Dynamic Perimeter Generation for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security protocols for managing electronic resources are inadequate in dynamically separating and securing resources across different perimeters, such as personal and enterprise environments, often requiring manual configuration and additional administrative steps.

Innovation Solution

A wireless communication device dynamically generates perimeters based on detected settings or policies, such as those associated with enterprise accounts, to securely separate resources and manage access privileges, allowing for automatic creation of enterprise perimeters without additional user or administrator intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration and administrative steps are used to create perimeters, then security control is achieved, but device complexity and time consumption increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically detects trigger events (such as adding an enterprise account) and dynamically generates appropriate perimeters without requiring manual user configuration. The device serves itself by monitoring account settings, identifying security requirements, and creating the necessary perimeter structures automatically, thereby maintaining security control while eliminating configuration complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary detection of account settings and security policies before perimeter creation is needed. By continuously monitoring for trigger events and pre-configuring security parameters based on detected settings, the system prepares the security framework in advance, so that when enterprise resources are added, the perimeter is already ready and requires no additional administrative steps

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual configuration and administrative steps are used to create perimeters, then security control is achieved, but time consumption increases

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically detects trigger events (such as adding an enterprise account) and dynamically generates appropriate perimeters without requiring manual user configuration. The device serves itself by monitoring account settings, identifying security requirements, and creating the necessary perimeter structures automatically, thereby maintaining security control while eliminating configuration time

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary detection of account settings and security policies before perimeter creation is needed. By continuously monitoring for trigger events and pre-configuring security parameters based on detected settings, the system prepares the security framework in advance, so that when enterprise resources are added, the perimeter is already ready and requires no additional administrative steps

Inventive Principle:
Principle #10Preliminary action

3Reliability

If resources are separated into different perimeters, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidperimeter management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically monitors account settings and dynamically generates perimeters based on detected trigger events. By self-managing the creation, configuration, and maintenance of perimeters based on enterprise account detection, the system enhances security through resource separation while eliminating the complexity of manual perimeter management for users

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system segments resources into distinct perimeters (personal and enterprise) based on account type detection. By automatically creating separate perimeter structures for different resource types and managing their boundaries, the system achieves secure resource separation while the automation of segmentation logic reduces the perceived complexity for end users

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9497220B2Dynamically generating perimeters
Publication Date: 2016.11.15 MALIKIE INNOVATIONS LTD
  • US9497220B2 patent drawing
  • US9497220B2 patent drawing
  • US9497220B2 patent drawing

AI summary

Systems and techniques relating to securely managing electronic resources are described. A described technique includes receiving a request to add to a mobile device an account setting for a server resource account. Detecting a trigger event for a new perimeter based on the account setting. In response to a parameter or a pattern associated with the account setting, retrieving a security policy from a resource server for the server resource account, and generating, by the mobile device, a new perimeter including the server resource account based on the security policy. The new perimeter is configured to prevent transferring data associated with the server resource account being transferred to mobile-device resources external to the new perimeter.