Security Agent Data Deletion for Mobile Device Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for mobile devices do not effectively address the risk of unauthorized access to sensitive enterprise data when devices are lost or stolen, as they lack automatic data deletion mechanisms triggered by a predetermined time frame without user or company instruction.

Innovation Solution

Implementing a security agent on portable devices that regularly re-authenticates with an authentication server, which issues a timeframe for re-authentication. If the user fails to re-authenticate within this timeframe, the security agent deletes sensitive enterprise data, providing an additional layer of security by automatically erasing data to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and password protection are used to secure mobile devices, then data security is improved, but the data remains on the device indefinitely and can eventually be circumvented

Engineering Contradiction:
Improvedata securityVSAvoiddata retention time
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The system performs preliminary action by scheduling data deletion in advance based on authentication timeframes. The security agent is configured with predetermined timeframes before data deletion, and automatically initiates deletion if re-authentication doesn't occur within the specified period, preventing indefinite data retention while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system makes the data retention period dynamic rather than static. Instead of permanent storage or fixed deletion triggers, the data retention timeframe adjusts based on authentication status and elapsed time since last successful re-authentication, allowing the system to adapt to changing security conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If manual deletion instructions are sent from the mobile device company, then data can be deleted, but the process requires user action and may not be initiated if the device is kept from connecting

Engineering Contradiction:
Improvedata securityVSAvoiddeletion initiation process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security agent on the mobile device autonomously monitors the elapsed time since last authentication and automatically initiates data deletion when the predetermined timeframe expires, without requiring user action or company intervention. The system serves itself by self-monitoring and self-executing the security measure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring deletion timeframes and automatically initiating deletion if re-authentication doesn't occur within the specified period, eliminating the need for manual deletion instructions to be sent and acted upon.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If automatic deletion after a predetermined time frame is implemented, then the window for unauthorized access is reduced, but the system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security agent autonomously monitors authentication timeframes and automatically initiates data deletion when the predetermined period expires, eliminating the need for complex external monitoring systems or manual intervention processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent combines the authentication mechanism with the deletion trigger mechanism into a unified system. The same authentication framework that secures data access also automatically triggers deletion after a predetermined timeframe, merging security and data lifecycle management functions.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10089484B2Method and system for destroying sensitive enterprise data on portable devices
Publication Date: 2018.10.02 QUEST SOFTWARE INC
  • US10089484B2 patent drawing
  • US10089484B2 patent drawing
  • US10089484B2 patent drawing

AI summary

Systems and methods for destroying sensitive enterprise data on portable devices are provided. Such systems and methods may include providing a portable device that includes a security agent for deleting sensitive enterprise data. The security agent on the portable device can be required to regularly be authenticated by a user through an authentication server. The authentication server provides a pre-determined timeframe for which the user would need to re-authenticate. Failure by the user to re-authenticate within the pre-determined timeframe can result in the security agent proceeding with deleting the sensitive enterprise data on the portable device.