Network Proxy Selective Corporate Data Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security solutions for corporate data on personal devices and shared servers are inefficient due to the complexity and cost of managing software agents on diverse devices, and they often result in catastrophic data loss by erasing both corporate and personal data.
Innovation Solution
A network proxy system that remotely and selectively deletes corporate data from mobile devices without installing software agents, using a null account mechanism to synchronize and erase data, while preserving personal data, and provides encryption, analytics, and access control through a centralized management console.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software agents are installed on each personal computing device to enable remote data deletion, then data security is improved, but device complexity and management cost increase significantly
Solution Approach 1:
The patent introduces a server as an intermediary between the corporate network and personal devices. The server hosts a web application that acts as a mediator to manage corporate data on devices without requiring persistent software agents. The web application communicates with devices through standard web protocols, eliminating the need for complex device-side software while maintaining security control.
Solution Approach 2:
The system enables devices to self-register and self-manage their own corporate data through the web application. Devices automatically generate cryptographic key pairs and store them locally, with the server storing only public keys. This self-service approach eliminates the need for manual software agent installation and reduces management complexity while maintaining security.
2Reliability
If software agents are used to remotely delete corporate data, then data loss risk is reduced, but personal data may be accidentally erased
Solution Approach 1:
The patent segments data into corporate and personal categories by using separate cryptographic key pairs for each device. The server stores public keys associated with specific devices, and when deletion is requested, the system generates a cryptographic proof that allows the device to delete only corporate data encrypted with its corresponding private key. This segmentation ensures personal data remains protected while enabling selective corporate data deletion.
Solution Approach 2:
The system implements local quality by storing cryptographic key pairs locally on each device rather than centrally on the server. The private key remains exclusively on the device, while the server stores only the public key. This distributed architecture ensures that even if the server is compromised, personal data on devices remains secure, and deletion operations can only affect corporate data that the device itself encrypted.
3Adaptability or versatility
If software agents are deployed across diverse devices, then remote data management capability is achieved, but implementation cost and difficulty increase
Solution Approach 1:
The patent implements universality by using standard web technologies (HTML, JavaScript, SSL/TLS) that are universally supported across all modern devices and operating systems. The web application can be accessed from any device with a web browser without requiring device-specific software installation. This approach provides cross-platform compatibility while significantly reducing deployment costs and complexity compared to device-specific agent solutions.
4Reliability
If all data is deleted from a device when an employee leaves, then security risk is eliminated, but valuable corporate data may be lost
Solution Approach 1:
The patent extracts the ability to selectively delete data from the device level to the server level. Instead of requiring complete device wiping or relying on device-specific agent functionality, the server generates cryptographic proofs that enable selective deletion of corporate data. This extraction allows administrators to precisely control what data is deleted and what remains, eliminating security risks while preserving valuable corporate data that should retain access.
Data Source
AI summary
A proxy server creates an index of keywords, receives an encrypted record, decrypts the received encrypted record as decrypted data and, when a keyword in the index is encountered in the decrypted data, associates in the index an encrypted record location identifier with the encountered keyword. The proxy server receives a search query and uses the keyword index to retrieve encrypted records from the server. The encrypted records are decrypted and sent as search results in response to the search query.


