Location-Based Security Policy Enforcement for BYOD Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the Bring Your Own Device (BYOD) trend and consumerization of information technology increase, enterprise administrators face challenges in ensuring compliance with security policies, particularly in managing access to sensitive resources based on the physical location of devices, which existing systems struggle to address effectively.

Innovation Solution

An integrated security system that employs a policy server, mobile device with a policy agent, and wireless non-contact storage elements like RFID tags to enforce location-based policies by communicating device location and user identity, allowing or restricting access to resources based on predefined premises-specific policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees are allowed to use personally owned devices to access enterprise networks and resources, then productivity and employee satisfaction improve, but security compliance and policy enforcement become increasingly difficult to maintain

Engineering Contradiction:
Improveemployee productivityVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by implementing location-specific security policies that adapt access controls based on the physical location of the device. Different security requirements are applied to different locations (e.g., restricted areas vs. open areas), allowing productive BYOD usage in safe zones while maintaining security compliance in sensitive zones through automated policy enforcement.

Inventive Principle:
Principle #3Local quality

2Reliability

If traditional security management approaches are used to control access to sensitive resources, then security compliance is maintained, but flexibility in allowing BYOD usage and employee autonomy are reduced

Engineering Contradiction:
Improvesecurity complianceVSAvoidBYOD usage flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on real-time location data from RFID tags and mobile devices. Instead of static access controls, the system dynamically enables or disables applications and resources based on the device's current location, providing flexibility for BYOD usage while maintaining security compliance through automated policy application.

Inventive Principle:
Principle #15Dynamics

3Reliability

If manual monitoring and control of device locations is implemented, then security policy enforcement is achieved, but system complexity and administrative burden increase

Engineering Contradiction:
Improvepolicy enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs self-service mechanisms where mobile devices automatically communicate their location via RFID tags to the security system, and policies are automatically applied without manual intervention. The system monitors and enforces security policies autonomously based on location data, eliminating the need for complex manual monitoring and reducing administrative burden while maintaining reliable policy enforcement.

Inventive Principle:
Principle #25Self-service

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables seamless enforcement of location-dependent security policies, enhancing compliance by accurately determining device presence within specific areas and applying relevant access controls, thereby improving the security and management of BYOD devices.

Implementation Method 1

location information provided by RFID tag

Methodology Applied
Scientific EffectRadio frequency identification (RFID): Electromagnetic Induction

Data Source

PatentEP2909776B1Premises aware security
Publication Date: 2019.12.04 MCAFEE LLC
  • EP2909776B1 patent drawingFigure 1~4
  • EP2909776B1 patent drawingFigure 2
  • EP2909776B1 patent drawingFigure 3

AI summary

Premise-based policies can be applied in the management of mobile devices and other computing devices within a system. A computing device is detected using close proximity wireless communication and location information is sent to the computing device using close proximity wireless communication. Policies applied to the computing device can be based at least in part on the location information.