Network Proxy Credential Encryption and Selective Data Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Mobile Device Management solutions face challenges in securely managing and remotely wiping corporate data from personal devices without affecting personal data, due to the complexity and cost of installing software agents on diverse devices, and the risk of data loss when employees leave or misplace devices.
Innovation Solution
A network proxy system that remotely and selectively deletes corporate data from mobile devices without the need for software agents, using a null account mechanism to synchronize and erase data, while preserving personal data, and encrypts user credentials to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software agents are installed on each personal computing device to enable remote data deletion, then corporate data security is improved, but device complexity and management cost increase significantly
Solution Approach 1:
The patent extracts the security management function from the client device by removing the need for software agents on personal devices. Instead, the proxy server handles all security operations including credential encryption, authentication, and remote data deletion by manipulating server-side stored credentials, thereby eliminating the complexity of installing and managing agents on diverse personal devices while maintaining corporate data security
Solution Approach 2:
The proxy server acts as an intermediary between the client device and the corporate infrastructure. It intercepts authentication requests, encrypts credentials before they reach the server, and enables remote data deletion by clearing credentials from the server-side store. This intermediary approach allows security management without requiring software agents on personal devices, reducing device complexity while improving security
2Reliability
If software agents are installed on personal devices to remotely delete corporate data, then data loss prevention is improved, but ease of operation deteriorates due to installation difficulties on diverse devices
Solution Approach 1:
The patent removes the software agent component entirely from personal devices. Data loss prevention is achieved by storing encrypted corporate credentials on the proxy server instead of on the device. When an employee leaves or a device is lost, the administrator can remotely delete corporate data by clearing credentials from the server-side store, eliminating installation complexity while maintaining data loss prevention
Solution Approach 2:
The system enables self-service credential management where the proxy server automatically handles credential encryption, storage, and deletion. The server-side credential store acts as a self-contained security mechanism that doesn't require external software agents on personal devices, making the system easier to operate across diverse device platforms while preventing data loss
3Reliability
If all data on a personal device is deleted when an employee leaves, then corporate data security is improved, but personal data loss occurs
Solution Approach 1:
The patent segments data into corporate and personal categories by storing corporate credentials separately in an encrypted format on the proxy server, distinct from personal device data. When an employee leaves, the system can selectively delete only the encrypted corporate credentials from the server-side store while leaving personal data on the device untouched, achieving corporate data security without personal data loss
Solution Approach 2:
The patent extracts corporate data management from the personal device storage entirely. Corporate credentials are stored and managed exclusively on the proxy server in encrypted form. Upon employee termination, the system remotely deletes corporate data by clearing credentials from the server-side store, while personal data remaining on the device is unaffected, thus preventing personal data loss while maintaining corporate security
4Ease of operation
If credentials are transmitted in clear text from client application to server, then ease of operation is improved, but network security deteriorates
Solution Approach 1:
The patent applies preliminary encryption to credentials before they leave the client application. The proxy server encrypts credentials using a stored encryption key before transmitting them to the corporate server in encrypted form. This preliminary security action prevents clear-text transmission vulnerabilities while maintaining ease of operation, as the encryption process is automated and transparent to users
Solution Approach 2:
The proxy server acts as an intermediary that intercepts credential transmissions between the client application and the corporate server. It encrypts credentials using stored encryption keys before forwarding them to the server, thereby eliminating clear-text transmission security risks while preserving ease of operation. The intermediary automatically handles encryption without requiring user awareness or intervention
Data Source
AI summary
A proxy server mitigates security risks of user credentials sent across a network in clear text. The proxy server encrypts user credentials within a client application request destined for an application server. The proxy server forwards the client application request to the application server. The application server sends the encrypted user credentials to the proxy server where the proxy server decrypts the user credentials and authenticates the user credentials with an authentication server.


