Multi-Persona Workspace Segregation for Secure BYOD Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile device management platforms face challenges in managing large numbers of devices, particularly in segregating personal and work-related data and applications on employee-owned devices, due to security concerns and the need for separate workspaces within operating systems.

Innovation Solution

A multi-persona enrollment management system that allows client devices to create a secondary workspace for work-related data and applications, interfacing with a management computing environment to enroll in device management services, establish an alternate persona account, and install an interface service, enabling remote administration of applications and data access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees use personal devices for enterprise computing systems (BYOD), then productivity and cost savings are improved, but security risks and data segregation challenges worsen

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the personal device into separate workspaces: a primary personal workspace and a secondary work persona workspace. This segmentation allows enterprise data and applications to be isolated from personal data, enabling secure BYOD implementation while maintaining productivity benefits.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an interface service as an intermediary component that enables communication between the primary and secondary workspaces while maintaining security boundaries. This intermediary controls data flow and access, resolving the conflict between security requirements and user productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secondary workspace is created for work-related data, then data segregation and security are improved, but device complexity and management difficulty worsen

Engineering Contradiction:
Improvedata segregationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The interface service acts as an intermediary that simplifies the complexity of managing multiple workspaces. It provides a standardized communication protocol and automation capabilities, reducing the burden on users and administrators while maintaining secure data segregation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service enrollment and configuration capabilities, allowing users to automatically set up their work personas without complex manual configuration. This reduces device complexity from the user perspective while maintaining security requirements.

Inventive Principle:
Principle #25Self-service

3Productivity

If remote administration capabilities are implemented, then management efficiency is improved, but system complexity and enrollment overhead worsen

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidenrollment overhead
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary enrollment actions where the interface service and workspace configuration are pre-established before actual use. This allows remote administration to be seamlessly integrated without adding complexity during user enrollment or daily operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11651101B2Multi-persona enrollment management
Publication Date: 2023.05.16 OMNISSA LLC
  • US11651101B2 patent drawing
  • US11651101B2 patent drawing
  • US11651101B2 patent drawing

AI summary

Examples of multi-persona account management in client devices are described. A client device can host a personal workspace, such as for personal data and applications of a user, along with a separate alternate persona workspace for work-related data and applications of the user. The client device interfaces with a management computing environment to enroll in device management services and establish the alternate persona workspace on the client device. In one example, the client device queries a management computing environment to establish an alternate persona workspace in the client device. The client device then creates the alternate persona workspace in the client device based on a response from the management computing environment, associates an alternate persona account with the alternate persona workspace, and receives a notification to install at least one application in the alternate persona workspace from an account administration environment of the alternate persona account.