Perimeter-Based Network Resource Routing Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication devices lack effective management of network resources across personal and enterprise perimeters, leading to security concerns and limited user control over data traffic routing, especially when using both personal and corporate networks simultaneously.
Innovation Solution
Implementing a system that allows users to manage network resources through logical perimeters, enabling cross-perimeter access control by defining policies for each perimeter, allowing users to choose whether personal or corporate data traffic is routed over specific networks, thereby separating and segregating traffic for added privacy and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users allow applications in a first perimeter to access network resources in a second perimeter, then network resource sharing and flexibility are improved, but security control and privacy protection deteriorate
Solution Approach 1:
The system divides the device into multiple perimeters (e.g., personal perimeter, enterprise perimeter) that logically separate applications and network resources. Each perimeter can independently control access to network resources, allowing selective sharing while maintaining security boundaries. This segmentation enables the device to share network resources across perimeters when needed while preserving security control through perimeter-specific policies.
2Ease of operation
If the device routes all data traffic through a single network connection, then network management is simplified, but user control over privacy and data segregation deteriorates
Solution Approach 1:
The system dynamically routes data traffic from different perimeters through different network connections based on user-defined policies and real-time conditions. Instead of a static single-network approach, the device can simultaneously use multiple network connections (e.g., corporate Wi-Fi for enterprise traffic, mobile data for personal traffic) and dynamically select which connection to use for each perimeter, providing both ease of operation and user control.
3Reliability
If enterprise administrators impose strict access controls on corporate network resources, then security and policy compliance are improved, but user convenience and flexibility deteriorate
Solution Approach 1:
The system segments network resources into enterprise-managed resources and personal resources within different perimeters. Enterprise administrators can impose strict access controls on corporate network resources in the enterprise perimeter while users maintain full control over personal applications and resources in the personal perimeter. This segmentation allows policy compliance for enterprise resources while preserving user convenience for personal use.
4Reliability
If the device separates personal and corporate traffic into different networks, then privacy and security are improved, but network complexity and configuration difficulty increase
Solution Approach 1:
The system automatically configures network routing based on perimeter definitions and user preferences without requiring complex manual network configuration. The device self-manages the separation of personal and corporate traffic by automatically applying perimeter policies and selecting appropriate network connections, reducing configuration complexity while maintaining privacy protection.
Data Source
AI summary
Some aspects of what is described here relate to managing the use of network resources on a mobile device. User input received at the device indicates whether to allow an application associated with a first perimeter on the device to access a network resource associated with a second perimeter on the device. For example, in some instances user input may indicate whether to allow data from applications associated with a personal perimeter on the device to be transmitted over an enterprise communication system. When outbound data associated with the first perimeter are received, the device determines, according to the indication from the user input, whether to route the outbound data to the network resource associated with the second perimeter.


