Multi-Domain Mobile Computing Security Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device management solutions fail to provide multi-level security and accessibility across different domains, such as classified and unclassified data, leading to potential security compromises due to untrustworthy applications and online behaviors.

Innovation Solution

A mobile computing device is configured to support multiple independent application environments or 'personas' with different security domains, allowing for secure management of communication and resource allocation, including encryption and network selection based on security domains, to isolate and protect data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple application environments with different security domains are supported simultaneously, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the computing device into multiple isolated application environments (first application environment and second application environment), each associated with different security domains. This segmentation allows security policies to be applied independently to each environment, improving security protection while managing complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A communication manager acts as an intermediary between the different application environments and the communication networks. This mediator controls and monitors all communications, applying appropriate security policies and encryption based on the security domain of each application environment, thereby improving security while simplifying the management of complex multi-domain interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If application environments are switched quickly between security domains, then productivity is improved, but loss of time during reconfiguration increases

Engineering Contradiction:
Improveswitching speedVSAvoidreconfiguration time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring multiple application environments with their respective security domains, communication networks, and security policies before switching is needed. The communication manager maintains ready-state configurations for different security domains, allowing rapid switching without time-consuming reconfiguration during actual domain transitions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements dynamic switching between application environments based on the security domain requirements of active applications. The communication manager dynamically adjusts communication settings, network selections, and security policies according to the currently active application environment, enabling fast adaptation to different security contexts without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If communication networks are selected based on security domain criteria, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidcommunication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The communication manager serves as an intermediary that centralizes the complexity of managing multiple communication networks and security domains. It automatically selects appropriate networks based on the security domain of the active application environment, applying encryption and security policies without requiring complex user-level configuration or management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service communication management where the communication manager automatically selects appropriate communication networks and applies security policies based on the active application environment's security domain. This automation reduces the need for manual intervention and simplifies user interaction despite the underlying complexity of multi-network management.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11599626B1Fast reconfiguring environment for mobile computing devices
Publication Date: 2023.03.07 ARCHITECTURE TECH CORP
  • US11599626B1 patent drawing
  • US11599626B1 patent drawing
  • US11599626B1 patent drawing

AI summary

An example method includes receiving an indication of a selection of a first application environment that includes a first virtual environment associated with a first security domain and is configured to isolate execution of software applications within the first application environment, suspending execution of a second application environment that includes a second virtual environment associated with a second security domain different from the first security domain, initiating execution of the first application environment, identifying information associated with the first security domain and provided by the first application environment that is to be sent to an external computing device associated with the first security domain, selecting communication network(s) from one or more communication networks that are each available to the mobile computing device for data communication, encrypting, based on the first security domain and network(s), the information, and sending, to the external computing device via the network(s), the encrypted information.