Docking-Based Boot Image Segmentation for BYOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing BYOD architectures face security threats and privacy concerns due to personal devices being connected to enterprise networks, with potential resource consumption and lack of trust in user-installed applications and OS configurations.

Innovation Solution

An information handling system with a management controller that determines if docked or undocked, booting from a personal image when undocked and an enterprise image when docked, ensuring secure and efficient resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal devices are connected to enterprise networks for BYOD scenarios, then user convenience and device autonomy are improved, but security threats and privacy concerns increase

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the boot image into two distinct parts: a personal image stored locally on the user's device and an enterprise image stored on the docking station. The management controller selectively boots from one or the other based on docking state, creating clear separation between personal and enterprise environments. This segmentation allows users to maintain personal customizations while ensuring enterprise security requirements are met when connected to the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The management controller acts as an intermediary between the personal device and the enterprise network infrastructure. It automatically determines the docking state and selects the appropriate boot image without user intervention. This intermediary function resolves the security-privacy contradiction by transparently managing which image loads based on the physical connection state, preventing users from accidentally booting enterprise-critical applications from personal images while at home.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators require enterprise applications to be installed on personal devices to ensure security, then enterprise security standards are improved, but personal device resources are consumed

Engineering Contradiction:
Improveenterprise security standardsVSAvoidpersonal device resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The enterprise image, including all enterprise applications, security policies, and configurations, is extracted from the personal device and stored externally on the docking station infrastructure. When the device is docked, the system boots from this external enterprise image rather than from the personal image. This extraction eliminates the need for personal device storage, processing power, and battery capacity to support enterprise applications, while still maintaining security standards when connected to the enterprise network.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the system boots from personal image when undocked, then user privacy and device autonomy are improved, but security control by administrators is reduced

Engineering Contradiction:
Improvedevice autonomyVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically changes its boot behavior based on the physical docking state. When undocked (mobile/remote), it boots from the personal image to maximize user autonomy and privacy. When docked (enterprise environment), it automatically boots from the enterprise image to enforce security controls. This dynamic adaptation resolves the contradiction by allowing both personal autonomy and enterprise security control at different times based on the device's physical context, rather than requiring a fixed configuration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11989564B2Systems and methods for ensuring security for bring-your-own device scenarios
Publication Date: 2024.05.21 DELL PROD LP
  • US11989564B2 patent drawing
  • US11989564B2 patent drawing

AI summary

An information handling system may include a processor, a management controller communicatively coupled to the processor for out-of-band management of the information handling system, and configured to determine if the information handling system is docked to a docking station, boot the information handling system from a personal image local to the information handling system if the information handling system is undocked from the docking station, and boot the information handling system from an enterprise image stored on the docking station if the information handling system is docked to the docking station.