Mobile Application Mode Segmentation for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a system to manage mobile devices that can securely access enterprise resources while also allowing personal use, ensuring secure communication and storage of business information, especially as employees use the same devices for both personal and professional tasks.

Innovation Solution

A method and system that employs a device manager to monitor and manage mobile devices by detecting the presence of applications capable of operating in multiple modes, based on user credentials, location, and other contextual factors, to provide secure access to enterprise resources while allowing personal use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If an application is allowed to execute in multiple operation modes on a mobile device, then the versatility and ease of operation are improved, but the security control and reliability deteriorate due to difficulty in managing different data types

Engineering Contradiction:
Improveapplication operation modesVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the application's operation modes into distinct managed and unmanaged modes, with separate data containers for managed and unmanaged data. This segmentation allows the application to operate in multiple modes while maintaining security boundaries, as the device manager can enforce security policies on the managed mode and data without compromising the unmanaged mode.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If business information is stored on a mobile device for remote access, then the ease of operation and productivity are improved, but the security risks and loss of information increase

Engineering Contradiction:
Improveremote access to enterprise resourcesVSAvoidsecurity of business data
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system performs preliminary action by establishing security policies and obtaining device manager approval before the application accesses managed data. The device manager pre-configures security settings, data access rules, and authentication mechanisms, ensuring that business information is protected from the moment it is accessed on the mobile device, rather than reacting to security threats afterward.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security mechanisms are enforced on a mobile device, then the reliability and protection of business data are improved, but the ease of operation and device versatility worsen due to restricted access

Engineering Contradiction:
Improvesecurity mechanismsVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies local quality by enforcing security policies and restrictions only on the managed mode and managed data, while leaving the unmanaged mode and unmanaged data accessible without restrictions. This allows users to access business information securely when needed, while maintaining full versatility and ease of operation for personal applications and data, thus resolving the contradiction between security enforcement and device accessibility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3541104A1Data management for an application with multiple operation modes
Publication Date: 2019.09.18 CITRIX SYSTEMS INC
  • EP3541104A1 patent drawingFigure 1
  • EP3541104A1 patent drawingFigure 2
  • EP3541104A1 patent drawingFigure 3

AI summary

A method and system for managing an application with multiple modes are described. A device manager that manages a mobile device may monitor the mobile device. The device manager may detect that a first type of application that runs in a managed mode (or in multiple managed modes) and an unmanaged mode is installed on the mobile device. When the application is executed on the device, the application executes in accordance with the selected application mode, e.g., based on location, user, role, industry presence, or other predefined context.