Mobile Device Application Control via Network Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices with VoIP capabilities pose security risks for enterprises due to peer-to-peer protocols like Skype, which can bypass corporate firewalls and IT security measures, and there is a need to control application usage based on network connections to ensure security and compliance.

Innovation Solution

A method and system that utilize network identifiers to correlate with stored application limitations, allowing only approved applications to run on mobile devices when connected to specific networks, such as corporate WiFi, thereby restricting usage to approved applications during work hours or within the corporate network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If peer-to-peer applications like Skype are allowed on mobile devices, then low-cost telephony service is achieved, but corporate security measures are bypassed

Engineering Contradiction:
Improvetelephony service cost reductionVSAvoidcorporate security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically adjusts application permissions based on network context. When the device connects to a corporate network, peer-to-peer applications are restricted or blocked. When connected to personal networks, the same applications are allowed. This dynamic policy adjustment resolves the contradiction by making security measures adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different security policies are applied to different network environments. The system identifies the current network context (corporate vs. personal) and applies appropriate application restrictions locally to that context. This allows low-cost telephony on personal networks while maintaining security on corporate networks.

Inventive Principle:
Principle #3Local quality

2Reliability

If handheld devices are restricted to business purposes only, then corporate security is maintained, but employee fringe benefit is reduced

Engineering Contradiction:
Improvecorporate securityVSAvoidemployee device usage flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system transitions from static restriction (business purposes only) to dynamic permissioning based on network context. Employees gain flexibility to use personal applications during non-work hours or on personal networks, while security is automatically enforced when connecting to corporate networks. This resolves the contradiction by making restrictions context-dependent rather than absolute.

Inventive Principle:
Principle #15Dynamics

3Reliability

If application usage is controlled based on network connection, then security compliance is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidapplication control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device automatically performs network identification and policy enforcement without requiring manual user configuration. The system self-determines the current network context and automatically applies the appropriate security policy, reducing the perceived complexity for users while maintaining robust security compliance.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2082519B1A method and apparatus to control the use of applications on handheld devices based on network service
Publication Date: 2018.02.21 BLACKBERRY LTD
  • EP2082519B1 patent drawingFigure 1
  • EP2082519B1 patent drawingFigure 2
  • EP2082519B1 patent drawingFigure 3

AI summary

A method and apparatus to control the use of applications on handheld device is based on network service, the method comprising the steps of: receiving a network identifier; correlating the network identifier with application and/or feature limitations stored on the mobile device; and limiting application usage based on the results of such correlating step.