Android Container Application for Secure Business Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses face challenges in protecting company data on personal devices used by employees without interfering with personal use, while employees want to maintain privacy and control over their personal data without affecting business use, and existing solutions are costly and invasive.

Innovation Solution

A container application is developed for Android devices that creates a secure computing environment by intercepting communications between business applications and the Android operating system, allowing businesses to monitor and control data access and usage without affecting personal use, while maintaining user transparency and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If businesses implement data protection solutions on personal devices, then company data security is improved, but device complexity and user privacy are worsened

Engineering Contradiction:
Improvecompany data securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the device into two distinct environments: a containerized business environment and a personal environment. The container application creates an isolated space where business applications run with restricted access to personal data, while personal applications remain outside the container. This segmentation allows data protection without requiring comprehensive system-wide changes, thus improving security while limiting the increase in device complexity to only the container portion.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If businesses implement monitoring and control mechanisms, then data visibility is improved, but ease of operation is worsened

Engineering Contradiction:
Improvedata visibilityVSAvoidease of operation
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The container application serves as an intermediary layer between business applications and the Android operating system. It intercepts and monitors communications between business apps and the OS, providing visibility into data access and usage patterns. This intermediary mechanism enables monitoring without requiring direct modification of business applications or the underlying OS, thus maintaining ease of operation while achieving data visibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If companies provision dedicated devices for business use, then data security is improved, but cost is worsened

Engineering Contradiction:
Improvedata securityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent enables a single device to serve multiple functions: both personal and business applications can run on the same device simultaneously. The container application creates an isolated environment for business apps, allowing the device to function as both a personal device and a secure business device. This multi-functionality eliminates the need for companies to provision separate dedicated devices for business use, reducing costs while maintaining data security through containerization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11604688B2Container application for android-based devices
Publication Date: 2023.03.14 CROWDSTRIKE
  • US11604688B2 patent drawing
  • US11604688B2 patent drawing
  • US11604688B2 patent drawing

AI summary

A computer-processor executable container application operates within an operating system, such as an Android operating system. The application is itself configured to execute applications contained within the container application. The container application may create a secure computing environment in which business applications on a computing device can be protected and monitored without affecting or interacting with other applications or data on the computing device. Such a secure computing environment may enable businesses to protect their data residing on a personal computing device and to have visibility into how the data is accessed, used, and shared, while not interfering with personal use of the personal computing device.