Policy Enforcement Points for Secure Domain Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current portable computing devices lack effective mechanisms for isolating and controlling application information according to policy requirements, failing to recognize multiple owners, provide persistent and pervasive policy enforcement, and segregate applications and data based on defined policies, especially when sharing between devices and services is necessary.
Innovation Solution
The implementation of a method and system that allows a computer data processing device to operate in multiple data security domains, using external policies to define and enforce fine-grained control over applications and data, without modifying the applications or requiring operating system privileges, through the use of domain-specific policy enforcement points and mediation modules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications and data are stored together on portable computing devices, then device utilization and accessibility are improved, but security control and data isolation deteriorate
Solution Approach 1:
The system segments the portable computing device into multiple security domains, each with its own policy enforcement mechanisms. Applications and data are assigned to specific domains based on security requirements, enabling simultaneous coexistence of multiple owners and data types while maintaining isolated security boundaries. This resolves the contradiction by allowing high device utilization through multiple domains while preserving security control through domain segmentation.
2Reliability
If OS-level protection mechanisms are used to separate enterprise and personal information, then security is improved, but flexibility and ease of operation deteriorate
Solution Approach 1:
The system introduces an intermediary policy enforcement point that operates between the application layer and the OS protection mechanisms. This intermediary enables flexible, policy-driven security control without requiring modifications to applications or deep OS integration. The policy enforcement point mediates security decisions based on domain policies, maintaining both security and flexibility by operating at the application-policy interface rather than requiring OS-level changes.
3Reliability
If virtualization technologies are used to isolate applications, then security isolation is improved, but device complexity and resource overhead worsen
Solution Approach 1:
The system extracts the security enforcement functionality from the complex virtualization infrastructure and implements it as a lightweight policy enforcement point within the existing OS architecture. Instead of relying on full virtualization overhead, the solution takes out only the essential security mediation functions and integrates them into the OS's existing process and memory management structures. This maintains effective isolation while reducing device complexity by avoiding the overhead of complete virtualization stacks.
Data Source
AI summary
This invention provides secure, policy-based separation of data and applications on computer, especially personal computers that operate in different environments, such as those including personal applications and corporate applications, so that both types of applications can run simultaneously while complying with all required policies. The invention enables employees to use their personal devices for work purposes, or work devices for personal purposes. The secure, policy-based separation is created by dividing the data processing device into two or more “domains,” each with its own policies. These policies may be configured by the device owner, an IT department, or other data or application owner.


