Certificate Management Segregating Corporate and Personal Memory Spaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing communication devices used for both personal and corporate purposes often restrict access, leading to a poor user experience due to IT policies that limit application installation and data security, without effectively segregating corporate and personal data.

Innovation Solution

Implementing a method to segregate memory spaces on communication devices into personal and corporate areas, allowing for dual modes of operation, where corporate data is encrypted and secured, and personal data is accessible while preventing access to corporate data by personal applications, with IT policies controlling data access and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT policies are implemented to secure corporate data on communication devices, then corporate data security is improved, but user experience deteriorates due to restricted application installation and device access

Engineering Contradiction:
Improvecorporate data securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the communication device into distinct work and personal modes with separate certificate stores and application environments. Corporate applications operate in work mode with full security restrictions, while personal applications run in personal mode with relaxed restrictions, allowing users to access both corporate and personal functions without compromising security in either domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically switches between work and personal modes based on the application being executed. The device can transition between these modes seamlessly, applying different IT policy restrictions appropriate to each mode. This dynamic behavior allows the same device to provide both secure corporate access and flexible personal use experience.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If IT policies restrict application installation to approved locations only, then virus spread prevention is improved, but application installation flexibility deteriorates

Engineering Contradiction:
Improvevirus spread preventionVSAvoidapplication installation flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent creates separate certificate stores for work and personal modes. In work mode, only certificates from approved corporate locations are trusted, preventing virus spread. In personal mode, the device accepts certificates from various sources including personal email and web browsers, providing installation flexibility without affecting corporate security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security trust levels are applied to different operational contexts. Corporate applications require strict verification from approved sources only, while personal applications allow broader certificate sources. This local quality approach ensures security where needed while providing flexibility where appropriate.

Inventive Principle:
Principle #3Local quality

3Reliability

If the communication device is locked to prevent unauthorized access, then data security is improved, but device accessibility deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The device implements dynamic access control based on operational mode. In work mode, the device is locked with strict authentication requirements to protect corporate data. In personal mode, the device is more accessible with relaxed authentication, allowing users to freely access personal applications and data without compromising corporate security.

Inventive Principle:
Principle #15Dynamics

4Reliability

If corporate and personal applications are segregated into different memory spaces, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidmemory space management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments memory into distinct work and personal spaces with separate certificate stores and application containers. This segmentation ensures that corporate data and personal data are isolated, preventing unauthorized access. The operating system automatically manages this segmentation through mode switching, hiding the complexity from users while maintaining security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2629479B1Certificate management method based on connectivity and policy
Publication Date: 2020.04.22 BLACKBERRY LTD
  • EP2629479B1 patent drawingFigure 1
  • EP2629479B1 patent drawingFigure 2
  • EP2629479B1 patent drawingFigure 3

AI summary

Plural modes of operation may be established on a mobile device. Specific modes of operation of the mobile device may be associated with specific spaces in memory. By associating the existing certificate store structure and key store structure with a mode of operation, certificates and keys can be assigned to one space among plural spaces. Furthermore, management (viewing/importation/deletion) of certificates associated with specific modes of operation may be controlled based on the presence or absence of a mobile device administration server and the status (enabled/disabled) of an IT policy.