Cloud-Based Mobile Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The proliferation of mobile devices in enterprises poses challenges for IT administrators due to their uncontrolled nature and diverse platforms, leading to difficulties in enforcing security policies and managing device security, as traditional antivirus solutions are ineffective and resource-intensive, and social media usage affects productivity while creating legal liabilities.

Innovation Solution

A cloud-based system that monitors and analyzes traffic from mobile devices, enforces policies by blocking or allowing traffic based on predefined guidelines, detects security threats, and manages device functions, providing granular control and compliance reporting, regardless of device type or platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional antivirus solutions are deployed on mobile devices, then security protection is provided, but device performance degrades and user experience is worsened due to limited processor, memory, and battery resources

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the security scanning function from the mobile device itself and relocates it to a remote server. The mobile device only needs to transmit data packets for analysis, while the computationally intensive security scanning is performed remotely, thus preserving device performance while maintaining security protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a remote server as an intermediary between the mobile device and the security threat database. The server acts as a mediator that receives data packets from the device, performs security analysis, and returns results, thereby offloading the computational burden from the mobile device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security apps are installed on mobile devices, then security monitoring is enabled, but deployment becomes complex and updates are difficult due to platform restrictions and user control

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a system where the mobile device automatically transmits data packets to the remote server without requiring user intervention for installation or configuration. The security monitoring is self-service in nature, with the device autonomously participating in the security analysis process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a platform-independent solution that works across different mobile operating systems (iOS, Android, etc.). The remote server architecture provides universal security monitoring capabilities that are not constrained by platform-specific restrictions, enabling broad applicability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If social media websites are blocked to improve productivity, then employee focus is enhanced, but employee dissatisfaction increases and controlled access is lost

Engineering Contradiction:
Improveemployee focusVSAvoiduser satisfaction
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements dynamic policy enforcement that can adapt to different situations, users, and time periods. Rather than static blocking, the system allows flexible control over social media access based on organizational needs, enabling productivity improvements while maintaining user satisfaction through controlled access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of website access from binary (blocked/allowed) to a more nuanced state with different levels of control. The system can modify access parameters such as time-based restrictions, user-based permissions, and application-specific controls to balance productivity and user satisfaction.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If comprehensive security scanning is performed on mobile devices, then security threats are detected, but battery power is depleted and device resources are consumed

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidbattery power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the energy-intensive security scanning operation from the mobile device and performs it remotely on a server with adequate computational resources. The mobile device only transmits minimal data packets for analysis, thereby detecting security threats without depleting battery power.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11716359B2Mobile device security, device management, and policy enforcement in a cloud-based system
Publication Date: 2023.08.01 ZSCALER INC
  • US11716359B2 patent drawing
  • US11716359B2 patent drawing
  • US11716359B2 patent drawing

AI summary

Mobile device security, device management, and policy enforcement are described in a cloud-based system where the “cloud” is used to pervasively enforce security and policy and perform device management regardless of device type, platform, location, etc. A method includes receiving one or more mobile profiles for one or more mobile devices each associated with a user from an enterprise; responsive to enrollment of a mobile device of the one or more mobile devices, communicating to the mobile device; determining an associated mobile profile of the one or more mobile profiles for the mobile device; and configuring the mobile device based on the associated mobile profile.