Mobile Device Application Access Control via Segmented Modes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management systems restrict user experience by locking down devices for corporate and personal use, limiting application installation and data access, which can be inflexible and insecure.

Innovation Solution

Implementing dual or plural modes of operation on mobile devices, segregating applications into corporate and personal spaces, with IT policies controlling corporate data access, and using identity and class attributes to manage application access to stores and memory spaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT policies are implemented to limit risk exposure of corporate data on mobile devices, then data security is improved, but user experience deteriorates as the device becomes locked and application installation is restricted

Engineering Contradiction:
Improvedata securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the mobile device into distinct work and personal modes, creating separate operational environments. In work mode, IT policies are enforced for corporate data protection, while in personal mode, users have full access to install and run personal applications. This segmentation resolves the contradiction by providing data security in work mode without restricting personal application usage in personal mode.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If the mobile device is locked to prevent virus spread, then security against malware is improved, but the range of installable applications is significantly limited

Engineering Contradiction:
Improvevirus protectionVSAvoidapplication installation range
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic switching between work and personal modes. When in personal mode, the device allows installation of applications from any source including unapproved locations, providing full adaptability. When switching to work mode, IT policies are enforced to prevent malware spread. This dynamic approach resolves the contradiction by adjusting security restrictions based on the operational context rather than maintaining constant limitations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2829998B1Managing application access to certificates and keys
Publication Date: 2017.04.12 BLACKBERRY LTD
  • EP2829998B1 patent drawing
  • EP2829998B1 patent drawing
  • EP2829998B1 patent drawing

AI summary

Plural modes of operation, each associated with a class attribute, may be established on a mobile device. The present application discloses a method of handling an application launch request, a computing device for carrying out the method and a computer readable medium for adapting a processor to carry out the method. The method includes receiving a launch request identifying an application that is to be launched, acquiring an identity for the application, acquiring a class for the application, labeling the application with the identity and the class and launching the application. The application's identity and class may then be taken into consideration when processing a request to access a store or create a new store. Notably, an application may request access to a store managed by a certificate manager, rather than accessing the store directly. Conveniently, a resource manager may handle parsing of a file path to the store.