Enterprise Workspace Segregation on BYOD Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies face increased security risks when employees' personal devices are compromised, allowing malicious access to corporate resources due to outdated security patches and lack of segregation between personal and enterprise data on BYOD policies.
Innovation Solution
The system configures separate personal and enterprise workspaces on devices, using an operating system to segregate components and data, with a management service that monitors and controls enterprise workspace activity without affecting personal workspace restrictions, and requires user account association for enterprise workspace access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If employees use personal devices for work purposes under BYOD policies, then device flexibility and employee convenience are improved, but security risks increase due to compromised devices and lack of data segregation
Solution Approach 1:
The patent implements separate personal and enterprise workspaces on the same device, with distinct security policies, data storage areas, and access controls. This segmentation allows the device to serve both personal and professional purposes while isolating enterprise data from potential security threats in the personal workspace.
Solution Approach 2:
The patent introduces a workspace management service as an intermediary that mediates between the personal and enterprise workspaces. This service enforces security policies, manages data protection, and controls access to enterprise resources, thereby reducing security risks while maintaining device flexibility.
2Object-affected harmful factors
If separate personal and enterprise workspaces are configured on the same device, then security is improved through data isolation, but device complexity increases
Solution Approach 1:
The patent creates a unified device that hosts multiple workspaces (personal and enterprise) with different security requirements. The device operates as a multi-functional system where a single hardware platform supports both personal use and enterprise resource access, managing complexity through software-based workspace abstraction.
Solution Approach 2:
The workspace management service automatically handles security policy enforcement, data protection, and access control without requiring manual user intervention for each security decision. This self-service approach reduces the perceived complexity for users while maintaining robust security measures.
3Object-affected harmful factors
If enterprise data is isolated in separate workspaces, then unauthorized access is prevented, but user convenience deteriorates due to restricted access
Solution Approach 1:
The workspace management service provides feedback mechanisms that inform users about security policy requirements and access permissions. This feedback loop helps users understand why certain restrictions exist and what actions are permitted, maintaining convenience while preventing unauthorized access to enterprise data.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Various examples relate to the configuration of enterprise workspaces that can be provided in computing devices. In some examples, a computing device is enrolled with a management service that controls operation of at least a portion of the computing device. A management component creates a user account with a distributor of the operating system based on an email address. The management component requests an authentication service to authenticate a user. The user account is associated with an enterprise workspace of the computing device.