Policy-Based Mobile App Management for BYOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise mobility management solutions face challenges in securely managing remote access to resources on personal mobile devices, particularly in Bring Your Own Device (BYOD) scenarios, where there is a lack of uniform control over devices and inherent security risks.

Innovation Solution

Implementing policy-based management for mobile applications, where each application operates under independent policy files defining security, feature, and resource limitations, enforced by a mobile device management system, allowing or restricting communications based on user credentials, role, location, and other determinable information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile device management approaches are used to manage entire mobile devices, then control over mobile devices and applications is improved, but device complexity and user flexibility are worsened

Engineering Contradiction:
Improvecontrol over mobile devicesVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments device management into application-level management. Instead of managing the entire device, the system manages individual applications independently through policy files. Each application has its own policy container that defines security, feature, and resource limitations, allowing granular control without impacting other applications or increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy files as intermediary objects between the management system and applications. These policy files act as mediators that carry management instructions from the server to the applications, enabling controlled communication without direct management of device operations. The policy files are stored in secure containers and enforced by the operating system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Bring Your Own Device scenarios are allowed, then user flexibility is improved, but security risks are worsened

Engineering Contradiction:
Improveuser flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by tailoring security policies to individual applications rather than applying uniform device-wide restrictions. Each application receives customized policy files that define its specific security requirements, permissions, and resource access rules. This allows users to install their own applications while maintaining targeted security control over each application's behavior.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses disposable security sandboxes for each application. Each application runs in an isolated environment with its own policy-enforced boundaries. When an application is uninstalled or compromised, its sandbox can be discarded without affecting other applications or the device. This disposable approach contains security risks within isolated containers.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If policy-based management is implemented for each application, then security control is improved, but management complexity is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy management framework that handles multiple security control functions through a single mechanism. The same policy file structure manages diverse requirements including security restrictions, feature limitations, resource access control, and communication guidelines. This multi-functional approach consolidates management complexity into a standardized policy format rather than requiring separate management systems for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9043480B2Policy-based application management
Publication Date: 2015.05.26 CITRIX SYSTEMS INC
  • US9043480B2 patent drawing
  • US9043480B2 patent drawing
  • US9043480B2 patent drawing

AI summary

Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.