Network Proxy for Selective Mobile Data Wiping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security solutions for corporate data on personal and employee-owned mobile devices are inefficient due to the need for software agents on each device, which is a difficult and expensive process, and existing remote wiping solutions can lead to catastrophic data loss by erasing both corporate and personal data.

Innovation Solution

A network proxy system that remotely and selectively deletes corporate data from mobile devices without installing software agents, using a null account mechanism to synchronize and erase data, while preserving personal data, and employing proxy routing, analytics, and encryption to manage and secure data access and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software agents are installed on each personal computing device to secure corporate data, then data security is improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidsoftware agent installation and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network proxy as an intermediary component that mediates between corporate servers and employee personal devices. The proxy intercepts and manages data transmissions, enabling security controls without requiring software agents on employee devices. This resolves the contradiction by providing data security through a centralized intermediary rather than through complex device-level software installation and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote wiping is used to delete corporate data on lost or stolen devices, then data security is improved, but personal data may be catastrophically lost

Engineering Contradiction:
Improvedata securityVSAvoidpersonal data loss
Core Design Contradiction:
ReliabilityVSLoss of substance

Solution Approach 1:

The patent segments data into corporate data and personal data categories. The network proxy identifies and selectively manages only corporate data transmissions, allowing remote wiping of corporate data while leaving personal data untouched. This segmentation approach resolves the contradiction by enabling targeted data protection without catastrophic loss of personal information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality controls to different types of data. Corporate data receives strict security controls including remote wiping capabilities, while personal data is excluded from these controls. This local quality differentiation allows selective data protection that secures corporate information without endangering personal data.

Inventive Principle:
Principle #3Local quality

3Reliability

If software agents are deployed across a large number of diverse devices, then data security coverage is improved, but implementation difficulty and cost increase

Engineering Contradiction:
Improvedata security coverageVSAvoidimplementation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The network proxy provides universal security functionality for all corporate data transmissions across diverse devices and platforms. Instead of requiring device-specific software agents for different operating systems and device types, a single proxy infrastructure handles security for all devices uniformly. This universality resolves the contradiction by achieving comprehensive security coverage without the implementation complexity of deploying specialized software across diverse device ecosystems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9047480B2Secure application access system
Publication Date: 2015.06.02 BITGLASS LLC
  • US9047480B2 patent drawing
  • US9047480B2 patent drawing
  • US9047480B2 patent drawing

AI summary

A proxy server creates an index of keywords, receives at least a portion of a file, and, when a keyword in the index is encountered in the at least a portion of the file as the at least a portion of the file is being encrypted, associates in the index an encrypted record location identifier with the encountered keyword. The proxy server receives a search query and uses the keyword index to retrieve encrypted records from the server. The encrypted records are decrypted and sent as search results in response to the search query.