Application Sandbox Allocation via Metadata-Driven Environment Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices lack an automated mechanism to allocate applications to sandboxes based on application-specific data, requiring manual user intervention and failing to guarantee an independent execution space for applications.
Innovation Solution
An electronic device with a communication module, processor, and memory that automatically installs and allocates applications to specific environments without user input, based on metadata indicating the required execution environment, ensuring secure and independent operation of applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual user intervention is used to allocate applications to sandboxes, then user control over application placement is improved, but automation level deteriorates and user burden increases
Solution Approach 1:
The application itself provides the necessary information (metadata indicating sandbox requirement) to enable the electronic device to automatically determine and allocate the application to the appropriate environment without requiring user intervention or manual configuration
Solution Approach 2:
The metadata indicating sandbox execution requirements is prepared in advance within the application package before installation, allowing the electronic device to automatically identify and allocate the application to the appropriate environment during the installation process itself
2Device complexity
If applications are executed in a shared environment, then system simplicity is improved, but data isolation and security deteriorate
Solution Approach 1:
The system divides the execution environment into distinct segments (first environment and second environment) with different security levels and data access permissions, allowing applications to be allocated to appropriate segments based on their sandbox requirements while maintaining overall system structure
Solution Approach 2:
Different execution environments are created with different local qualities - the first environment provides full data access while the second environment provides restricted access with data isolation, allowing each application to operate in the environment most suitable for its security requirements
3Extent of automation
If automated allocation based on application data is implemented, then automation level and security are improved, but system complexity increases
Solution Approach 1:
The metadata indicating sandbox execution requirements is prepared in advance within the application package before installation, allowing the electronic device to automatically identify and allocate the application to the appropriate environment during the installation process itself, avoiding the need for complex post-installation analysis mechanisms
Solution Approach 2:
Metadata serves as an intermediary element that carries information about sandbox execution requirements from the application to the electronic device, enabling automated allocation without requiring the device to perform complex analysis of application code or data structures
Data Source
AI summary
An electronic device and method of controlling an electronic device are provided. The electronic device includes a communication module; a processor; and a memory that stores instructions to instruct the processor to install a first application operating only in a first environment, install a second application selectively operating in at least one of the first environment and a second environment, grant access to the first application to first data, the first data being generated while the second application operates in the first environment, deny access to the first application to second data, the second data being generated while the second application operates in the second environment, grant access to the second application to third data, the third data being generated while the first application operates in the first environment, and allocate the second application to at least the second environment without a user's input when the second application is installed.


