Policy-Based Mobile App Management for BYOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise mobility management solutions face challenges in securely managing remote access to resources on personal mobile devices, particularly in Bring Your Own Device (BYOD) scenarios, where there is a lack of uniform control over devices and inherent security risks.

Innovation Solution

Implementing policy-based management for mobile applications, where each application executes under the control of independent policy files defining security, feature, and resource limitations, allowing or restricting communications based on user credentials, role, location, and other determinable information, to enforce secure access to enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile device management approaches are used to manage entire mobile devices, then control over mobile devices is improved, but adaptability to personal devices and user autonomy deteriorates

Engineering Contradiction:
Improvecontrol over mobile devicesVSAvoidadaptability to personal devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments device management into application-level management. Instead of managing the entire mobile device, the system manages individual applications separately through policy files. This allows enterprise control over specific apps while leaving the rest of the device (OS, other apps, personal data) untouched and unmanaged.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the mobile device have different management characteristics. The patent applies management policies selectively to specific applications based on their security requirements and enterprise relevance. Not all applications are treated equally - only those marked for management receive policy constraints, while personal apps remain unaffected.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If Bring Your Own Device scenarios are allowed, then user autonomy and adaptability are improved, but security control and enterprise data protection deteriorate

Engineering Contradiction:
Improveuser autonomyVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces policy files as intermediary objects between enterprises and applications. These policy files act as mediators that carry security rules and control instructions from the enterprise to the applications. The policies are stored separately from the applications and contain the necessary control logic to secure data access and communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security policies are established and communicated to applications before the applications execute on personal devices. The policy files are distributed to mobile devices in advance, and applications retrieve and enforce the relevant policies before accessing enterprise resources. This preliminary setup ensures security controls are in place before any potential security incidents can occur.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If applications are managed through centralized policy control, then security and compliance are improved, but device complexity and management overhead increase

Engineering Contradiction:
Improvesecurity and complianceVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security management functionality from the application code itself and places it in separate policy files. This separation allows security policies to be managed independently of application logic. The policy files contain all the security control instructions, and applications simply retrieve and enforce the relevant policies without embedding complex management logic within their own code.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8881229B2Policy-based application management
Publication Date: 2014.11.04 CITRIX SYSTEMS INC
  • US8881229B2 patent drawing
  • US8881229B2 patent drawing
  • US8881229B2 patent drawing

AI summary

Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.