Dynamic Policy Enforcement for Private Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise environments, devices used for both personal and professional purposes often face challenges in accessing enterprise resources securely when outside the trusted network, particularly when they are not fully configured with enterprise policies, leading to inefficiencies and security risks due to the need for comprehensive policy implementation.

Innovation Solution

A system that temporarily applies the minimum necessary enterprise policies required for a specific action on a private device, using a virtual machine to implement policies and allowing the action while removing them post-completion, thereby enhancing flexibility and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive enterprise policies are implemented on private devices to ensure security, then security protection is improved, but device complexity and computational resource requirements increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidpolicy configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments enterprise policies into two categories: comprehensive policies for enterprise-managed devices and minimal policies for private devices. Only the essential policies required for secure resource access are applied to private devices, reducing complexity while maintaining security. This is achieved through the policy determination component that identifies and applies only necessary policies based on the action context.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different policy sets to different device types locally. Enterprise-managed devices receive full policy enforcement, while private devices receive tailored minimal policies. The system customizes policy application based on device ownership and context, ensuring each device type receives appropriate security measures without unnecessary complexity.

Inventive Principle:
Principle #3Local quality

2Reliability

If all enterprise policies are applied to private devices, then security is improved, but computational resources and processing time increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing only the minimum necessary policies on private devices rather than all enterprise policies. The policy determination component analyzes the requested action and applies only the essential policies needed for secure execution, reducing computational overhead while maintaining adequate security protection.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If comprehensive policy validation is performed before allowing actions, then security is improved, but access speed and user convenience deteriorate

Engineering Contradiction:
Improvesecurity validationVSAvoidaction execution speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system performs preliminary action by pre-determining and caching the minimal policy set required for common actions on private devices. When a user requests an action, the system quickly checks against the pre-determined policy requirements rather than performing comprehensive validation, significantly improving access speed while maintaining security through the policy enforcement component.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If minimal policies are applied to private devices, then ease of operation is improved, but security protection worsens

Engineering Contradiction:
Improvedevice accessibilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic policy adjustment where the policy set applied to a private device changes based on the specific action being performed. The policy determination component dynamically selects and applies only the policies relevant to the current action context, providing ease of operation for routine tasks while maintaining strong security protection when needed. This dynamic approach allows the system to adapt security measures to actual risk levels.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11310280B2Implementation of selected enterprise policies
Publication Date: 2022.04.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11310280B2 patent drawing
  • US11310280B2 patent drawing
  • US11310280B2 patent drawing

AI summary

Access is temporarily allowed to selected enterprise resources. A request to carry out an action is received from a private device. The private device is associated with an enterprise device, which has one or more enterprise policies in place. One or more steps for carrying out the requested action are defined, and it is determined that at least one policy from the enterprise policies is required for at least one of the steps. It is also determined that the at least one policy is in place on the private device. The private device is then allowed to carry out the requested action according to the at least one policy.