rules are automatically executed. The server with which the client computer device communicates includes one server located inside the firewall of a particular organization, or a mirror server located outside the firewall, and thereby allow for the re-setting of the activation interval when the client is properly outside of the firewall through communication with the mirror server, as well as the to provide command an control over a lost or stolen client by pushing updated rules if communication is subsequently attempted with the mirror server.


