Enterprise App Store Access via Token-Based Gateway
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in securely managing and accessing enterprise applications across various devices, particularly in BYOD environments, where personal and enterprise resources coexist, requiring a solution that balances security and user convenience while allowing remote access to enterprise application stores.
Innovation Solution
A system and method for secure remote access to enterprise application stores using a gateway that provides an access token to an authenticated access manager, enabling mobile devices to access both private enterprise and publicly available application stores, with features like session cookie handling and temporary authorization for secure application delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprises use traditional mobile device management (MDM) approaches to control enterprise resources, then enterprise security and control are improved, but user convenience and flexibility deteriorate
Solution Approach 1:
The patent segments the device into managed (enterprise) and unmanaged (personal) portions, allowing different levels of control and access for different parts of the device. This enables enterprises to secure only the portions needed for business while leaving personal areas untouched, thus maintaining security without sacrificing user convenience.
Solution Approach 2:
The patent introduces an intermediary access manager that acts as a bridge between the application management service and the enterprise application store. This intermediary handles authentication and authorization, enabling secure access without requiring full device management, thus balancing security requirements with user autonomy.
2Adaptability or versatility
If enterprises allow remote access to enterprise resources, then user flexibility and accessibility are improved, but security risks and control challenges worsen
Solution Approach 1:
The patent implements dynamic authorization where access rights are not static but are granted temporarily and specifically for particular actions. The access manager can issue time-limited access tokens and revoke permissions as needed, enabling flexible remote access while maintaining dynamic security control.
Solution Approach 2:
The patent changes the parameters of access control by moving from binary (access/denial) to graded control with multiple authorization levels, time limits, and scope restrictions. This allows enterprises to provide flexible remote access while maintaining security through parameterized control policies.
3Reliability
If enterprises provide full control over mobile devices, then enterprise resource protection is improved, but device compatibility and user autonomy deteriorate
Solution Approach 1:
The patent applies different levels of control and protection to different portions of the device rather than uniform control. Enterprise resources and data receive enhanced protection measures, while personal areas maintain full user control and device compatibility, thus protecting resources without sacrificing versatility.
4Reliability
If enterprises use session cookies for authentication, then secure access control is improved, but compatibility with certain services deteriorates
Solution Approach 1:
The access manager serves as an intermediary that translates between different authentication mechanisms. It can accept session cookies from services that require them while issuing access tokens to services that use token-based authentication, thus maintaining both authentication security and service compatibility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for providing secure remote access to an enterprise application store with enterprise applications for a service running on a mobile device includes receiving an authentication request with user credentials from an access manager on the mobile device. Authentication and a valid session cookie are provided if user credentials are valid. An access token request is received and an access token is provided in response to the token request if the token request includes the valid session cookie. An access request from the service is received and access to the enterprise application store by the service is allowed if the request includes the access token. The service may then download applications or receive applications delivered via the enterprise application store. The application management service can also access a publicly available application store.