Perimeter-Based Data Access Control for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security management systems for communication devices fail to effectively segregate and manage multiple user and enterprise data perimeters, leading to potential data breaches and lack of fine-grained control over access to resources.
Innovation Solution
Implementing a perimeter-based architecture that logically separates resources and policies on a device, allowing for multiple perimeters with distinct management schemes, encryption strengths, and user-defined preferences, enabling secure access control and data segregation from the operating system to the user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security management systems are used, then device security is maintained, but data segregation and fine-grained access control between multiple user perimeters are insufficient
Solution Approach 1:
The system divides the device data space into multiple isolated perimeters (e.g., personal perimeter, enterprise perimeter, government perimeter), each with its own security policies and access controls. This segmentation enables independent management of different data types while maintaining overall security, resolving the contradiction between security reliability and adaptability for multi-user environments.
Solution Approach 2:
The patent introduces a new dimensional layer of perimeter abstraction above the traditional file system hierarchy. This dimensional change allows security policies to be applied at the perimeter level rather than just at individual files or folders, enabling fine-grained access control across multiple user contexts while maintaining system-wide security consistency.
2Ease of operation
If multiple perimeters with distinct management schemes are implemented, then fine-grained access control is achieved, but system complexity increases
Solution Approach 1:
The system introduces perimeter management components as intermediary layers between applications and the underlying file system. These intermediaries handle the complexity of multi-perimeter management, policy enforcement, and access control decisions, allowing users to benefit from fine-grained control without directly managing the underlying system complexity.
Solution Approach 2:
The perimeter architecture provides universal access control mechanisms that work across all applications and data types uniformly. By creating a standardized perimeter interface and policy framework, the system achieves fine-grained control without requiring separate management approaches for different scenarios, thereby reducing operational complexity despite the enhanced control capabilities.
3Reliability
If data is segregated across multiple perimeters, then data breach risk is reduced, but data sharing between perimeters becomes restricted
Solution Approach 1:
The system implements dynamic access control policies that can adaptively grant or restrict perimeter crossings based on contextual factors such as user identity, data sensitivity, and operation type. This dynamic approach allows data to be protected by default while enabling legitimate sharing scenarios, resolving the contradiction between data protection and accessibility.
Solution Approach 2:
The perimeter management system incorporates feedback mechanisms that monitor access requests and enforce policies based on real-time conditions. This feedback loop ensures that data remains protected while allowing authorized sharing to occur, as the system continuously evaluates access requests against current security contexts and policy rules.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for managing application execution and data access on a mobile device, wherein a request to access data is received from an application associated with a first perimeter on a device, while the data has a data type and is associated with a second, perimeter on the device, which is different from the first perimeter. It is determined, based on the data type, whether a management policy associated with the first perimeter permits the application to access the data independently of a second, different management policy assigned to the second perimeter. Depending on the results of the determination, the application is provided access to the data.