Managed Container Geofencing for Enterprise Content Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional content control software and services are inadequate in managing and protecting enterprise content downloaded to user devices, especially when these devices are lost, stolen, or moved outside authorized geographical locations.
Innovation Solution
A system and method that utilize an application gateway server computer to manage content through a managed container on user devices, which enforces geofencing by denying or restricting access to content based on the device's geographical location, ensuring enterprise content is protected and controlled.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional content control software is used to control content delivered over the Internet, then access to certain websites can be blocked, but control over enterprise content downloaded to user devices is lost
Solution Approach 1:
The patent implements a managed container that acts as a nested virtualized environment within the user device. This container encapsulates enterprise content and enforcement agents, allowing control software to operate independently within the device's operating system. The nested structure enables content control to extend to downloaded applications and data without requiring control of the entire device, thus resolving the contradiction between control effectiveness and device coverage.
Solution Approach 2:
The managed container serves as an intermediary layer between the enterprise content and the user device environment. It mediates access to controlled content through geofencing rules and enforcement agents, enabling content control to function effectively even on unmanaged devices. This intermediary approach allows the system to maintain control over enterprise content while adapting to various device types and operating systems.
2Productivity
If enterprise content is downloaded to unmanaged devices, then employee productivity is improved, but security control over the content is compromised
Solution Approach 1:
By nesting the managed container within the unmanaged device environment, the system enables employees to access and use enterprise content on their personal devices, thereby improving productivity. Simultaneously, the nested container maintains security boundaries through virtualization and enforcement agents that prevent unauthorized access or modification of controlled content, thus preserving security control despite the device being unmanaged.
Solution Approach 2:
The patent applies local quality by implementing geofencing rules that create location-specific access controls. The managed container enforces different security policies based on the device's geographical location, allowing content access in authorized locations while blocking access in unauthorized areas. This location-aware approach maintains security control while enabling flexible access for productivity purposes.
3Reliability
If content access is restricted based on geographical location, then enterprise content protection is improved, but user flexibility and mobility are reduced
Solution Approach 1:
The geofencing system implements dynamic content protection by continuously monitoring the device's location and automatically adjusting access controls based on current geographical context. Rather than imposing static restrictions, the system dynamically enables or disables content access as the device enters or exits authorized zones. This dynamic approach maintains strong content protection while preserving user flexibility, as employees can access content when traveling to authorized locations without being constrained by permanent access denials.
Data Source
AI summary
A managed container may have a managed cache storing content managed by or through an application gateway server computer. The managed container may receive a request for content from an application running in a secure shell provided by the managed container on a client device. The managed container may determine whether the client device is within a specified geographical location. If not, the managed container may deny or restrict the application access to the requested content. The access denial or restriction may continue until a connection is made to the application gateway server computer or until the client device has returned to within the specified geographical location. If the client device is within the specified geographical location, the managed container may provide or restore access to requested content. Embodiments of the managed container can therefore perform geofencing by disabling or limiting access to content based on predetermined secure/insecure designations.


