On-device Application Compliance Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional compliance enforcement systems rely on central servers, which are ineffective when devices are offline and lack granularity in application-specific compliance enforcement, leading to uniform restrictions across all applications on a device.

Innovation Solution

Implementing on-device, application-specific compliance enforcement using a compliance engine within applications to evaluate and enforce compliance rules independently, allowing for conditional remedial actions without server connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central server is used for compliance evaluation and enforcement, then compliance rules can be applied consistently across devices, but the system becomes ineffective when devices are offline and lacks application-specific granularity

Engineering Contradiction:
Improvecompliance enforcement reliabilityVSAvoidapplication-specific compliance granularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments compliance enforcement by embedding compliance engines within individual applications rather than using a single centralized system. Each application contains its own compliance engine that independently evaluates and enforces compliance rules specific to that application, enabling granular control while maintaining reliability through distributed operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Applications perform self-compliance evaluation by executing compliance engines locally on the device. The compliance engines automatically assess whether compliance conditions are met and enforce remedial actions without requiring continuous server connectivity, making the system self-sufficient and reliable in offline scenarios.

Inventive Principle:
Principle #25Self-service

2Extent of automation

If a dedicated agent is installed on devices for compliance enforcement, then centralized control is maintained, but the agent requires frequent updates and faces user resistance to adoption

Engineering Contradiction:
Improvecentralized compliance controlVSAvoidagent adoption and maintenance
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent extracts compliance enforcement functionality from a centralized agent and embeds it directly within applications. This eliminates the need for a separate dedicated agent on devices, reducing installation friction and user resistance while maintaining automated compliance control through application-integrated engines.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The compliance engine is merged with the application itself rather than being a separate agent. This integration combines compliance enforcement with the application's core functionality, eliminating the need for additional software installation and reducing user resistance to adoption.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If device-level compliance rules are enforced, then all applications are treated uniformly, but application-specific compliance requirements cannot be met

Engineering Contradiction:
Improvecompliance rule simplicityVSAvoidapplication-specific compliance control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments compliance control at the application level rather than treating all applications uniformly. Each application's compliance engine independently manages compliance for that specific application, allowing differentiated control strategies for different applications while maintaining simple rule evaluation within each context.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by enabling each application to have its own compliance characteristics and enforcement strategies. Compliance rules are evaluated and enforced locally within each application context, allowing application-specific compliance requirements to be met without complicating the overall system architecture.

Inventive Principle:
Principle #3Local quality

4Object-affected harmful factors

If all application connections are restricted when untrusted locations are detected, then security is maximized, but legitimate business functionality is blocked

Engineering Contradiction:
Improvesecurity protectionVSAvoidapplication functionality availability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent segments connection restrictions by application rather than applying uniform blocking. Each application's compliance engine independently evaluates compliance conditions and enforces restrictions only for that specific application, allowing legitimate business functionality to continue while blocking only the specific application that violates compliance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by enabling selective enforcement of compliance restrictions at the application level. Each application is treated according to its specific compliance status and requirements, allowing differentiated control strategies that protect security while maintaining productivity for compliant applications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10848563B2On-device, application-specific compliance enforcement
Publication Date: 2020.11.24 OMNISSA LLC
  • US10848563B2 patent drawing
  • US10848563B2 patent drawing
  • US10848563B2 patent drawing

AI summary

Examples herein describe systems and methods for on-device, application-specific compliance enforcement. An example method can include receiving, at a user device, an application having a compliance engine. The user device can also store a compliance rule that applies to the received application. The compliance rule can specify a condition and a remedial action for the application. The user device can execute the application. The application can determine, using the compliance engine within the application, whether the condition is present. The determination can be made regardless of whether the device has internet or cellular connectivity. Based on determining that the condition is present, the application can perform the remedial action.