Policy Enforcement Points for Secure Domain Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current portable computing devices lack effective mechanisms for isolating and controlling application information according to policy requirements, failing to recognize multiple owners, provide persistent and pervasive policy enforcement, and segregate applications and data based on defined policies, especially when sharing between devices and services is necessary.

Innovation Solution

The implementation of a method and system that allows a computer data processing device to operate in multiple data security domains, using external policies to define and enforce fine-grained control over applications and data, without modifying the applications or requiring operating system privileges, through the use of domain-specific policy enforcement points and mediation modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications and data are stored together on portable computing devices, then device utilization and accessibility are improved, but security control and data isolation deteriorate

Engineering Contradiction:
Improvedevice utilizationVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the portable computing device into multiple security domains, each with its own policy enforcement mechanisms. Applications and data are assigned to specific domains based on security requirements, enabling simultaneous coexistence of multiple owners and data types while maintaining isolated security boundaries. This resolves the contradiction by allowing high device utilization through multiple domains while preserving security control through domain segmentation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If OS-level protection mechanisms are used to separate enterprise and personal information, then security is improved, but flexibility and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary policy enforcement point that operates between the application layer and the OS protection mechanisms. This intermediary enables flexible, policy-driven security control without requiring modifications to applications or deep OS integration. The policy enforcement point mediates security decisions based on domain policies, maintaining both security and flexibility by operating at the application-policy interface rather than requiring OS-level changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If virtualization technologies are used to isolate applications, then security isolation is improved, but device complexity and resource overhead worsen

Engineering Contradiction:
ImproveisolationVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the security enforcement functionality from the complex virtualization infrastructure and implements it as a lightweight policy enforcement point within the existing OS architecture. Instead of relying on full virtualization overhead, the solution takes out only the essential security mediation functions and integrates them into the OS's existing process and memory management structures. This maintains effective isolation while reducing device complexity by avoiding the overhead of complete virtualization stacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10305937B2Dividing a data processing device into separate security domains
Publication Date: 2019.05.28 PULSE SECURE LLC
  • US10305937B2 patent drawing
  • US10305937B2 patent drawing
  • US10305937B2 patent drawing

AI summary

This invention provides secure, policy-based separation of data and applications on computer, especially personal computers that operate in different environments, such as those including personal applications and corporate applications, so that both types of applications can run simultaneously while complying with all required policies. The invention enables employees to use their personal devices for work purposes, or work devices for personal purposes. The secure, policy-based separation is created by dividing the data processing device into two or more “domains,” each with its own policies. These policies may be configured by the device owner, an IT department, or other data or application owner.