Mobile Device Application Control via Network Context
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices with VoIP capabilities pose security risks for enterprises due to peer-to-peer protocols like Skype, which can bypass corporate firewalls and IT security measures, and there is a need to control application usage based on network connections to ensure security and compliance.
Innovation Solution
A method and system that utilize network identifiers to correlate with stored application limitations, allowing only approved applications to run on mobile devices when connected to specific networks, such as corporate WiFi, thereby restricting usage to approved applications during work hours or within the corporate network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If peer-to-peer applications like Skype are allowed on mobile devices, then low-cost telephony service is achieved, but corporate security measures are bypassed
Solution Approach 1:
The system dynamically adjusts application permissions based on network context. When the device connects to a corporate network, peer-to-peer applications are restricted or blocked. When connected to personal networks, the same applications are allowed. This dynamic policy adjustment resolves the contradiction by making security measures adaptive rather than static.
Solution Approach 2:
Different security policies are applied to different network environments. The system identifies the current network context (corporate vs. personal) and applies appropriate application restrictions locally to that context. This allows low-cost telephony on personal networks while maintaining security on corporate networks.
2Reliability
If handheld devices are restricted to business purposes only, then corporate security is maintained, but employee fringe benefit is reduced
Solution Approach 1:
The system transitions from static restriction (business purposes only) to dynamic permissioning based on network context. Employees gain flexibility to use personal applications during non-work hours or on personal networks, while security is automatically enforced when connecting to corporate networks. This resolves the contradiction by making restrictions context-dependent rather than absolute.
3Reliability
If application usage is controlled based on network connection, then security compliance is enhanced, but device complexity increases
Solution Approach 1:
The device automatically performs network identification and policy enforcement without requiring manual user configuration. The system self-determines the current network context and automatically applies the appropriate security policy, reducing the perceived complexity for users while maintaining robust security compliance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and apparatus to control the use of applications on handheld device is based on network service, the method comprising the steps of: receiving a network identifier; correlating the network identifier with application and/or feature limitations stored on the mobile device; and limiting application usage based on the results of such correlating step.