Mobile Device Traffic Splicer for BYOD Security and Metering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a BYOD environment, managing and securing personal devices used for work purposes becomes complex due to shared usage among family members and multiple companies, making it difficult to separate enterprise and personal app content, and accurately reimbursing data usage across multiple enterprises.
Innovation Solution
A mobile traffic splicer system that routes device traffic through a secure node to split and route traffic based on policies, using a cloud MDM proxy to manage participation by multiple MDM servers, meter traffic usage, and provide security features like audit logging and API-level filtering, allowing enterprises to connect securely and reimburse employees for enterprise data usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a device is managed by a company in a BYOD environment, then security and control of enterprise content are improved, but employee control and privacy are reduced
Solution Approach 1:
The patent segments the device into personal and enterprise portions, allowing separate management and control. The enterprise can secure and manage only the enterprise content and applications, while the employee retains full control over personal content, resolving the contradiction between security and employee control through spatial and functional separation of device domains.
2Adaptability or versatility
If an employee's device is shared with family members and multiple companies, then device utility and versatility are improved, but management complexity increases
Solution Approach 1:
The patent introduces clear segmentation between personal and enterprise device portions, establishing distinct management boundaries. This allows the device to be shared among family members and multiple companies without complexity, as each entity manages only its designated segment with defined policies, eliminating the need for complex coordination across overlapping management domains.
Solution Approach 2:
The patent employs an enterprise portion that acts as an intermediary layer between the device and multiple companies. This intermediary manages enterprise content and policies centrally, allowing the device to serve multiple companies and family members simultaneously while the intermediary handles the complexity of coordinating between different management requirements.
3Reliability
If device level VPN and proxy are used to secure traffic, then security and audit capabilities are improved, but device usability and performance are reduced
Solution Approach 1:
The patent segments network traffic into enterprise and personal portions, applying security measures only to enterprise traffic. The enterprise portion enforces VPN and proxy protocols selectively for enterprise applications and content, while personal traffic flows without these overheads, maintaining security for enterprise data while preserving overall device usability and performance.
4Reliability
If multiple enterprises require access to device traffic, then enterprise security requirements are met, but accurate traffic attribution and reimbursement become difficult
Solution Approach 1:
The patent segments device traffic into distinct enterprise portions, with each enterprise's traffic clearly demarcated and attributed. This segmentation enables precise measurement and tracking of data usage per enterprise, allowing accurate reimbursement calculations while maintaining security compliance for each organization's traffic requirements.
Data Source
AI summary
A mobile device traffic splicer is disclosed. In various embodiments, a network communication associated with a destination is received from a mobile device. A stored routing data associated with the mobile device is used to determine, based at least in part on the destination, to redirect the network communication to a proxy associated with the destination. The network communication is sent to the proxy associated with the destination. In various embodiments, one or both of metering network traffic by destination and/or domain and filtering network communications and/or portions thereof based on the destination and/or domain may be performed.


