Mode Sensitive Networking Framework for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile device encryption mechanisms are limited in providing mode separation and security, as they primarily operate at the application level, leaving vulnerabilities and gaps in data and application separation, especially when switching between personal and enterprise modes, and do not effectively encrypt external memory cards.

Innovation Solution

A multiple framework level mode system that introduces operating system-level classification of processes into modes, managing persistent storage, memory, and networking interfaces, enabling encryption at the file system level and dynamic split tunneling for secure network connections, while allowing seamless transitions between modes without disrupting user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise grade applications are downloaded and installed on mobile devices to provide secure tunnels for transmitting data, then data transmission security is improved, but framework level behavior remains unaffected creating potential vulnerabilities and gaps in data and application separation

Engineering Contradiction:
Improvedata transmission securityVSAvoidapplication separation model
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the mobile device into distinct personal and enterprise modes at the operating system framework level. This segmentation creates separate runtime environments, storage spaces, and network configurations for personal and enterprise applications, ensuring that enterprise-grade security mechanisms operate in isolation from personal applications, thereby eliminating framework-level vulnerabilities while maintaining application separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer (the mode separation service and resource partitioning engine) that mediates between personal and enterprise modes. This intermediary manages resource allocation, enforces security policies, and controls transitions between modes, ensuring that framework-level behavior is appropriately differentiated while maintaining secure data and application separation without requiring complex application-specific implementations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If a single application level encryption mechanism is used on mobile devices, then implementation simplicity is maintained, but mode separation and security are severely limited leaving vulnerabilities in data and application separation

Engineering Contradiction:
Improveimplementation simplicityVSAvoidmode separation security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent transitions from application-level encryption to operating system framework-level mode separation. By adding this new dimension of security at the framework level, the system achieves comprehensive mode separation and security without sacrificing implementation simplicity. The framework-level implementation provides automatic enforcement of security policies across all applications, eliminating the need for complex application-specific encryption mechanisms while maintaining ease of deployment.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If framework level behavior is not affected by enterprise grade applications, then application compatibility is maintained, but potential vulnerabilities and gaps in data and application separation models are created

Engineering Contradiction:
Improveapplication compatibilityVSAvoiddata separation security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically adjusts framework-level behavior based on the active mode (personal or enterprise). When enterprise mode is activated, the framework enforces strict security policies, data separation, and application restrictions. When personal mode is active, standard framework behavior applies. This dynamic adaptation maintains application compatibility across both modes while ensuring data separation security is enforced when needed, without creating permanent vulnerabilities.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9143943B2Mode sensitive networking
Publication Date: 2015.09.22 DELL PROD LP
  • US9143943B2 patent drawing
  • US9143943B2 patent drawing
  • US9143943B2 patent drawing

AI summary

Mode sensitive networking is provided to allow mode specific communications using a mobile device. If a device has an established secured connection and an application is running in work mode, packets are routed through the secure connection. If the device has an established secured connection but an application is running in personal mode, packets are routed through an alternate connection. Secured connections may be established by using privileged applications. A device and associated applications may have access to different servers, sites, and destinations based on a current mode.