Per-Application Profile Management for Secure Work-Personal Data Coexistence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of personal smartphones for work purposes poses security and privacy risks due to uncontrolled applications and data storage, and existing virtualization techniques are resource-intensive and limit simultaneous use of work and personal applications.
Innovation Solution
A profile management service that creates and manages per-application profiles, allowing users to switch individual applications between work and personal profiles without affecting other applications, using storage partitions for data isolation and a policy enforcer to implement security policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtualization techniques are used to separate work and personal data, then security and privacy are improved, but resource overhead increases and simultaneous use of work and personal applications is limited
Solution Approach 1:
The patent segments the application execution environment into multiple isolated containers, each associated with a specific profile (work or personal). Each container has its own execution context and data storage, allowing security isolation without requiring full virtualization overhead. This enables multiple applications to run simultaneously in different profile contexts with minimal resource consumption.
Solution Approach 2:
The patent introduces a profile dimension orthogonal to the application layer, allowing the same application to be instantiated multiple times with different profile contexts. This dimensional approach enables work and personal applications to coexist without competing for the same execution resources, reducing overhead while maintaining security isolation.
2Reliability
If virtualization techniques are used to separate work and personal data, then security and privacy are improved, but device complexity increases
Solution Approach 1:
The system segments data storage and application execution contexts into profile-specific containers. Each profile has its own isolated storage area and execution environment, achieving privacy protection through logical segmentation rather than complex virtualization infrastructure. This reduces device complexity while maintaining strong privacy boundaries.
Solution Approach 2:
The patent introduces a profile management service as an intermediary layer between applications and the underlying system resources. This mediator handles profile switching, data isolation, and security policy enforcement, simplifying the overall system architecture compared to full virtualization while maintaining privacy protection.
3Ease of operation
If the same device is used for both work and personal activities, then convenience is improved, but security risks increase
Solution Approach 1:
The patent implements dynamic profile switching that allows applications to change their security context on-demand. Users can switch between work and personal profiles for different applications without leaving the device or disrupting their workflow, maintaining convenience while adapting security boundaries dynamically to the current usage context.
Solution Approach 2:
The system applies different security qualities locally to different applications and data based on their profile associations. Each application container has its own security characteristics and access permissions tailored to its specific profile, allowing high security for work applications while maintaining ease of use for personal applications on the same device.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for creating and managing per-application profiles are disclosed. A method may include receiving input designating at least a first profile policy and a second profile policy. At least a first application profile and a second application profile may be created based on the received first profile policy and the second profile policy. An application of the plurality of applications may be associated with both the first application profile and the second application profile. A first storage partition and a second storage partition may be created within a storage space of the computing device. The storage space may be associated with the application. The first storage partition may store application data while the application is running under the first application profile. The second storage partition may store application data while the application is running under the second application profile.