Mode Sensitive Networking Framework for Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mobile device encryption mechanisms are limited in providing mode separation and security, as they primarily operate at the application level, leaving vulnerabilities and gaps in data and application separation, especially when switching between personal and enterprise modes, and do not effectively encrypt external memory cards.
Innovation Solution
A multiple framework level mode system that introduces operating system-level classification of processes into modes, managing persistent storage, memory, and networking interfaces, enabling encryption at the file system level and dynamic split tunneling for secure network connections, while allowing seamless transitions between modes without disrupting user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprise grade applications are downloaded and installed on mobile devices to provide secure tunnels for transmitting data, then data transmission security is improved, but framework level behavior remains unaffected creating potential vulnerabilities and gaps in data and application separation
Solution Approach 1:
The system segments the mobile device into distinct personal and enterprise modes at the operating system framework level. This segmentation creates separate runtime environments, storage spaces, and network configurations for personal and enterprise applications, ensuring that enterprise-grade security mechanisms operate in isolation from personal applications, thereby eliminating framework-level vulnerabilities while maintaining application separation.
Solution Approach 2:
The patent introduces an intermediary layer (the mode separation service and resource partitioning engine) that mediates between personal and enterprise modes. This intermediary manages resource allocation, enforces security policies, and controls transitions between modes, ensuring that framework-level behavior is appropriately differentiated while maintaining secure data and application separation without requiring complex application-specific implementations.
2Ease of manufacture
If a single application level encryption mechanism is used on mobile devices, then implementation simplicity is maintained, but mode separation and security are severely limited leaving vulnerabilities in data and application separation
Solution Approach 1:
The patent transitions from application-level encryption to operating system framework-level mode separation. By adding this new dimension of security at the framework level, the system achieves comprehensive mode separation and security without sacrificing implementation simplicity. The framework-level implementation provides automatic enforcement of security policies across all applications, eliminating the need for complex application-specific encryption mechanisms while maintaining ease of deployment.
3Adaptability or versatility
If framework level behavior is not affected by enterprise grade applications, then application compatibility is maintained, but potential vulnerabilities and gaps in data and application separation models are created
Solution Approach 1:
The system dynamically adjusts framework-level behavior based on the active mode (personal or enterprise). When enterprise mode is activated, the framework enforces strict security policies, data separation, and application restrictions. When personal mode is active, standard framework behavior applies. This dynamic adaptation maintains application compatibility across both modes while ensuring data separation security is enforced when needed, without creating permanent vulnerabilities.
Data Source
AI summary
Mode sensitive networking is provided to allow mode specific communications using a mobile device. If a device has an established secured connection and an application is running in work mode, packets are routed through the secure connection. If the device has an established secured connection but an application is running in personal mode, packets are routed through an alternate connection. Secured connections may be established by using privileged applications. A device and associated applications may have access to different servers, sites, and destinations based on a current mode.


