Mobile Enterprise Server BYOD Memory Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing a Bring-Your-Own-Device (BYOD) policy poses challenges for businesses in accommodating diverse client devices with different hardware, operating systems, and securing employee-owned devices, as existing solutions struggle to manage and secure enterprise applications and data across various platforms.

Innovation Solution

A system comprising a mobile enterprise server that facilitates communication between client devices and application servers, using a client application with a memory protection engine to allocate separate memory locations for enterprise and non-enterprise data, and applying security policies to ensure secure access and data protection across different devices and operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If a BYOD policy is implemented to allow employees to use personal devices for business, then device cost and operating expenses are reduced, but security control and data protection become more difficult

Engineering Contradiction:
Improveoperating expensesVSAvoidsecurity control
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The system segments the personal device into distinct operational environments: a secure corporate environment for enterprise applications and data, and a personal environment for non-enterprise use. This segmentation allows the business to reduce costs by allowing BYOD while maintaining security control through environmental isolation of enterprise resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The mobile enterprise server acts as an intermediary between the enterprise applications and the client device, enforcing security policies and managing access controls. This intermediary layer enables cost-effective BYOD implementation while maintaining reliable security control through centralized policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If existing solutions are used to manage enterprise applications on personal devices, then device compatibility is limited, but security management becomes simpler

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The mobile enterprise server provides universal security management capabilities that work across diverse device types, operating systems, and hardware configurations. This universal approach enables broad device compatibility while keeping security management straightforward through centralized control, rather than requiring device-specific security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The server acts as an intermediary that abstracts away device-specific complexities, providing consistent security management across heterogeneous devices. This allows the system to support multiple device types and operating systems while maintaining simple, unified security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate devices are required for business and personal use, then security control is easier, but device cost and employee convenience worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidemployee convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of requiring physically separate devices, the system segments the single device into distinct secure environments. This allows employees to use one device for both personal and business purposes while maintaining security control through environmental separation, thereby improving convenience without sacrificing security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges the functionality of separate business and personal devices into a single unified device, allowing employees to carry one device rather than two. Security control is maintained through virtualization and environmental segmentation, combining the benefits of device consolidation with the security of separation.

Inventive Principle:
Principle #5Merging (Combining)

4Speed

If enterprise data is stored locally on personal devices, then access speed is improved, but security risk and data protection difficulty increase

Engineering Contradiction:
Improvedata access speedVSAvoidsecurity risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system segments data storage into secure enterprise environment containers on the device, isolating enterprise data from the rest of the personal device. This allows fast local access to enterprise data while maintaining security through environmental isolation, preventing unauthorized access even if the device is compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security qualities are applied to different parts of the device: enterprise data stored in secure containers with strict access controls, while personal data remains accessible. This local quality approach enables fast access to enterprise data within the secure environment while maintaining overall security through differentiated protection strategies.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8839354B2Mobile enterprise server and client device interaction
Publication Date: 2014.09.16 VERIZON PATENT & LICENSING INC
  • US8839354B2 patent drawing
  • US8839354B2 patent drawing
  • US8839354B2 patent drawing

AI summary

A system includes an application server that hosts a plurality of enterprise applications and stores enterprise data associated with each of the enterprise applications. A client device executes a client application that can provide access to each of the enterprise applications. The client application includes a memory protection engine that allocates a first memory location for the enterprise data transmitted to the client device so the enterprise data is accessible to each of the plurality of enterprise applications through the client application. A second allocated memory location is allocated for non-enterprise data. A mobile enterprise server transmits the enterprise data to the client device.