Dynamic Application Containers for Mobile Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing different classifications of data on handheld mobile devices, particularly in mixed user settings, is challenging due to the difficulty in isolating personal versus corporate data and enforcing appropriate interaction boundaries between applications.
Innovation Solution
Implementing a method that dynamically organizes applications into container groups based on various conditions, such as policy constraints, installation sources, and device states, to enforce interaction boundaries and manage access through a device management agent, allowing applications to participate in multiple containers and change membership as conditions change.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If applications are isolated into separate containers for different data classifications, then data security is improved, but application interaction capability deteriorates
Solution Approach 1:
The patent introduces container groups as intermediary structures between individual application containers. These container groups enable controlled interaction between applications from different containers by providing a managed interface that maintains security boundaries while allowing necessary data and function exchange. The container group acts as a mediator that reconciles the isolation requirements with interaction needs.
Solution Approach 2:
The patent implements a nested container structure where individual application containers are nested within container groups. This hierarchical nesting allows applications to maintain their individual security boundaries while being part of a larger collaborative group. The nested structure enables both isolation (at the container level) and interaction (at the container group level) simultaneously.
2Device complexity
If static container membership is used for applications, then system complexity is reduced, but adaptability to changing conditions deteriorates
Solution Approach 1:
The patent implements dynamic container membership where applications can be automatically added to or removed from container groups based on changing conditions such as device state, policy constraints, and installation sources. This dynamic behavior allows the system to adapt to different scenarios without requiring manual reconfiguration, maintaining low complexity while achieving high adaptability through automated condition-based rules.
3Adaptability or versatility
If dynamic container membership is implemented, then adaptability to changing conditions is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service mechanisms where the container management system automatically monitors conditions and performs membership changes without user intervention. The system evaluates conditions such as device state, policy constraints, and installation sources, and automatically adds or removes applications from container groups based on these evaluations. This automation reduces the perceived complexity for users while maintaining the adaptive functionality.
4Reliability
If strict interaction boundaries are enforced between containers, then data security is improved, but ease of operation deteriorates
Solution Approach 1:
The container group serves as an intermediary that simplifies operation by providing a unified interface for interacting with multiple containers. Users can work with container groups as single entities rather than managing individual container boundaries, making operations easier while the underlying strict boundaries between containers maintain security. The intermediary abstracts the complexity of multiple boundaries into a single manageable interface.
Data Source
Figure 1
Figure 2
AI summary
Managing application interaction on a device using dynamic containers. A method includes, for a set of applications on a device, based on certain conditions, determining a plurality of container groups. Each container group defines a set of applications and a set of interactions parameters defining boundaries of interactions between the applications for the applications in the container group. The method further includes identifying one or more changes in the certain conditions. As a result of identifying one or more changes in the certain conditions, the method includes changing membership in the container groups.