Code Injection for Mobile App Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device-based security models fail to distinguish between corporate and personal data on employee-owned devices, leading to unnecessary locking or loss of personal data, and require proprietary SDKs or libraries for application-level security, limiting vendor independence and flexibility.

Innovation Solution

A code injection approach for mobile information management that allows security policies to be dynamically wrapped around applications without recompilation, using a middleware system with a governance console and security console to manage and apply policies at the application level, independent of specific vendors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-based security models are used to protect corporate data on employee-owned devices, then corporate data security is improved, but personal data may be locked up or lost along with enterprise data

Engineering Contradiction:
Improvecorporate data securityVSAvoidpersonal data accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the security model from the device itself, applying security policies at the application level rather than device level. This allows corporate applications to have security restrictions while personal applications remain accessible, resolving the contradiction between corporate data security and personal data accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security policies to different applications based on their classification (corporate vs. personal). Each application receives tailored security treatment rather than uniform device-wide security, allowing corporate data protection without affecting personal data accessibility.

Inventive Principle:
Principle #3Local quality

2Reliability

If application-based security with proprietary SDK or library is used, then security policy enforcement is improved, but vendor independence is reduced and application recompilation is required for policy updates

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidvendor independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component that acts as a security policy enforcement mechanism without requiring proprietary SDKs or libraries. This intermediary layer enables security policy enforcement while maintaining vendor independence and allowing dynamic policy updates without application recompilation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamics by making security policies dynamically updateable without requiring application recompilation. Security policies can be modified and deployed in real-time, providing adaptability and vendor independence while maintaining effective security enforcement.

Inventive Principle:
Principle #15Dynamics

3Reliability

If device-based security is applied to employee-owned devices, then corporate data protection is improved, but device complexity increases due to need to separate personal and corporate data

Engineering Contradiction:
Improvecorporate data protectionVSAvoiddata separation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security enforcement mechanism from the device operating system and implements it at the application level. This extraction simplifies the device complexity by avoiding the need for complex device-wide security management while still providing effective corporate data protection through application-specific security policies.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9280660B2Mobile information management methods and systems
Publication Date: 2016.03.08 COGNIZANT TECHNOLOGY SOLUTIONS US CORP
  • US9280660B2 patent drawing
  • US9280660B2 patent drawing
  • US9280660B2 patent drawing

AI summary

A system and method are disclosed for mobile information management using a code injection approach. The method for information management of applications includes the steps of: receiving, by a computer, one or more compiled applications, and receiving, by a computer, one or more security policies, wherein each security policy indicates one or more use cases and one or more security actions associated with each use case. The method also includes the step of associating the received applications with the one or more received security policies. Additionally, the method includes the step of automatically wrapping the received applications with the associated security policy using a code injection script.