Dynamic Application Containers for Mobile Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing different classifications of data on handheld mobile devices, particularly in mixed user settings, is challenging due to the difficulty in isolating personal versus corporate data and enforcing appropriate interaction boundaries between applications.

Innovation Solution

Implementing a method that dynamically organizes applications into container groups based on various conditions, such as policy constraints, installation sources, and device states, to enforce interaction boundaries and manage access through a device management agent, allowing applications to participate in multiple containers and change membership as conditions change.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications are isolated into separate containers for different data classifications, then data security is improved, but application interaction capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidapplication interaction capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces container groups as intermediary structures between individual application containers. These container groups enable controlled interaction between applications from different containers by providing a managed interface that maintains security boundaries while allowing necessary data and function exchange. The container group acts as a mediator that reconciles the isolation requirements with interaction needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a nested container structure where individual application containers are nested within container groups. This hierarchical nesting allows applications to maintain their individual security boundaries while being part of a larger collaborative group. The nested structure enables both isolation (at the container level) and interaction (at the container group level) simultaneously.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Device complexity

If static container membership is used for applications, then system complexity is reduced, but adaptability to changing conditions deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidadaptability to changing conditions
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic container membership where applications can be automatically added to or removed from container groups based on changing conditions such as device state, policy constraints, and installation sources. This dynamic behavior allows the system to adapt to different scenarios without requiring manual reconfiguration, maintaining low complexity while achieving high adaptability through automated condition-based rules.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If dynamic container membership is implemented, then adaptability to changing conditions is improved, but system complexity increases

Engineering Contradiction:
Improveadaptability to changing conditionsVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the container management system automatically monitors conditions and performs membership changes without user intervention. The system evaluates conditions such as device state, policy constraints, and installation sources, and automatically adds or removes applications from container groups based on these evaluations. This automation reduces the perceived complexity for users while maintaining the adaptive functionality.

Inventive Principle:
Principle #25Self-service

4Reliability

If strict interaction boundaries are enforced between containers, then data security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The container group serves as an intermediary that simplifies operation by providing a unified interface for interacting with multiple containers. Users can work with container groups as single entities rather than managing individual container boundaries, making operations easier while the underlying strict boundaries between containers maintain security. The intermediary abstracts the complexity of multiple boundaries into a single manageable interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3195123B1Dynamic application containers
Publication Date: 2020.11.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3195123B1 patent drawingFigure 1
  • EP3195123B1 patent drawingFigure 2

AI summary

Managing application interaction on a device using dynamic containers. A method includes, for a set of applications on a device, based on certain conditions, determining a plurality of container groups. Each container group defines a set of applications and a set of interactions parameters defining boundaries of interactions between the applications for the applications in the container group. The method further includes identifying one or more changes in the certain conditions. As a result of identifying one or more changes in the certain conditions, the method includes changing membership in the container groups.