Hooking Library for Non-Cooperative OS Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate IT infrastructures face security risks due to unmanaged personal devices accessing corporate resources, leading to data transfer vulnerabilities and compliance issues, as most personal device operating systems lack management capabilities.
Innovation Solution
A method and system for configuring applications in non-cooperative environments by loading a hooking library that monitors and adjusts the behavior of target applications according to predefined policies, including authentication, data encryption, and geographic restrictions, while presenting a custom user interface to enforce compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If employees are permitted to access corporate resources via personal devices, then employee efficiency and productivity are improved, but security risks and data transfer vulnerabilities increase
Solution Approach 1:
The patent introduces an intermediary layer (hooking library) between the personal device operating system and corporate resources. This intermediary monitors and controls API calls, enabling secure access to corporate resources while maintaining the benefits of personal device usage. The hooking library acts as a mediator that enforces IT policies without requiring modifications to the underlying non-cooperative OS.
2Adaptability or versatility
If personal devices are used to access corporate IT infrastructure, then access flexibility is improved, but compliance with laws and regulations becomes more difficult
Solution Approach 1:
The system implements continuous feedback mechanisms by monitoring API calls in real-time and enforcing compliance policies dynamically. The hooking library observes application behavior and adjusts access control decisions based on policy violations, ensuring ongoing compliance with regulations such as HIPAA and Sarbanes-Oxley while maintaining flexible access to corporate resources.
3Ease of operation
If personal device operating systems are used without management capabilities, then ease of operation is improved, but ability to enforce IT policies deteriorates
Solution Approach 1:
The patent embeds a management layer (hooking library) within the existing personal device operating system without requiring OS modifications. The hooking library nests itself into the application execution environment, capturing and controlling API calls while leaving the underlying non-cooperative OS intact. This nested approach enables policy enforcement while preserving the ease of operation of personal devices.
Data Source
AI summary
The present invention extends to methods, systems, and computer program products for configuring applications and policies in non-cooperative environments. Embodiments of the invention provide the ability to configure non-cooperative applications and operating systems to comply with a policy. For example, applications and operating systems at a user's (e.g., an information worker's) personal device (e.g., smartphone) can be appropriately configured to provide more secure access to a corporate IT infrastructure. An IT worker can programmatically repackage an application to comply with a policy, deploy it to a user's personal device, and adjust the application's behavior during execution to comply with the policy. Adjusted behavior can include injecting custom user interfaces into an application to support various scenarios. Injecting a custom user interface can be facilitated by tracking visual context for an application across one or more displays and switching between the application's visual context and the custom user interface.


