Multi-Domain Data Processing Device Security Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current portable computing devices lack the ability to effectively recognize multiple owners of applications and data, provide combined external and local policy-defined segregation, enforce persistent control over applications and information, and offer fine-grained control over operations between applications, leading to inadequate data protection and management.
Innovation Solution
The solution involves operating a computer data processing device in multiple data security domains, using external policies to define and manage application and data domains, with mechanisms for persistent control and fine-grained policy-based operations, including physical separation and dynamic mediation of communications between domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If applications and data are stored together on portable computing devices to enable employee independence and BYOD, then ease of operation and adaptability improve, but data security and control deteriorate
Solution Approach 1:
The patent divides the portable computing device into multiple segregated domains (enterprise domain, personal domain, etc.), each with its own policy enforcement mechanisms. This segmentation allows employees to use personal devices for both work and personal purposes while maintaining data security through domain isolation and persistent policy controls.
2Reliability
If virtualization technologies are used to segregate applications and data into disparate virtual machines, then data security improves, but application communication and information sharing deteriorate
Solution Approach 1:
The patent introduces a persistent control mechanism that acts as an intermediary between segregated domains. This mediator enables controlled communication and information sharing between domains while maintaining security boundaries, allowing applications in different domains to interact when policy permits without compromising data protection.
3Device complexity
If applications enforce required policies only when running, then device complexity remains low, but policy enforcement persistence and pervasiveness deteriorate
Solution Approach 1:
The patent implements persistent control mechanisms that establish policy enforcement rules in advance, before applications execute. These pre-configured policies are stored in the persistent control mechanism and automatically enforced whenever relevant applications run, ensuring consistent policy adherence without requiring complex real-time monitoring or application-level implementation.
Data Source
AI summary
This invention creates separation between personal applications and corporate applications on a data processing device, so that both types of applications can run simultaneously while complying with all required policies. This enables employees to use their personal devices for work purposes, or work devices for personal purposes. The separation is created by dividing the data processing device into two or more “domains”, each with its own policies. These policies may be configured by the device owner, an IT department, or other data or application owner.


