Application Gateway with Managed Containers for Offline Content Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional content control software and services are inadequate in managing content downloaded by users to their computers, particularly for enterprises wanting to retain control over enterprise content on devices not owned or controlled by them.

Innovation Solution

An application gateway server computer communicates with managed containers on client devices to control and manage enterprise content, providing a secure shell and managed cache that encrypts data, applies rules for storage and access, and ensures updates are propagated from backend systems, even when offline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional content control software is used to block access to certain websites or limit application usage time, then access control is improved, but control over downloaded content on user devices is lost

Engineering Contradiction:
Improvecontent control capabilityVSAvoidcontrol over downloaded content
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a gateway server as an intermediary between the content delivery network and user devices. This gateway intercepts content requests, applies security policies, and manages downloaded content remotely. The gateway acts as a mediator that maintains enterprise control over content even after it's downloaded to user devices, resolving the contradiction between ease of content access and reliability of content control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by establishing security policies and rules before content is downloaded to user devices. The gateway server pre-configures content control parameters, encryption methods, and access restrictions. This preliminary setup ensures that even when content is downloaded offline, the control mechanisms are already in place, maintaining reliability of content control while allowing easy user access.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If content is downloaded to user devices for offline access, then accessibility is improved, but control and security management becomes difficult

Engineering Contradiction:
Improveoffline access capabilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway server serves as a centralized intermediary that manages security policies for multiple user devices. Instead of implementing complex security management on each individual device, the gateway maintains and distributes security configurations, simplifying the overall system architecture while enabling offline access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway server provides universal security management functionality across diverse user devices and content types. It handles multiple security policies, encryption methods, and content control scenarios through a single unified system, reducing the complexity that would otherwise need to be implemented separately on each device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security policies are enforced on user devices, then content protection is improved, but update propagation to offline devices becomes challenging

Engineering Contradiction:
Improvecontent protectionVSAvoidpolicy update propagation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The gateway server implements preliminary action by maintaining a queue of security policies and rules that are prepared in advance. When devices come online, pre-configured policy updates are immediately available for propagation. This preliminary preparation minimizes the time loss associated with updating offline devices, while maintaining reliable content protection through pre-vetted security policies.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If managed containers are implemented on client devices to provide secure shell and cache management, then security control is improved, but device resource usage increases

Engineering Contradiction:
Improvesecure content managementVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the security management functionality into a separate managed container that runs on the user device. This container is responsible for enforcing security policies and managing content cache, while the main device operating system remains unaffected. The segmentation isolates resource consumption to a dedicated container, improving secure content management while containing resource usage to specific system portions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12373548B2Application gateway architecture with multi-level security policy and rule promulgations
Publication Date: 2025.07.29 OPEN TEXT SA ULC
  • US12373548B2 patent drawing
  • US12373548B2 patent drawing
  • US12373548B2 patent drawing

AI summary

Embodiments of an application gateway architecture may include an application gateway server computer communicatively connected to backend systems and client devices operating on different platforms. The application gateway server computer may include application programming interfaces and services configured for communicating with the backend systems and managed containers operating on the client devices. The application gateway server computer may provide applications that can be centrally managed and may extend the capabilities of the client devices, including the ability to authenticate across backend systems. A managed container may include a managed cache and may provide a secure shell for applications received from the application gateway server computer. The managed container may store the applications in the managed cache and control access to the managed cache according to rules propagated from at least one of the backend systems via the application gateway server computer.