Device Access Token Management for BYOD Data Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for terminating access to company networks from personal devices are overly restrictive and destructive, often resulting in loss of personal data when an employee leaves or loses their device, as they require wiping or factory resetting, which is undesirable and lacks flexibility.
Innovation Solution
A system and method for registering, authenticating, and authorizing computing devices to access network resources using a server that generates tokens with a time-to-live, allowing for secure and flexible management of access without deleting personal data, enabling administrators to disable specific applications or devices without modifying device data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods (remote wipe or factory reset) are used to terminate access to company networks from personal devices, then security is improved, but personal data is lost
Solution Approach 1:
The patent segments the device into company-managed portions and personal portions. The company can only manage and secure its own data and applications, while personal data remains separate and protected from company management actions. This is achieved through containerization or virtualization techniques that create isolated environments for company resources on personal devices.
Solution Approach 2:
The patent introduces an intermediary management layer that sits between the company's network resources and the personal device. This intermediary enables secure access control and data protection without requiring direct manipulation of the personal device's entire filesystem, thus preventing unnecessary data loss while maintaining security.
2Reliability
If remote wipe or factory reset is performed to secure company networks, then access control is improved, but device usability is worsened
Solution Approach 1:
By segmenting company resources from personal data, the patent enables selective management actions. The company can disable or remove only company-related applications and data without affecting personal data or device functionality, thus maintaining access control while preserving device usability for personal purposes.
3Reliability
If company data is separated from personal data on personal devices, then data protection is improved, but device complexity is worsened
Solution Approach 1:
The patent employs universal containerization or virtualization technologies that can be applied across different device types and operating systems. These technologies provide automated data separation and management capabilities without requiring complex custom implementations for each device, thus achieving data protection while minimizing the increase in device complexity.
Data Source
AI summary
A system includes one or more processors to receive a registration request, the registration request comprising a representation of a username and a password, verify the username and the password and transmit a one-time-use password, receive the one-time-use password and first device identifier information from a mobile computing device, receive an access request from the mobile computing device comprising the representation of the username and the password, second device identifier information, and application key information, verify the username, the password, the second device identifier information, and the application key information, and transmit a token to the mobile computing device, and receive a resource request from the mobile computing device comprising the token and third device identifier information.


