Dynamic Policy Enforcement for Private Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In enterprise environments, devices used for both personal and professional purposes often face challenges in accessing enterprise resources securely when outside the trusted network, particularly when they are not fully configured with enterprise policies, leading to inefficiencies and security risks due to the need for comprehensive policy implementation.
Innovation Solution
A system that temporarily applies the minimum necessary enterprise policies required for a specific action on a private device, using a virtual machine to implement policies and allowing the action while removing them post-completion, thereby enhancing flexibility and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive enterprise policies are implemented on private devices to ensure security, then security protection is improved, but device complexity and computational resource requirements increase
Solution Approach 1:
The patent segments enterprise policies into two categories: comprehensive policies for enterprise-managed devices and minimal policies for private devices. Only the essential policies required for secure resource access are applied to private devices, reducing complexity while maintaining security. This is achieved through the policy determination component that identifies and applies only necessary policies based on the action context.
Solution Approach 2:
The patent applies different policy sets to different device types locally. Enterprise-managed devices receive full policy enforcement, while private devices receive tailored minimal policies. The system customizes policy application based on device ownership and context, ensuring each device type receives appropriate security measures without unnecessary complexity.
2Reliability
If all enterprise policies are applied to private devices, then security is improved, but computational resources and processing time increase
Solution Approach 1:
The patent applies partial action by implementing only the minimum necessary policies on private devices rather than all enterprise policies. The policy determination component analyzes the requested action and applies only the essential policies needed for secure execution, reducing computational overhead while maintaining adequate security protection.
3Reliability
If comprehensive policy validation is performed before allowing actions, then security is improved, but access speed and user convenience deteriorate
Solution Approach 1:
The system performs preliminary action by pre-determining and caching the minimal policy set required for common actions on private devices. When a user requests an action, the system quickly checks against the pre-determined policy requirements rather than performing comprehensive validation, significantly improving access speed while maintaining security through the policy enforcement component.
4Ease of operation
If minimal policies are applied to private devices, then ease of operation is improved, but security protection worsens
Solution Approach 1:
The patent implements dynamic policy adjustment where the policy set applied to a private device changes based on the specific action being performed. The policy determination component dynamically selects and applies only the policies relevant to the current action context, providing ease of operation for routine tasks while maintaining strong security protection when needed. This dynamic approach allows the system to adapt security measures to actual risk levels.
Data Source
AI summary
Access is temporarily allowed to selected enterprise resources. A request to carry out an action is received from a private device. The private device is associated with an enterprise device, which has one or more enterprise policies in place. One or more steps for carrying out the requested action are defined, and it is determined that at least one policy from the enterprise policies is required for at least one of the steps. It is also determined that the at least one policy is in place on the private device. The private device is then allowed to carry out the requested action according to the at least one policy.


