Mobile Device Domain Container Trust Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device management systems face challenges in securely creating and managing multiple domains on a device, particularly in ensuring that a new domain authority is trusted by both the existing domain and the management authority, while maintaining data integrity and isolating corporate and personal resources.

Innovation Solution

A method for creating a managed domain on a mobile device involves initializing a container, retrieving and running a management agent, establishing policies, and configuring the domain based on these policies, with mechanisms to ensure trust and secure data isolation between domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a new domain authority is enrolled on a mobile device, then the device can be managed by additional authorities for enterprise use, but the trust relationship between existing domains and new authorities becomes complex and difficult to establish

Engineering Contradiction:
Improvemulti-domain management capabilityVSAvoidtrust relationship management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a container as an intermediary layer between domain authorities and the mobile device. The container manages trust relationships centrally, allowing multiple domain authorities to be enrolled without creating complex direct trust relationships between each authority and every existing domain. The container acts as a mediator that handles authentication and trust verification for all domain operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the device into isolated domain containers, each managed by its own authority. This segmentation allows independent trust management for each domain while maintaining overall system coherence through the container framework. Each domain's trust relationships are encapsulated within its container, preventing trust complexity from propagating across the entire device.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple domains are created on a mobile device, then corporate and personal resources can be isolated for security, but the process of creating and managing each domain becomes increasingly complex

Engineering Contradiction:
Improvedata isolation and securityVSAvoiddomain creation and management process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements segmentation by creating isolated container environments for each domain. Each container is a self-contained unit with its own virtualized operating system and resource namespace, ensuring that corporate and personal resources are physically isolated at the system level. This segmentation approach maintains security while simplifying management compared to traditional multi-domain implementations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The container framework provides universal functionality for domain creation, management, and isolation. A single container infrastructure supports multiple domains with different security requirements, policies, and authorities. This multi-functional approach eliminates the need for separate management mechanisms for each domain, reducing overall system complexity while maintaining robust security isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a container is initialized to house a managed domain, then secure isolation is achieved, but the device requires additional resources for container initialization and management

Engineering Contradiction:
Improvedomain isolation securityVSAvoiddevice resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent uses virtualization to create virtual copies of operating system environments within containers. Instead of requiring separate physical hardware for each domain, the system creates virtualized copies of the OS that share the underlying physical resources. This copying approach provides strong isolation security while efficiently utilizing device resources through virtualization overhead rather than physical duplication.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2950561B1Method and system for domain creation and bootstrapping
Publication Date: 2018.07.11 BLACKBERRY LTD
  • EP2950561B1 patent drawingFigure 1
  • EP2950561B1 patent drawingFigure 2
  • EP2950561B1 patent drawingFigure 3

AI summary

A method at a mobile device for creating a managed domain on the mobile device, the method initializing a container on the mobile device to house the managed domain; retrieving, from the mobile device, a management agent for the management domain; establishing policies to govern the creation of the managed domain; and configuring the container for the domain based on the established policies.