Policy-Based Mobile App Management for BYOD Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise mobility management solutions face challenges in securely managing remote access to resources on personal mobile devices, particularly in Bring Your Own Device (BYOD) scenarios, where there is a lack of uniform control over devices and inherent security risks.
Innovation Solution
Implementing policy-based management for mobile applications, where each application executes under the control of independent policy files defining security, feature, and resource limitations, allowing or restricting communications based on user credentials, role, location, and other determinable information, to enforce secure access to enterprise resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile device management approaches are used to manage entire mobile devices, then control over mobile devices is improved, but adaptability to personal devices and user autonomy deteriorates
Solution Approach 1:
The patent segments device management into application-level management. Instead of managing the entire mobile device, the system manages individual applications separately through policy files. This allows enterprise control over specific apps while leaving the rest of the device (OS, other apps, personal data) untouched and unmanaged.
Solution Approach 2:
Different parts of the mobile device have different management characteristics. The patent applies management policies selectively to specific applications based on their security requirements and enterprise relevance. Not all applications are treated equally - only those marked for management receive policy constraints, while personal apps remain unaffected.
2Adaptability or versatility
If Bring Your Own Device scenarios are allowed, then user autonomy and adaptability are improved, but security control and enterprise data protection deteriorate
Solution Approach 1:
The patent introduces policy files as intermediary objects between enterprises and applications. These policy files act as mediators that carry security rules and control instructions from the enterprise to the applications. The policies are stored separately from the applications and contain the necessary control logic to secure data access and communication.
Solution Approach 2:
Security policies are established and communicated to applications before the applications execute on personal devices. The policy files are distributed to mobile devices in advance, and applications retrieve and enforce the relevant policies before accessing enterprise resources. This preliminary setup ensures security controls are in place before any potential security incidents can occur.
3Reliability
If applications are managed through centralized policy control, then security and compliance are improved, but device complexity and management overhead increase
Solution Approach 1:
The patent extracts security management functionality from the application code itself and places it in separate policy files. This separation allows security policies to be managed independently of application logic. The policy files contain all the security control instructions, and applications simply retrieve and enforce the relevant policies without embedding complex management logic within their own code.
Data Source
AI summary
Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.


