Context-Aware Mobile Device Locking for Secure Enterprise Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need to control and manage mobile devices to ensure secure access to enterprise resources while allowing personal use, as employees often use the same devices for both business and personal purposes, posing security risks.
Innovation Solution
Implementing a system that locks a mobile device based on context parameters such as location, network connections, settings, and current time, using a user name to determine whether to switch the device to a locked or unlocked mode, and selecting applications to present accordingly, ensuring secure access to enterprise resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the mobile device allows full access to all applications, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent segments the mobile device interface into different operational modes (locked mode and unlocked mode) with distinct application access rights. In locked mode, only selected applications are accessible, while in unlocked mode, full application access is permitted. This segmentation allows the system to provide both security and ease of operation by switching between restricted and unrestricted access based on contextual conditions.
Solution Approach 2:
The patent implements a dynamic interface that can transition between locked and unlocked states based on real-time context monitoring. The system dynamically adjusts application accessibility by monitoring parameters such as location, time, network connectivity, and device state, thereby adapting the level of security to current operational conditions while maintaining user convenience.
2Reliability
If the mobile device implements strict access control, then security is improved, but ease of operation is worsened
Solution Approach 1:
The patent applies local quality by providing different levels of access control for different applications and different contexts. Instead of a uniform access policy, the system selectively applies restrictions only to specific applications or functionality based on the current context (e.g., location, time of day, network environment), while allowing unrestricted access to other applications, thereby maintaining both security and ease of operation.
Solution Approach 2:
The system automatically monitors contextual parameters and makes decisions about access control without requiring manual user intervention. The mobile device self-evaluates its current state against predefined policies and autonomously switches between locked and unlocked modes, reducing the burden on users while maintaining strong security controls.
3Reliability
If the mobile device monitors multiple context parameters, then security control is improved, but device complexity is worsened
Solution Approach 1:
The patent employs a universal context monitoring framework that can evaluate multiple parameters (location, time, network connectivity, device state) through a single integrated system. This multi-functional approach allows the device to assess various security-relevant conditions using existing hardware and software components, avoiding the need for separate dedicated systems for each monitoring function and thereby reducing overall complexity.
Solution Approach 2:
The system manages complexity by dynamically adjusting the number and type of monitored parameters based on current conditions and policy requirements. Rather than continuously monitoring all possible parameters, the system selectively activates relevant monitoring functions based on the current operational context, reducing processing overhead and system complexity while maintaining effective security control.
Data Source
AI summary
A method and system for locking a mobile device on an interface are described. A user logs on to a mobile device with a user name. The mobile device then determines a context for the mobile device based on one or more operational parameters and/or the user name. For example, a context for the mobile device may be a current location of the device. Based on the context and user name, the mobile device may run in locked mode. In locked mode, applications are selected to be presented on the mobile device based on the user name and context. The mobile device is locked on a springboard that presents only the selected applications to the user for launching. A user may switch between launched applications on the mobile device, but the user may only switch between launched applications that are presented on the springboard.


