Portable Device Resource Protection via Conditional Security Actions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for protecting resources downloaded to portable devices from enterprise systems are inadequate, as they often rely on manual removal or remote wiping, which can be unreliable and may inadvertently delete personal data.
Innovation Solution
An enterprise system formulates and sends security actions and conditions with resources to portable devices, allowing the devices to determine and enforce access control, such as deletion or read-only modes, based on specified policies, ensuring secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual removal or remote wiping is used to protect downloaded resources, then resource security is improved, but personal data may be inadvertently deleted and reliability deteriorates
Solution Approach 1:
The system segments resources into different types (enterprise resources vs. personal data) and applies different protection rules to each. Portable device applications are categorized as either enterprise applications subject to protection policies or personal applications excluded from such policies, ensuring that remote wiping only affects enterprise resources while preserving personal data.
Solution Approach 2:
The patent introduces an intermediary mechanism (the portable device application and protection policy system) that sits between the remote wiping command and the actual data deletion process. This intermediary selectively identifies and removes only protected enterprise resources while automatically preserving personal data, thus resolving the contradiction between effective resource protection and personal data safety.
2Reliability
If comprehensive protection policies are enforced on portable devices, then resource security is improved, but device complexity and user convenience deteriorate
Solution Approach 1:
The system implements self-service protection where portable device applications automatically enforce protection policies without requiring user intervention. The portable device application autonomously determines whether to allow resource downloads, enforce read-only modes, or perform selective wiping based on protection policies, eliminating the need for users to manually manage security settings while maintaining ease of operation.
Solution Approach 2:
The patent applies preliminary action by establishing protection policies before resources are downloaded to portable devices. Security rules, authentication requirements, and retention policies are pre-configured and automatically enforced during resource access and download operations, preventing security issues rather than addressing them after they occur, thus maintaining both security and user convenience.
3Productivity
If resources are made available for offline access on portable devices, then productivity is improved, but security control and resource protection deteriorate
Solution Approach 1:
The system implements dynamic protection that adapts to different access scenarios. When resources are accessed online, standard enterprise security controls apply. When downloaded for offline access, the system dynamically adjusts by enforcing device-specific protection policies, read-only modes, or authentication requirements based on the resource type and user context, thereby maintaining both offline productivity and resource protection.
Solution Approach 2:
The patent changes security parameters based on the access context. Resources downloaded to portable devices have their protection parameters modified according to pre-defined policies - for example, changing from full write access to read-only mode, or requiring additional authentication factors for offline access. This allows offline productivity while maintaining appropriate security controls through parameter adjustment.
Data Source
AI summary
Protection of resources hosted on enterprise systems. In an embodiment, an enterprise system receives a request from a portable device to download a resource, and in response formulates multiple security actions and associated conditions for the requested resource. The enterprise system sends the requested resource, the security actions and the conditions to the portable device. The portable device determines whether each condition is satisfied and performs the security actions associated with the conditions determined to have been satisfied. Due to the ability to send multiple security actions and associated conditions, better control in protection and retention of downloaded resources is obtained.


