Appbox Segmentation for Enterprise Data Security on Portable Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise mobility management systems face challenges in securely managing enterprise data and applications on portable devices, particularly in BYOD environments, where privacy and device performance are compromised, and existing solutions either incur high costs or slow down devices.
Innovation Solution
A system and method utilizing appboxes on portable devices to securely manage enterprise applications and data, featuring AppGuard for authentication and security, AppHealth for monitoring and remediation, and an admin module for remote configuration and management, ensuring privacy and performance without monitoring personal device usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MDM solutions are used to manage portable communication devices, then device health and application control are improved, but user privacy and freedom are curtailed due to continuous monitoring
Solution Approach 1:
The system segments device management into two distinct modes: full monitoring mode for enterprise devices and restricted monitoring mode for personal devices. This segmentation allows selective application of monitoring policies based on device ownership, thereby maintaining device health management capabilities while preserving user privacy for personal devices.
Solution Approach 2:
The system applies different monitoring qualities to different devices based on their ownership status. Enterprise-owned devices receive full monitoring for health and security, while personal devices receive limited monitoring only for security-related events. This local differentiation resolves the contradiction by tailoring monitoring intensity to device context.
2Ease of operation
If MAM solutions are used to control access to business applications, then application provisioning is improved, but user privacy is compromised due to continuous application monitoring
Solution Approach 1:
The system segments application management into enterprise applications and personal applications, applying different monitoring policies to each segment. Enterprise applications receive full monitoring for security and compliance, while personal applications are excluded from monitoring, thus maintaining ease of operation for business apps while preserving user privacy for personal apps.
Solution Approach 2:
The system applies monitoring quality locally to each application based on its ownership status. Business applications receive comprehensive monitoring for provisioning and security, while personal applications are exempt from monitoring. This local quality differentiation resolves the contradiction by targeting monitoring only where business needs dictate.
3Reliability
If type 1 mobile virtualization is implemented, then enterprise application isolation is improved, but vendor acceptance is limited due to hardware-level hypervisor requirements
Solution Approach 1:
The system introduces a software-based virtualization layer that acts as an intermediary between the hardware and enterprise applications. This intermediary layer provides application isolation and virtualization benefits without requiring hardware-level hypervisors, thereby maintaining application isolation reliability while improving vendor compatibility and device versatility.
Solution Approach 2:
The system replaces hardware-level virtualization mechanisms with software-based virtualization. Instead of relying on hardware hypervisors that limit vendor acceptance, the system uses software emulation and sandboxing techniques to achieve application isolation, thus resolving the contradiction between isolation reliability and vendor adaptability.
4Adaptability or versatility
If type 2 mobile virtualization is implemented, then multiple operating systems can run simultaneously, but device performance is slowed down
Solution Approach 1:
The system segments the execution environment into isolated virtual containers for different operating systems. Each container runs independently with its own resource allocation, allowing multiple OSes to coexist without interfering with each other's performance. This segmentation maintains OS compatibility while minimizing performance impact through controlled resource isolation.
Solution Approach 2:
The system implements partial virtualization where only the necessary virtualization features are applied to maintain performance. Instead of full virtualization that overheads performance, the system uses selective virtualization mechanisms that provide OS compatibility where needed while maintaining native performance for critical operations, thus resolving the contradiction between versatility and speed.
5Ease of manufacture
If BYOD approach is adopted, then device acquisition costs are reduced, but security management becomes difficult
Solution Approach 1:
The system segments device management into personal device zones and enterprise application zones. Personal devices are managed with minimal intervention, reducing acquisition costs for enterprises, while enterprise applications are isolated in secure containers with comprehensive security monitoring. This segmentation resolves the contradiction by applying different management strategies to different parts of the ecosystem.
Solution Approach 2:
The system introduces a security intermediary layer between personal devices and enterprise applications. This intermediary provides authentication, authorization, and security monitoring without requiring enterprise control of the personal devices themselves. It enables BYOD cost savings while maintaining data security through centralized security policy enforcement at the application level.
Data Source
AI summary
A system and computer-implemented method for securely managing enterprise related applications and associated data on one or more portable communication devices is provided. The system comprises one or more appboxes, residing on the one or more portable communication devices, configured to secure, monitor and collect information related to at least one of: one or more applications and associated data and the one or more portable communication devices. The system further comprises a server configured to facilitate one or more administrators to monitor and manage overall functionality of at least one of: the one or more applications and associated data and the one or more portable communication devices using the collected information.


