Policy-Based Mobile App Management for BYOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise mobility management solutions face challenges in securely managing remote access to resources on personal mobile devices, particularly in Bring Your Own Device (BYOD) scenarios, where there is a lack of uniform control over devices and inherent security risks due to the mixed use of personal and enterprise data.

Innovation Solution

Implementing policy-based management for mobile applications, where each application operates under independent policy files defining security, feature, and resource limitations, allowing or restricting interactions with other applications and resources based on user credentials, role, location, and other determinable information, enforced by a mobile device management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If enterprises allow employees to use personal mobile devices for work purposes (BYOD), then employee convenience and flexibility are improved, but security control and data protection deteriorate

Engineering Contradiction:
Improveemployee convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the mobile device into managed and unmanaged partitions, allowing enterprise applications to operate in a controlled environment while personal applications remain outside this controlled zone. This segmentation enables security policies to be applied selectively to enterprise resources without restricting personal device usage, thus resolving the contradiction between employee convenience and security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an enterprise mobility management system as an intermediary layer between enterprise resources and mobile devices. This intermediary enforces security policies, controls data access, and manages application behavior without requiring direct control over the entire device. This allows employees to use personal devices freely while maintaining enterprise security through the mediating management system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises implement traditional mobile device management (MDM) solutions, then security control over enterprise resources is improved, but device complexity and user autonomy deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoiduser autonomy
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides device management into two distinct domains: managed enterprise applications with full security control and unmanaged personal applications with user autonomy. This segmentation allows MDM solutions to enforce security policies only where needed (enterprise resources) while leaving personal applications untouched, thereby reducing overall device complexity and preserving user autonomy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different management qualities to different parts of the device: enterprise applications receive strict security management and policy enforcement, while personal applications operate with minimal interference. This local differentiation of management quality allows comprehensive security control over enterprise resources without imposing unnecessary complexity on the entire device ecosystem.

Inventive Principle:
Principle #3Local quality

3Reliability

If enterprises enforce strict security policies over all applications, then data protection is improved, but application functionality and user flexibility deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a segmented architecture where security policies are applied only to enterprise applications within the managed partition, while personal applications in the unmanaged partition operate without these restrictions. This selective policy application protects enterprise data while preserving full functionality and flexibility of personal applications, resolving the contradiction between data protection and application versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The enterprise mobility management system acts as an intermediary that selectively enforces security policies based on application type and data sensitivity. It allows enterprise applications to access protected resources with appropriate security controls while permitting personal applications to function freely, thus maintaining both data protection and application functionality without mutual interference.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3422236A1Policy-based application management
Publication Date: 2019.01.02 CITRIX SYSTEMS INC
  • EP3422236A1 patent drawingFigure 1
  • EP3422236A1 patent drawingFigure 2
  • EP3422236A1 patent drawingFigure 3

AI summary

Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.