Security Agent Data Deletion for Mobile Device Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for mobile devices do not effectively address the risk of unauthorized access to sensitive enterprise data when devices are lost or stolen, as they lack automatic data deletion mechanisms triggered by a predetermined time frame without user or company instruction.
Innovation Solution
Implementing a security agent on portable devices that regularly re-authenticates with an authentication server, which issues a timeframe for re-authentication. If the user fails to re-authenticate within this timeframe, the security agent deletes sensitive enterprise data, providing an additional layer of security by automatically erasing data to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and password protection are used to secure mobile devices, then data security is improved, but the data remains on the device indefinitely and can eventually be circumvented
Solution Approach 1:
The system performs preliminary action by scheduling data deletion in advance based on authentication timeframes. The security agent is configured with predetermined timeframes before data deletion, and automatically initiates deletion if re-authentication doesn't occur within the specified period, preventing indefinite data retention while maintaining security.
Solution Approach 2:
The system makes the data retention period dynamic rather than static. Instead of permanent storage or fixed deletion triggers, the data retention timeframe adjusts based on authentication status and elapsed time since last successful re-authentication, allowing the system to adapt to changing security conditions.
2Reliability
If manual deletion instructions are sent from the mobile device company, then data can be deleted, but the process requires user action and may not be initiated if the device is kept from connecting
Solution Approach 1:
The security agent on the mobile device autonomously monitors the elapsed time since last authentication and automatically initiates data deletion when the predetermined timeframe expires, without requiring user action or company intervention. The system serves itself by self-monitoring and self-executing the security measure.
Solution Approach 2:
The system performs preliminary action by pre-configuring deletion timeframes and automatically initiating deletion if re-authentication doesn't occur within the specified period, eliminating the need for manual deletion instructions to be sent and acted upon.
3Reliability
If automatic deletion after a predetermined time frame is implemented, then the window for unauthorized access is reduced, but the system complexity increases
Solution Approach 1:
The security agent autonomously monitors authentication timeframes and automatically initiates data deletion when the predetermined period expires, eliminating the need for complex external monitoring systems or manual intervention processes.
Solution Approach 2:
The patent combines the authentication mechanism with the deletion trigger mechanism into a unified system. The same authentication framework that secures data access also automatically triggers deletion after a predetermined timeframe, merging security and data lifecycle management functions.
Data Source
AI summary
Systems and methods for destroying sensitive enterprise data on portable devices are provided. Such systems and methods may include providing a portable device that includes a security agent for deleting sensitive enterprise data. The security agent on the portable device can be required to regularly be authenticated by a user through an authentication server. The authentication server provides a pre-determined timeframe for which the user would need to re-authenticate. Failure by the user to re-authenticate within the pre-determined timeframe can result in the security agent proceeding with deleting the sensitive enterprise data on the portable device.


