Mobile Application Policy Enforcement via XML Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in controlling the usage of mobile devices, accessing resources, and managing the interaction of applications within these devices, as existing solutions lack efficient and effective mechanisms for enforcing security constraints and managing application execution.

Innovation Solution

An enterprise application store is implemented, allowing for the configuration and provision of policies that constrain the execution of mobile applications through a user interface, generating a policy file in XML format, which is downloadable to mobile devices to enforce security settings, including access controls and resource management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices are provided with increasing functions and accessibility, then device capability and user functionality are improved, but security control and resource access management become more difficult

Engineering Contradiction:
Improvedevice capabilityVSAvoidsecurity control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments security control into application-level policies that can be independently configured for each mobile application. Instead of managing security at the device level, the system creates separate policy profiles for each application, allowing granular control over resource access, data usage, and execution constraints. This segmentation reduces overall control complexity by breaking down the management task into manageable, application-specific units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy management system as an intermediary between the mobile device and the resources it accesses. This intermediary layer handles the complexity of security control by mediating between application requests and resource access, enforcing policies without requiring complex device-level security mechanisms. The policy server acts as a mediator that translates high-level security requirements into enforceable constraints.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If policies are configured through user interface and generated as downloadable files, then ease of operation and policy customization are improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvepolicy configuration easeVSAvoidsystem processing complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent uses XML format as a standardized copy representation of policy settings. Instead of requiring complex binary formats or proprietary configurations, the system translates policy settings into a universal XML structure that can be easily parsed and executed. This copying approach simplifies both the configuration interface and the execution mechanism, as XML is a well-established format that balances expressiveness with ease of processing.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the representation parameters of policies from complex structured data to a standardized XML format. This parameter transformation allows the system to maintain flexibility in policy configuration while simplifying the underlying processing requirements. XML's hierarchical structure enables easy parsing and execution without requiring complex data processing logic, effectively managing the trade-off between configuration ease and system complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple policy settings are enforced on mobile applications, then security and resource management control are improved, but application execution efficiency may be reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidapplication execution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by establishing policy constraints before application execution begins. Instead of continuously monitoring and enforcing security policies during runtime, the system pre-configures all necessary constraints, permissions, and resource access rules in the policy file before the application starts. This preliminary setup reduces runtime overhead and improves execution efficiency while maintaining strong security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing the mobile device to automatically download, parse, and enforce policies without requiring continuous intervention from the security management system. The device independently manages policy application and compliance verification, reducing the processing burden on centralized systems and improving overall system efficiency. This self-service approach maintains reliable security control while minimizing system resource consumption.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9654508B2Configuring and providing profiles that manage execution of mobile applications
Publication Date: 2017.05.16 CITRIX SYSTEMS INC
  • US9654508B2 patent drawing
  • US9654508B2 patent drawing
  • US9654508B2 patent drawing

AI summary

Various aspects of the disclosure relate to configuring and providing policies that manage execution of mobile applications. In some embodiments, a user interface may be generated that allows an IT administrator or other operator to set, change and/or add to policy settings. The policy settings can be formatted into a policy file and be made available for download to a mobile device, such as via an application store or to be pushed to the mobile device as part of a data push service. The mobile device, based on the various settings included in the policy file, may perform various actions to enforce the security constraints that are represented by the policy. The various settings that can be included in a policy are numerous and some examples and variations thereof are described in connection with the example embodiments discussed herein.