Mobile Device Data Segmentation for Enterprise Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The deployment, management, and configuration of mobile devices in enterprise environments are challenging due to the vast and constantly changing variety of device types, functions, and capabilities, which complicates configuration, provisioning, and troubleshooting.
Innovation Solution
A mobile device management system that includes a device management server hosting a mobile device management application, which selectively logs data from mobile devices, maintains device objects, and uses a control client application to synchronize device states and track data, enabling administrators to manage devices securely and efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices are deployed with extended functionality for enterprise use, then device capabilities and business functionality are improved, but device complexity and management difficulty increase
Solution Approach 1:
The patent segments mobile devices into personal and enterprise portions, allowing independent management of each. The enterprise portion can be configured, provisioned, and secured separately from personal data and applications, reducing overall management complexity while maintaining extended functionality.
Solution Approach 2:
The patent introduces an enterprise management system as an intermediary between the user and the mobile device. This mediator handles configuration, provisioning, and security policies, simplifying management of complex device functionalities through centralized control.
2Productivity
If enterprise applications and data are accessed on mobile devices, then business functionality is improved, but security risks increase
Solution Approach 1:
The patent divides the mobile device into separate personal and enterprise portions with distinct security boundaries. Enterprise applications and data are isolated in the enterprise portion, which can be secured with enterprise policies without affecting personal data, thus enabling business functionality while mitigating security risks.
Solution Approach 2:
The patent implements preliminary security measures by pre-configuring the enterprise portion with security policies, encryption, and access controls before enterprise data is accessed. This preventive approach addresses security risks before they can manifest, allowing secure business functionality.
3Measurement precision
If selective data management is implemented, then data control precision is improved, but system complexity increases
Solution Approach 1:
The patent segments data into personal and enterprise categories stored in separate portions of the mobile device. This segmentation enables precise selective management of enterprise data (logging, erasing, tagging) without affecting personal data, achieving data control precision while managing complexity through clear separation.
Data Source
AI summary
In various embodiments, a method is described that includes registering a mobile device with an enterprise by storing registration data for the mobile device in a device management database; designating one or more group designations for the mobile device; storing the one or more group designations in the device management database; determining one or more policies for the mobile device based at least in part on the one or more group designations; and selectively taking action on selected data from the mobile device in the device management database based on the one or more policies.


