Portable Device Data Destruction via Security Interval Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods, such as user IDs and passwords, and data encryption, are inadequate in preventing unauthorized access to sensitive information on lost or stolen portable devices, and data erasure techniques can leave behind recoverable vestiges of data.

Innovation Solution

A system comprising a client, a central controller server, and a communications link, with an embedded agent that implements security rules for encryption, data destruction, and monitoring, which detects compromised devices and initiates rapid, targeted data destruction using methods like prioritized overwrite and encryption key destruction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is used to conceal electronic information, then data security is improved, but encryption keys may be discovered by computer driven trial and error processes

Engineering Contradiction:
Improvedata securityVSAvoidkey discovery risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by destroying encryption keys and sensitive data proactively when loss or theft is detected, before unauthorized users can attempt to discover keys through trial and error processes. The agent monitors device status and automatically initiates key destruction upon detecting compromise conditions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by pre-destroying encryption keys and sensitive data when compromise is detected, preventing potential key discovery attacks before they can occur. This counter-measure neutralizes the vulnerability to computer-driven trial and error key discovery processes.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If data erasure is performed to remove files, then data access is restricted, but vestiges of erased files remain on data storage devices that can be reconstructed

Engineering Contradiction:
Improvedata protectionVSAvoiddata recoverability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system changes the parameter of data destruction by using repetitive overwriting with multiple passes of random data patterns instead of single-pass erasure. This multi-pass overwriting process fundamentally alters the storage media state to prevent sophisticated reconstruction tools from detecting variations that could reveal previously stored data.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system converts the potential harm of data recovery risks into benefit by implementing secure overwriting protocols that use random data patterns. The repetitive writing process not only destroys original data but also creates a beneficial security layer that actively prevents reconstruction attempts through multiple overlapping data layers.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If rapid data destruction is initiated upon detecting device compromise, then data exposure risk is reduced, but the system must quickly distinguish between temporary communication loss and actual device loss

Engineering Contradiction:
Improvedata exposure preventionVSAvoiddecision time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring security rules, monitoring parameters, and response protocols before compromise occurs. The agent continuously monitors device status and communication link state, maintaining readiness to execute data destruction without delay when compromise conditions are met, eliminating decision-making latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses feedback mechanisms by continuously monitoring communication link status and device operational parameters to distinguish between temporary communication loss and actual device compromise. The agent analyzes patterns of communication failures and device behavior feedback to make accurate real-time decisions about whether to initiate data destruction.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7421589B2System and method for lost data destruction of electronic data stored on a portable electronic device using a security interval
Publication Date: 2008.09.02 BEACHHEAD SOLUTIONS
  • US7421589B2 patent drawing
  • US7421589B2 patent drawing
  • US7421589B2 patent drawing

AI summary

A data security system and method protects stored data from unauthorized access. According to one aspect of the invention, a client computing device communicates periodically with a server. If communications is not established between the client and the server for a selected activation interval and a subsequent grace period, the data is determined to be lost, and programmed security rules are automatically executed.