Dual-Mode Mobile OS Segregating Corporate and Personal Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for managing mobile devices used for both personal and corporate purposes often restrict user experience by locking down the device, limiting application installation and access, which can be inefficient and inflexible.

Innovation Solution

Implementing a dual-mode operation system on mobile devices that segregates applications and data into personal and corporate spaces, allowing for separate memory areas and access control mechanisms to enforce IT policies, ensuring corporate data security while allowing personal applications and data on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT policies are implemented to limit data exposure risk on mobile devices, then corporate data security is improved, but user experience deteriorates due to device locking and limited application installation

Engineering Contradiction:
Improvecorporate data securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the mobile device into separate work and personal modes with distinct application environments. The work mode contains corporate applications and data subject to IT policies, while the personal mode allows unrestricted personal applications. This segmentation resolves the contradiction by providing security for corporate data in work mode while maintaining user freedom in personal mode, eliminating the need to lock down the entire device.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the mobile device is locked to prevent virus spread, then data security is improved, but application installation flexibility deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidapplication installation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The device is segmented into work and personal modes where different security policies apply. The work mode enforces restricted application installation from approved sources only, while the personal mode allows installation from any source. This resolves the contradiction by applying security restrictions only where necessary (work mode) while maintaining flexibility elsewhere (personal mode).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security characteristics are applied to different parts of the system. The work mode has strict security controls for corporate data protection, while the personal mode has relaxed controls for user convenience. This local differentiation of security quality allows the system to be secure where needed without sacrificing flexibility overall.

Inventive Principle:
Principle #3Local quality

3Reliability

If the mobile device is restricted regarding non-work applications, then corporate data security is improved, but user functionality deteriorates

Engineering Contradiction:
Improvecorporate data securityVSAvoiduser functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates separate work and personal modes that can coexist on the same device. Users can install and run personal applications in personal mode without affecting corporate data security in work mode. The system automatically manages which mode is active and prevents unauthorized access between modes, thus maintaining both security and functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobile device is designed to serve multiple functions simultaneously - both corporate and personal uses - through the dual-mode architecture. The same physical device can securely handle corporate applications during work mode and personal applications during personal mode, making the device universal rather than requiring separate devices for different purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2951676B1Managing application access to data
Publication Date: 2020.12.30 BLACKBERRY LTD
  • EP2951676B1 patent drawingFigure 1
  • EP2951676B1 patent drawingFigure 2
  • EP2951676B1 patent drawingFigure 3

AI summary

Plural modes of operation, each associated with a class attribute, may be established on a mobile device. The present application discloses a method of handling an application launch request, a computing device for carrying out the method and a computer readable medium for adapting a processor to carry out the method. The method includes receiving a launch request identifying an application that is to be launched, acquiring an identity for the application, acquiring a class for the application, labeling the application with the identity and the class and launching the application.