Application Distribution System with Gateway Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of personal electronic devices in the workplace poses challenges in securing company data, transferring data securely to company computers, ensuring the trustworthiness of applications, and making new applications available while maintaining data security and policy compliance.
Innovation Solution
A method for deploying applications to endpoint devices that includes obtaining and launching applications, connecting them to a gateway for authentication and policy enforcement, ensuring device and user binding, and invoking application logic only after successful authentication and policy compliance, utilizing an application framework, distribution system, and gateway for encryption, authentication, and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If applications are made available on personal electronic devices, then application availability and productivity improve, but security risks and data protection challenges worsen
Solution Approach 1:
The patent introduces an application distribution system that acts as an intermediary between application sources and personal electronic devices. This system includes a marketplace that vets applications, a distribution mechanism that delivers them securely, and a gateway that enforces security policies during deployment and execution, thereby enabling application availability while maintaining data security through multiple layers of mediation and control
Solution Approach 2:
The system performs preliminary vetting and analysis of applications in the marketplace before they are distributed to personal devices. Applications are analyzed for security compliance and policy conformance in advance, ensuring that only trustworthy applications reach users' devices, thus preventing security issues before they occur
2Ease of operation
If data is transferred from personal devices to company computers, then data accessibility improves, but transmission security challenges worsen
Solution Approach 1:
The gateway serves as an intermediary that mediates all data transfers between personal devices and company computers. It enforces security policies during transmission, authenticates users and applications, and controls data flow, thereby enabling easy data transfer while protecting against security threats through policy enforcement at the transmission point
3Reliability
If applications are vetted for trustworthiness, then application reliability improves, but deployment complexity worsens
Solution Approach 1:
The patent merges the vetting, distribution, and deployment functions into a single integrated application distribution system. The marketplace analyzes applications for trustworthiness, the distribution mechanism delivers them, and the gateway enforces policies - all as part of one unified system that automates the complex vetting and deployment process, making it manageable despite the complexity involved
Data Source
AI summary
A system and method are disclosed for deploying applications to end point devices. The applications are obtained from a marketplace that checks the applications and packages them for endpoint use according to certain policies. Packaging an application includes compiling or assembling and linking the application, possibly with a framework and possibly with a binding token, which can be a device binding token and/or a user binding token. The application is loaded onto an endpoint device and if the application is bound to the device and the user is allowed to use the application, the application is enabled to be used on the endpoint device. A gateway between the endpoint device and an authentication server helps to authenticate the user. The gateway also manages data transfers between the endpoint device and a data server according to a selected protocol.


