Network Proxy Selective Corporate Data Deletion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security solutions for corporate data on personal devices and shared servers are inefficient due to the complexity and cost of managing software agents on diverse devices, and they often result in catastrophic data loss by erasing both corporate and personal data.

Innovation Solution

A network proxy system that remotely and selectively deletes corporate data from mobile devices without installing software agents, using a null account mechanism to synchronize and erase data, while preserving personal data, and provides encryption, analytics, and access control through a centralized management console.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software agents are installed on each personal computing device to enable remote data deletion, then data security is improved, but device complexity and management cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsoftware agent management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary between the corporate network and personal devices. The server hosts a web application that acts as a mediator to manage corporate data on devices without requiring persistent software agents. The web application communicates with devices through standard web protocols, eliminating the need for complex device-side software while maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables devices to self-register and self-manage their own corporate data through the web application. Devices automatically generate cryptographic key pairs and store them locally, with the server storing only public keys. This self-service approach eliminates the need for manual software agent installation and reduces management complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

2Reliability

If software agents are used to remotely delete corporate data, then data loss risk is reduced, but personal data may be accidentally erased

Engineering Contradiction:
Improvedata loss preventionVSAvoidpersonal data loss
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments data into corporate and personal categories by using separate cryptographic key pairs for each device. The server stores public keys associated with specific devices, and when deletion is requested, the system generates a cryptographic proof that allows the device to delete only corporate data encrypted with its corresponding private key. This segmentation ensures personal data remains protected while enabling selective corporate data deletion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements local quality by storing cryptographic key pairs locally on each device rather than centrally on the server. The private key remains exclusively on the device, while the server stores only the public key. This distributed architecture ensures that even if the server is compromised, personal data on devices remains secure, and deletion operations can only affect corporate data that the device itself encrypted.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If software agents are deployed across diverse devices, then remote data management capability is achieved, but implementation cost and difficulty increase

Engineering Contradiction:
Improvecross-platform data managementVSAvoiddeployment cost and difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements universality by using standard web technologies (HTML, JavaScript, SSL/TLS) that are universally supported across all modern devices and operating systems. The web application can be accessed from any device with a web browser without requiring device-specific software installation. This approach provides cross-platform compatibility while significantly reducing deployment costs and complexity compared to device-specific agent solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If all data is deleted from a device when an employee leaves, then security risk is eliminated, but valuable corporate data may be lost

Engineering Contradiction:
Improvesecurity risk eliminationVSAvoidcorporate data loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the ability to selectively delete data from the device level to the server level. Instead of requiring complete device wiping or relying on device-specific agent functionality, the server generates cryptographic proofs that enable selective deletion of corporate data. This extraction allows administrators to precisely control what data is deleted and what remains, eliminating security risks while preserving valuable corporate data that should retain access.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9552492B2Secure application access system
Publication Date: 2017.01.24 BITGLASS LLC
  • US9552492B2 patent drawing
  • US9552492B2 patent drawing
  • US9552492B2 patent drawing

AI summary

A proxy server creates an index of keywords, receives an encrypted record, decrypts the received encrypted record as decrypted data and, when a keyword in the index is encountered in the decrypted data, associates in the index an encrypted record location identifier with the encountered keyword. The proxy server receives a search query and uses the keyword index to retrieve encrypted records from the server. The encrypted records are decrypted and sent as search results in response to the search query.