Policy-Based Secure Containers for Enterprise Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securing their networks while allowing employees to use a variety of personal devices, as managing these devices for security purposes can be inconvenient and impractical, and unmanaged devices may compromise network security.

Innovation Solution

Implementing a system with policy-based secure containers that enforce enterprise security policies on client computing devices, allowing users to access enterprise applications while managing security at the application level rather than the device level, using a client computing device and an enterprise policy server to enforce security policies based on trust and sensitivity levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise management of user-owned consumer devices is implemented, then network security is improved, but user convenience and ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the device into managed and unmanaged portions by implementing a containerized application environment. The container acts as a boundary that isolates enterprise applications and their data from the rest of the device, allowing the enterprise to manage only the necessary portion (the container) while leaving the rest of the consumer device unmanaged. This resolves the contradiction by providing security where needed without imposing enterprise management constraints on the entire device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies enterprise security policies locally to specific applications and data within containers rather than globally across the entire device. Each container can have its own security policies, permissions, and management rules tailored to the specific enterprise application it contains. This allows the enterprise to enforce security measures precisely where enterprise data and applications reside, without affecting other parts of the device that remain unmanaged and user-controlled.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If unmanaged devices are allowed access to enterprise networks, then user convenience is improved, but network security deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a container as an intermediary layer between the unmanaged consumer device and the enterprise network resources. The container mediates all interactions between enterprise applications and the device's hardware, operating system, and other applications. It enforces security policies, controls access to sensitive data, and manages communication channels, thereby protecting the enterprise network while allowing the device to remain unmanaged and convenient for the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If enterprise applications are deployed on consumer devices, then adaptability and versatility are improved, but security management complexity increases

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal containerized application environment that can run on various consumer devices regardless of their specific operating system, hardware configuration, or other characteristics. The container provides a standardized interface and execution environment that works across different device types, allowing enterprise applications to be deployed widely without requiring device-specific customization or management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12184704B2Policy-based secure containers for multiple enterprise applications
Publication Date: 2024.12.31 INTEL CORP
  • US12184704B2 patent drawing
  • US12184704B2 patent drawing
  • US12184704B2 patent drawing

AI summary

Technologies for providing policy-based secure containers for multiple enterprise applications include a client computing device and an enterprise policy server. The client computing device sends device attribute information and a request for access to an enterprise application to the enterprise policy server. The enterprise policy server determines a device trust level based on the device attribute information and a data sensitivity level based on the enterprise application, and sends a security policy to the client computing device based on the device trust level and the data sensitivity level. The client computing device references or creates a secure container for the security policy, adds the enterprise application to the secure container, and enforces the security policy while executing the enterprise application in the secure container. Multiple enterprise applications may be added to each secure container. Other embodiments are described and claimed.