Persona-Based Mobile Device Data Isolation and Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End devices in mobile enterprise scenarios are vulnerable to unauthorized access and data loss, particularly when used on open wireless networks or lost, with existing solutions being limited in effectiveness, especially requiring network connectivity for remote data wiping.

Innovation Solution

Implementing multiple personae on a device with variable access criteria, applying policies to each persona, and creating a sandbox for secure access to resources, which isolates personal and business data and controls device functionalities based on context and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple personae with variable access are implemented, then data security and isolation are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the device into multiple personae (e.g., personal, work, guest) with separate sandboxes for each persona. Each persona has its own sandbox that isolates applications and data, preventing unauthorized access between personae. This segmentation approach improves data security while managing complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy manager as an intermediary component that mediates between different personae and controls access to device resources. The policy manager evaluates access requests against defined policies and determines whether to grant access, thereby simplifying the complexity management by centralizing control logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sandboxes are created for each persona, then unauthorized access is prevented, but device functionality is restricted

Engineering Contradiction:
Improveunauthorized accessVSAvoiddevice functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by creating sandboxes with different access permissions for different personae. Each persona's sandbox has specific local rules about what resources it can access (e.g., work persona can access corporate files, personal persona can access personal photos). This allows the system to prevent unauthorized access while maintaining appropriate functionality for each persona.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic access control where the allowed functionality changes based on which persona is active. The system can dynamically switch between different sandbox configurations and access policies depending on the current persona, allowing the device to adapt its functionality rather than being permanently restricted.

Inventive Principle:
Principle #15Dynamics

3Reliability

If access control policies are applied, then data protection is improved, but ease of operation decreases

Engineering Contradiction:
Improvedata protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by allowing users to select their preferred persona without needing to manually configure complex access controls. The system automatically applies the appropriate sandbox and policy settings when a user switches personas, making data protection transparent and convenient rather than burdensome.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8539561B2Systems and methods to control device endpoint behavior using personae and policies
Publication Date: 2013.09.17 SERVICENOW INC
  • US8539561B2 patent drawing
  • US8539561B2 patent drawing
  • US8539561B2 patent drawing

AI summary

The creation of multiple personae in mobile devices. Access to personae is controlled based on the persona that is currently active. The creation or existence of different personae helps prevent data leakage or loss, in that any or all of the following characteristics, by way of example, may be manifested: business data and applications are firewalled from applications or other items associated with personal use; connectivity of the device is controlled; resources (such cameras, GPS, other sensors, etc.) on the device are controlled; data are protected even if removable storage or the device itself are lost.