Wireless Device Data Protection via Network Register Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks lack a mechanism to securely manage and protect data on devices before denying network access when they are reported lost or stolen, as the security module cannot reach the device once it is blacklisted.

Innovation Solution

A system and method where the security manager communicates with the Equipment Identity Register (EIR) or Home Location Register (HLR) to secure data on a wireless device by sending commands over the air before denying network access, allowing for operations like data backup, wipe, or lock, and restoring data when the device is recovered.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the device is immediately added to the black list upon being reported lost or stolen, then network access is denied promptly, but the security module cannot reach the device to perform data protection operations

Engineering Contradiction:
Improvedata protectionVSAvoidtime to secure data
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs data protection operations (backup, wipe, or lock) before adding the device to the black list. This preliminary action ensures that security measures are executed while the device is still accessible via the network, preventing data breaches while maintaining timely response.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the device is kept on the network longer to allow security operations, then data can be protected, but network access remains vulnerable for a longer period

Engineering Contradiction:
Improvedata protectionVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Security operations are initiated immediately when a device is reported lost or stolen, before the device is blacklisted. This ensures data protection actions are completed during the brief window of network accessibility, eliminating the vulnerability period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system proactively executes countermeasures (data backup, wipe, or lock) before the device can be compromised by unauthorized users. This preliminary anti-action neutralizes the security threat before it can materialize.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If security operations are performed before blacklisting, then data is secured, but the process complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically executes a predefined sequence of operations: receive loss/stolen report, determine device type, select appropriate security operation, execute the operation, then blacklist the device. This automated workflow manages complexity through standardization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module autonomously performs data protection operations without requiring manual intervention. The system self-manages the entire process from receiving the report to executing security measures and blacklisting, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8515390B2System and method for protecting data in wireless devices
Publication Date: 2013.08.20 MFORMATION
  • US8515390B2 patent drawing
  • US8515390B2 patent drawing
  • US8515390B2 patent drawing

AI summary

When a network-based wireless device such as a mobile phone or data terminal is reported lost or stolen or is determined to be malfunctioning, a service provider can immediately deny the device access to the network. However, any management operation to secure data carried by the wireless device cannot be carried out as the device is no longer reachable from the network. Therefore, the data should be secured before the device is rendered inoperable. Apparatus and methods are provided to back-up the data or wipe the data before the system denies access to the device. A system and method are provided by which a security manager works in conjunction with an equipment register of the network to lock and wipe data on the wireless device before the device is denied access to the network. Similarly, for a wireless device that is later recovered or determined to be operable, the device can be granted access to the network again and any data that was locked or wiped can be unlocked or restored over the network.