Enterprise Workspace Segregation on BYOD Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face increased security risks when employees' personal devices are compromised, allowing malicious access to corporate resources due to outdated security patches and lack of segregation between personal and enterprise data on BYOD policies.

Innovation Solution

The system configures separate personal and enterprise workspaces on devices, using an operating system to segregate components and data, with a management service that monitors and controls enterprise workspace activity without affecting personal workspace restrictions, and requires user account association for enterprise workspace access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If employees use personal devices for work purposes under BYOD policies, then device flexibility and employee convenience are improved, but security risks increase due to compromised devices and lack of data segregation

Engineering Contradiction:
Improvedevice flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements separate personal and enterprise workspaces on the same device, with distinct security policies, data storage areas, and access controls. This segmentation allows the device to serve both personal and professional purposes while isolating enterprise data from potential security threats in the personal workspace.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a workspace management service as an intermediary that mediates between the personal and enterprise workspaces. This service enforces security policies, manages data protection, and controls access to enterprise resources, thereby reducing security risks while maintaining device flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If separate personal and enterprise workspaces are configured on the same device, then security is improved through data isolation, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent creates a unified device that hosts multiple workspaces (personal and enterprise) with different security requirements. The device operates as a multi-functional system where a single hardware platform supports both personal use and enterprise resource access, managing complexity through software-based workspace abstraction.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The workspace management service automatically handles security policy enforcement, data protection, and access control without requiring manual user intervention for each security decision. This self-service approach reduces the perceived complexity for users while maintaining robust security measures.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If enterprise data is isolated in separate workspaces, then unauthorized access is prevented, but user convenience deteriorates due to restricted access

Engineering Contradiction:
Improveunauthorized accessVSAvoiduser convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The workspace management service provides feedback mechanisms that inform users about security policy requirements and access permissions. This feedback loop helps users understand why certain restrictions exist and what actions are permitted, maintaining convenience while preventing unauthorized access to enterprise data.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3930289B1Associating user accounts with enterprise workspaces
Publication Date: 2023.09.06 AIRWATCH LLC
  • EP3930289B1 patent drawingFigure 1
  • EP3930289B1 patent drawingFigure 2A
  • EP3930289B1 patent drawingFigure 2B

AI summary

Various examples relate to the configuration of enterprise workspaces that can be provided in computing devices. In some examples, a computing device is enrolled with a management service that controls operation of at least a portion of the computing device. A management component creates a user account with a distributor of the operating system based on an email address. The management component requests an authentication service to authenticate a user. The user account is associated with an enterprise workspace of the computing device.