Mobile Device Security Policy Enforcement via Hard-Coded Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively separate personal and corporate data on mobile devices, leading to security concerns for corporations while infringing on user privacy, as existing solutions are often unsatisfactory in maintaining a clear boundary between personal and corporate data.

Innovation Solution

A wireless device with a non-volatile memory that hard-codes a security type, determining whether to apply security policies to personal or corporate resources, allowing for different security types such as personal-liable, corporate-liable, and regulated, ensuring appropriate security measures without compromising user privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are applied to all data on mobile devices, then corporate security is improved, but user privacy and freedom are worsened

Engineering Contradiction:
Improvecorporate securityVSAvoiduser privacy and freedom
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments mobile devices into distinct operational modes (personal mode and corporate mode) with separate security policy applications. The system divides data and resources into personal and corporate categories, allowing different security rules to apply to each segment. This enables corporate security policies to protect corporate data while leaving personal data unaffected, thus maintaining user privacy while improving corporate security.

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If software applications are used to separate personal and corporate data, then data separation is improved, but the boundary between personal and corporate data is worsened (becomes permeable and changeable)

Engineering Contradiction:
Improvedata separation boundaryVSAvoidboundary stability
Core Design Contradiction:
Manufacturing precisionVSStability of the object's composition

Solution Approach 1:

The patent establishes security mode boundaries and data classification rules in advance through pre-configured security policies. The system pre-defines which data belongs to personal or corporate categories and sets up enforcement mechanisms before data mixing can occur. This preliminary structuring ensures that the boundary between personal and corporate data remains stable and resistant to software-based tampering.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If corporations impose security policies on personal devices, then corporate security control is improved, but user autonomy is worsened

Engineering Contradiction:
Improvecorporate security controlVSAvoiduser autonomy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security mode switching that adapts to the user's needs and context. Users can switch between personal mode and corporate mode based on what they are doing, allowing the system to provide corporate security control when needed while maintaining user autonomy when personal use is required. This dynamic approach balances corporate security requirements with user freedom to use the device for personal purposes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2722786B1Methods and systems for implementing security policies on a mobile device
Publication Date: 2020.03.04 BLACKBERRY LTD
  • EP2722786B1 patent drawingFigure 1A
  • EP2722786B1 patent drawingFigure 1B~1C
  • EP2722786B1 patent drawingFigure 2

AI summary

Methods and devices for implementing security policies on a wireless device. The wireless device may include a non-volatile memory comprising a security type hard-coded in the non-volatile memory. Based on the security type, it may be determined whether a received security policy governing behavior of one or more resources designated as personal is applicable to the one or more resources designated as personal. If the security type is determined to indicate that the received security policy is not applicable to the one or more resources designated as personal, the security policy may not be applied to the one or more resources designated as personal.