Mobile Device Communication Domain Security Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The availability of multiple communication domains on a mobile device poses security challenges, as enterprise domains are generally more secure than non-enterprise domains, and administrators need to restrict certain call features to maintain control over the use of these domains.

Innovation Solution

A mobile device with a processor and memory that includes communication restriction modules to determine and apply restrictions based on the communication domain, ensuring that communication service requests adhere to predefined security protocols, thereby managing and controlling communications across different domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple communication domains are made available on a mobile device, then communication versatility is improved, but security control deteriorates

Engineering Contradiction:
Improvecommunication versatilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the communication system into multiple domains (enterprise domain and non-enterprise domain) with distinct security policies. Each domain is treated as a separate entity with its own access control rules, allowing the system to maintain security boundaries while supporting multiple communication channels. The domain identifier associated with each communication service request enables targeted application of security restrictions to specific domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the domain module and communication restriction module) that sits between the communication requests and the actual communication services. This intermediary evaluates each service request against domain-specific restrictions and enforces security policies before allowing communication, thus maintaining security control while permitting versatile multi-domain communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators restrict certain call features on enterprise domain, then security control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically evaluating communication service requests against stored communication restrictions without requiring manual administrator intervention for each request. The domain module and communication restriction module work autonomously to enforce security policies, reducing the operational burden on administrators while maintaining strict security control over enterprise domain communications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-configuring communication restrictions in the enterprise domain before communication occurs. Security policies are established in advance and automatically applied to relevant service requests, eliminating the need for real-time security decisions and simplifying administrator operations while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If conference call bridging between enterprise and non-enterprise domains is allowed, then communication versatility is improved, but security risk increases

Engineering Contradiction:
Improvecommunication versatilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preemptively blocking potentially harmful conference call bridging operations between enterprise and non-enterprise domains. The communication restriction module identifies and prevents service requests that would allow unauthorized bridging of conference calls across domain boundaries, countering security risks before they can materialize while still permitting legitimate multi-domain communications.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2224781B1System and method for security on a mobile device using multiple communication domains
Publication Date: 2017.09.20 BLACKBERRY LTD
  • EP2224781B1 patent drawingFigure 1
  • EP2224781B1 patent drawingFigure 2
  • EP2224781B1 patent drawingFigure 3

AI summary

A mobile device and a method for providing security to a mobile device having two or more communication domains is provided. The mobile device receives a communication service request. The communication domain of the communication service request is determined, the request domain being one of the two or more communication domains of the mobile device. A set of applicable restrictions is then determined from a list of communication restrictions comprising restrictions on use of services of the mobile device for each of the two or more communications domains. These applicable restrictions are then applied to the communication service request by the mobile device.