Hooking Library for Non-Cooperative OS Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate IT infrastructures face security risks due to unmanaged personal devices accessing corporate resources, leading to data transfer vulnerabilities and compliance issues, as most personal device operating systems lack management capabilities.

Innovation Solution

A method and system for configuring applications in non-cooperative environments by loading a hooking library that monitors and adjusts the behavior of target applications according to predefined policies, including authentication, data encryption, and geographic restrictions, while presenting a custom user interface to enforce compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees are permitted to access corporate resources via personal devices, then employee efficiency and productivity are improved, but security risks and data transfer vulnerabilities increase

Engineering Contradiction:
Improveemployee efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary layer (hooking library) between the personal device operating system and corporate resources. This intermediary monitors and controls API calls, enabling secure access to corporate resources while maintaining the benefits of personal device usage. The hooking library acts as a mediator that enforces IT policies without requiring modifications to the underlying non-cooperative OS.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If personal devices are used to access corporate IT infrastructure, then access flexibility is improved, but compliance with laws and regulations becomes more difficult

Engineering Contradiction:
Improveaccess flexibilityVSAvoidcompliance reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements continuous feedback mechanisms by monitoring API calls in real-time and enforcing compliance policies dynamically. The hooking library observes application behavior and adjusts access control decisions based on policy violations, ensuring ongoing compliance with regulations such as HIPAA and Sarbanes-Oxley while maintaining flexible access to corporate resources.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If personal device operating systems are used without management capabilities, then ease of operation is improved, but ability to enforce IT policies deteriorates

Engineering Contradiction:
Improvedevice usabilityVSAvoidpolicy enforcement capability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent embeds a management layer (hooking library) within the existing personal device operating system without requiring OS modifications. The hooking library nests itself into the application execution environment, capturing and controlling API calls while leaving the underlying non-cooperative OS intact. This nested approach enables policy enforcement while preserving the ease of operation of personal devices.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS9661024B2Configuring applications and policies in non-cooperative environments
Publication Date: 2017.05.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9661024B2 patent drawing
  • US9661024B2 patent drawing
  • US9661024B2 patent drawing

AI summary

The present invention extends to methods, systems, and computer program products for configuring applications and policies in non-cooperative environments. Embodiments of the invention provide the ability to configure non-cooperative applications and operating systems to comply with a policy. For example, applications and operating systems at a user's (e.g., an information worker's) personal device (e.g., smartphone) can be appropriately configured to provide more secure access to a corporate IT infrastructure. An IT worker can programmatically repackage an application to comply with a policy, deploy it to a user's personal device, and adjust the application's behavior during execution to comply with the policy. Adjusted behavior can include injecting custom user interfaces into an application to support various scenarios. Injecting a custom user interface can be facilitated by tracking visual context for an application across one or more displays and switching between the application's visual context and the custom user interface.