Multi-Domain Data Processing Device Security Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current portable computing devices lack the ability to effectively recognize multiple owners of applications and data, provide combined external and local policy-defined segregation, enforce persistent control over applications and information, and offer fine-grained control over operations between applications, leading to inadequate data protection and management.

Innovation Solution

The solution involves operating a computer data processing device in multiple data security domains, using external policies to define and manage application and data domains, with mechanisms for persistent control and fine-grained policy-based operations, including physical separation and dynamic mediation of communications between domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications and data are stored together on portable computing devices to enable employee independence and BYOD, then ease of operation and adaptability improve, but data security and control deteriorate

Engineering Contradiction:
Improveemployee independenceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the portable computing device into multiple segregated domains (enterprise domain, personal domain, etc.), each with its own policy enforcement mechanisms. This segmentation allows employees to use personal devices for both work and personal purposes while maintaining data security through domain isolation and persistent policy controls.

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtualization technologies are used to segregate applications and data into disparate virtual machines, then data security improves, but application communication and information sharing deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidapplication communication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a persistent control mechanism that acts as an intermediary between segregated domains. This mediator enables controlled communication and information sharing between domains while maintaining security boundaries, allowing applications in different domains to interact when policy permits without compromising data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If applications enforce required policies only when running, then device complexity remains low, but policy enforcement persistence and pervasiveness deteriorate

Engineering Contradiction:
Improvecontrol mechanism complexityVSAvoidpolicy enforcement persistence
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements persistent control mechanisms that establish policy enforcement rules in advance, before applications execute. These pre-configured policies are stored in the persistent control mechanism and automatically enforced whenever relevant applications run, ensuring consistent policy adherence without requiring complex real-time monitoring or application-level implementation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8931042B1Dividing a data processing device into separate security domains
Publication Date: 2015.01.06 PULSE SECURE LLC
  • US8931042B1 patent drawing
  • US8931042B1 patent drawing
  • US8931042B1 patent drawing

AI summary

This invention creates separation between personal applications and corporate applications on a data processing device, so that both types of applications can run simultaneously while complying with all required policies. This enables employees to use their personal devices for work purposes, or work devices for personal purposes. The separation is created by dividing the data processing device into two or more “domains”, each with its own policies. These policies may be configured by the device owner, an IT department, or other data or application owner.