Policy-Based Secure Containers for Enterprise Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in securing their networks while allowing employees to use a variety of personal devices, as managing these devices for security purposes can be inconvenient and impractical, and unmanaged devices may compromise network security.
Innovation Solution
Implementing a system with policy-based secure containers that enforce enterprise security policies on client computing devices, allowing users to access enterprise applications while managing security at the application level rather than the device level, using a client computing device and an enterprise policy server to enforce security policies based on trust and sensitivity levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprise management of user-owned consumer devices is implemented, then network security is improved, but user convenience and ease of operation deteriorates
Solution Approach 1:
The patent segments the device into managed and unmanaged portions by implementing a containerized application environment. The container acts as a boundary that isolates enterprise applications and their data from the rest of the device, allowing the enterprise to manage only the necessary portion (the container) while leaving the rest of the consumer device unmanaged. This resolves the contradiction by providing security where needed without imposing enterprise management constraints on the entire device.
Solution Approach 2:
The patent applies enterprise security policies locally to specific applications and data within containers rather than globally across the entire device. Each container can have its own security policies, permissions, and management rules tailored to the specific enterprise application it contains. This allows the enterprise to enforce security measures precisely where enterprise data and applications reside, without affecting other parts of the device that remain unmanaged and user-controlled.
2Ease of operation
If unmanaged devices are allowed access to enterprise networks, then user convenience is improved, but network security deteriorates
Solution Approach 1:
The patent introduces a container as an intermediary layer between the unmanaged consumer device and the enterprise network resources. The container mediates all interactions between enterprise applications and the device's hardware, operating system, and other applications. It enforces security policies, controls access to sensitive data, and manages communication channels, thereby protecting the enterprise network while allowing the device to remain unmanaged and convenient for the user.
3Adaptability or versatility
If enterprise applications are deployed on consumer devices, then adaptability and versatility are improved, but security management complexity increases
Solution Approach 1:
The patent creates a universal containerized application environment that can run on various consumer devices regardless of their specific operating system, hardware configuration, or other characteristics. The container provides a standardized interface and execution environment that works across different device types, allowing enterprise applications to be deployed widely without requiring device-specific customization or management complexity.
Data Source
AI summary
Technologies for providing policy-based secure containers for multiple enterprise applications include a client computing device and an enterprise policy server. The client computing device sends device attribute information and a request for access to an enterprise application to the enterprise policy server. The enterprise policy server determines a device trust level based on the device attribute information and a data sensitivity level based on the enterprise application, and sends a security policy to the client computing device based on the device trust level and the data sensitivity level. The client computing device references or creates a secure container for the security policy, adds the enterprise application to the secure container, and enforces the security policy while executing the enterprise application in the secure container. Multiple enterprise applications may be added to each secure container. Other embodiments are described and claimed.


