Mobile Device Traffic Splicer for BYOD Security and Metering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a BYOD environment, managing and securing personal devices used for work purposes becomes complex due to shared usage among family members and multiple companies, making it difficult to separate enterprise and personal app content, and accurately reimbursing data usage across multiple enterprises.

Innovation Solution

A mobile traffic splicer system that routes device traffic through a secure node to split and route traffic based on policies, using a cloud MDM proxy to manage participation by multiple MDM servers, meter traffic usage, and provide security features like audit logging and API-level filtering, allowing enterprises to connect securely and reimburse employees for enterprise data usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a device is managed by a company in a BYOD environment, then security and control of enterprise content are improved, but employee control and privacy are reduced

Engineering Contradiction:
ImprovesecurityVSAvoidemployee control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the device into personal and enterprise portions, allowing separate management and control. The enterprise can secure and manage only the enterprise content and applications, while the employee retains full control over personal content, resolving the contradiction between security and employee control through spatial and functional separation of device domains.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If an employee's device is shared with family members and multiple companies, then device utility and versatility are improved, but management complexity increases

Engineering Contradiction:
Improvedevice sharingVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces clear segmentation between personal and enterprise device portions, establishing distinct management boundaries. This allows the device to be shared among family members and multiple companies without complexity, as each entity manages only its designated segment with defined policies, eliminating the need for complex coordination across overlapping management domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs an enterprise portion that acts as an intermediary layer between the device and multiple companies. This intermediary manages enterprise content and policies centrally, allowing the device to serve multiple companies and family members simultaneously while the intermediary handles the complexity of coordinating between different management requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If device level VPN and proxy are used to secure traffic, then security and audit capabilities are improved, but device usability and performance are reduced

Engineering Contradiction:
ImprovesecurityVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments network traffic into enterprise and personal portions, applying security measures only to enterprise traffic. The enterprise portion enforces VPN and proxy protocols selectively for enterprise applications and content, while personal traffic flows without these overheads, maintaining security for enterprise data while preserving overall device usability and performance.

Inventive Principle:
Principle #1Segmentation

4Reliability

If multiple enterprises require access to device traffic, then enterprise security requirements are met, but accurate traffic attribution and reimbursement become difficult

Engineering Contradiction:
Improvesecurity complianceVSAvoidtraffic attribution
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments device traffic into distinct enterprise portions, with each enterprise's traffic clearly demarcated and attributed. This segmentation enables precise measurement and tracking of data usage per enterprise, allowing accurate reimbursement calculations while maintaining security compliance for each organization's traffic requirements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10595205B2Mobile device traffic splitter
Publication Date: 2020.03.17 IVANTI INC
  • US10595205B2 patent drawing
  • US10595205B2 patent drawing
  • US10595205B2 patent drawing

AI summary

A mobile device traffic splicer is disclosed. In various embodiments, a network communication associated with a destination is received from a mobile device. A stored routing data associated with the mobile device is used to determine, based at least in part on the destination, to redirect the network communication to a proxy associated with the destination. The network communication is sent to the proxy associated with the destination. In various embodiments, one or both of metering network traffic by destination and/or domain and filtering network communications and/or portions thereof based on the destination and/or domain may be performed.