Framework Level Modes for Secure Data Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile device solutions provide limited security and mode separation, as they primarily operate at the application level, failing to effectively isolate data and networking behavior across different modes, leading to vulnerabilities and gaps in data and application separation models.

Innovation Solution

A multiple framework level mode system that introduces deeper operating system-level classification and management of processes, enabling different views of persistent storage, memory, and networking interfaces based on modes, with encryption and dynamic split tunneling to ensure secure data separation and network access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If enterprise grade applications are downloaded and installed on mobile devices, then visual separation between work and personal environments is provided, but data storage and networking behavior remain unaffected creating security vulnerabilities

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity separation
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements a container application that nests multiple virtual device environments within a single mobile device. Each virtual device (work device, personal device, family device) is contained within the container application, creating layered isolation where applications run inside virtual devices which run inside the container. This nested structure enables security policies to be enforced at the virtual device level while maintaining the convenience of a single application deployment.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent segments the mobile device into multiple isolated virtual devices, each with its own operating system instance, file system, and network stack. This segmentation divides the monolithic device into separate functional units that can be independently secured and managed, allowing data storage and networking behavior to be affected by mode switches at the virtual device level.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple operating system instances or virtual machines are used to provide mode separation, then data and application separation is improved, but device complexity increases

Engineering Contradiction:
Improvemode separationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The container application serves multiple functions: it acts as a launcher for virtual devices, a security policy enforcement point, a resource manager, and a user interface for mode switching. By consolidating these functions into a single container application rather than requiring separate management systems for each virtual device, the patent reduces overall system complexity while maintaining strong mode separation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The container application serves as an intermediary layer between the user and multiple virtual device instances. Instead of users directly managing multiple operating systems or virtual machines, the container application mediates access, presenting a simplified interface for switching between work, personal, and family devices while handling the complexity of multiple OS instances in the background.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If enterprise grade applications are used for security, then application-level security features are provided, but gaps in data and application separation models remain

Engineering Contradiction:
Improveapplication securityVSAvoidseparation coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent adds a new dimension to security by implementing isolation at the virtual device level rather than only at the application level. This dimensional shift from application-level security to virtual device-level security creates comprehensive separation that affects all data storage, networking, and system calls, eliminating gaps that exist when only application-level security is used.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9772875B2Multiple framework level modes
Publication Date: 2017.09.26 DELL PROD LP
  • US9772875B2 patent drawing
  • US9772875B2 patent drawing
  • US9772875B2 patent drawing

AI summary

Mechanisms are provided to allow devices to support multiple modes, such as work, personal, and family modes. Conventional mobile solutions provide only for mode distinctions at the application level, e.g. one work application may prevent access to certain data, but a different application may want to allow access to that same data. Existing computer system solutions rely on multiple operating system instances or multiple virtual machines. Framework level modes are provided that do not require different, mutually exclusive, or possibly conflicting applications or platforms. A device and associated applications may have access to different data and capabilities based on a current mode.