Network Proxy Credential Encryption and Selective Data Deletion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Mobile Device Management solutions face challenges in securely managing and remotely wiping corporate data from personal devices without affecting personal data, due to the complexity and cost of installing software agents on diverse devices, and the risk of data loss when employees leave or misplace devices.

Innovation Solution

A network proxy system that remotely and selectively deletes corporate data from mobile devices without the need for software agents, using a null account mechanism to synchronize and erase data, while preserving personal data, and encrypts user credentials to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software agents are installed on each personal computing device to enable remote data deletion, then corporate data security is improved, but device complexity and management cost increase significantly

Engineering Contradiction:
Improvecorporate data securityVSAvoidsoftware agent installation and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security management function from the client device by removing the need for software agents on personal devices. Instead, the proxy server handles all security operations including credential encryption, authentication, and remote data deletion by manipulating server-side stored credentials, thereby eliminating the complexity of installing and managing agents on diverse personal devices while maintaining corporate data security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The proxy server acts as an intermediary between the client device and the corporate infrastructure. It intercepts authentication requests, encrypts credentials before they reach the server, and enables remote data deletion by clearing credentials from the server-side store. This intermediary approach allows security management without requiring software agents on personal devices, reducing device complexity while improving security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software agents are installed on personal devices to remotely delete corporate data, then data loss prevention is improved, but ease of operation deteriorates due to installation difficulties on diverse devices

Engineering Contradiction:
Improvedata loss preventionVSAvoidsoftware agent installation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent removes the software agent component entirely from personal devices. Data loss prevention is achieved by storing encrypted corporate credentials on the proxy server instead of on the device. When an employee leaves or a device is lost, the administrator can remotely delete corporate data by clearing credentials from the server-side store, eliminating installation complexity while maintaining data loss prevention

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables self-service credential management where the proxy server automatically handles credential encryption, storage, and deletion. The server-side credential store acts as a self-contained security mechanism that doesn't require external software agents on personal devices, making the system easier to operate across diverse device platforms while preventing data loss

Inventive Principle:
Principle #25Self-service

3Reliability

If all data on a personal device is deleted when an employee leaves, then corporate data security is improved, but personal data loss occurs

Engineering Contradiction:
Improvecorporate data securityVSAvoidpersonal data
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent segments data into corporate and personal categories by storing corporate credentials separately in an encrypted format on the proxy server, distinct from personal device data. When an employee leaves, the system can selectively delete only the encrypted corporate credentials from the server-side store while leaving personal data on the device untouched, achieving corporate data security without personal data loss

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts corporate data management from the personal device storage entirely. Corporate credentials are stored and managed exclusively on the proxy server in encrypted form. Upon employee termination, the system remotely deletes corporate data by clearing credentials from the server-side store, while personal data remaining on the device is unaffected, thus preventing personal data loss while maintaining corporate security

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If credentials are transmitted in clear text from client application to server, then ease of operation is improved, but network security deteriorates

Engineering Contradiction:
Improvecredential transmissionVSAvoidnetwork security risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary encryption to credentials before they leave the client application. The proxy server encrypts credentials using a stored encryption key before transmitting them to the corporate server in encrypted form. This preliminary security action prevents clear-text transmission vulnerabilities while maintaining ease of operation, as the encryption process is automated and transparent to users

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The proxy server acts as an intermediary that intercepts credential transmissions between the client application and the corporate server. It encrypts credentials using stored encryption keys before forwarding them to the server, thereby eliminating clear-text transmission security risks while preserving ease of operation. The intermediary automatically handles encryption without requiring user awareness or intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10868811B2Secure user credential access system
Publication Date: 2020.12.15 BITGLASS LLC
  • US10868811B2 patent drawing
  • US10868811B2 patent drawing
  • US10868811B2 patent drawing

AI summary

A proxy server mitigates security risks of user credentials sent across a network in clear text. The proxy server encrypts user credentials within a client application request destined for an application server. The proxy server forwards the client application request to the application server. The application server sends the encrypted user credentials to the proxy server where the proxy server decrypts the user credentials and authenticates the user credentials with an authentication server.