Personal Device Container System for Secure Multi-User Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing personal computing devices over secured networks lack an efficient method for provisioning and securing communication, leading to compatibility issues with various devices and inadequate multi-user management.

Innovation Solution

A personal device container system that authenticates devices using security credentials, creates network tunnels, and filters messages to ensure secure communication between personal computing devices and network segments, while also managing user access and location-based security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal computing devices are provided with unrestricted network access, then device compatibility and ease of operation are improved, but network security and message filtering control deteriorate

Engineering Contradiction:
Improvedevice compatibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The network is divided into multiple segments (provisioning network segment and secured network segment) with distinct access control mechanisms. The personal device container system creates separate network tunnels for provisioning communications and secured network communications, allowing each segment to have customized security policies while maintaining overall device compatibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The personal device container system acts as an intermediary between personal computing devices and the network segments. It receives communications from devices, determines the appropriate network segment, creates necessary network tunnels, filters messages according to security policies, and routes communications accordingly. This intermediary layer enables both device compatibility and network security by mediating between the two requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple network tunnels are created for different network segments, then network security and message filtering are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The personal device container system performs multiple functions within a single integrated platform: it manages network tunnel creation, filters messages, determines routing paths, and handles communications with multiple network segments. By consolidating these functions into one universal system rather than separate components, the patent reduces overall device complexity while maintaining comprehensive network security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If strict message filtering rules are applied to all communications, then network security is improved, but communication efficiency and productivity deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Different message filtering rules are applied to different network segments based on local requirements. The provisioning network segment has one set of filtering criteria for device onboarding, while the secured network segment has different criteria for data communications. This localized quality approach allows each segment to have appropriate security measures without unnecessarily blocking legitimate communications across the entire network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The message filtering rules are dynamically adjusted based on the communication context, the network segment being accessed, and the device's provisioning status. The system determines which filtering rules apply in real-time based on the communication type and destination, allowing efficient communications to pass through while blocking only truly malicious or unauthorized messages.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9571483B2Multi user device management system
Publication Date: 2017.02.14 BANK OF AMERICA CORP
  • US9571483B2 patent drawing
  • US9571483B2 patent drawing
  • US9571483B2 patent drawing

AI summary

Disclosed is a personal device container system. The personal device container system typically includes a processor, a memory, and an access management module stored in the memory. The personal device container system is typically configured to establish network communication between a personal computing device and a provisioning system that validates the identity of the personal computing device and provides a certificate to the personal computing device. Thereafter, the personal computing device requests access to a secured network segment and provides the certificate to the personal device container system. The personal device container system then authenticates the personal computing device's certificate before allowing the personal computing device to communicate with the secured network segment. User credentials associated with a user are authenticated before user-specific content associated with the user is provided to the personal computing device. Accordingly, a user-specific experience may be provided to different users of the personal computing device.