Private Personal Mobile Device Management for Enterprise Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need to balance the security of enterprise data on personal devices used by employees, ensuring protection while respecting user privacy, as existing device management solutions often compromise privacy to enforce security policies.
Innovation Solution
The implementation of Private Personal Mobile Device Management (PPMDM) which allows users to control access to their devices, enforcing enterprise security policies while protecting personal data and privacy through user-defined permissions and conditional access, using APIs to manage device functions and data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional device management solutions are used to enforce enterprise security policies, then data security is improved, but user privacy is compromised
Solution Approach 1:
The patent segments device management into two distinct modes: public mode for enterprise data and resources where full security policies apply, and private mode for personal data where user privacy is preserved. This segmentation allows simultaneous enforcement of security policies for enterprise data while protecting personal information from surveillance and control.
Solution Approach 2:
The patent applies different management qualities to different parts of the device based on data type and usage context. Enterprise applications and data receive full security policy enforcement, while personal applications and data operate under relaxed privacy-protective policies. This local differentiation resolves the contradiction by applying strict security only where necessary.
2Reliability
If strict security policies are enforced on personal devices, then enterprise data protection is improved, but device usability is reduced
Solution Approach 1:
The patent implements dynamic policy enforcement that adapts to the current usage context. The system automatically switches between public and private modes based on which application is active and what type of data is being accessed. This dynamic approach maintains strict security when enterprise data is involved while providing full usability when personal applications are used.
Solution Approach 2:
The device management system serves multiple functions through a single unified framework: it enforces security policies for enterprise data protection, preserves user privacy for personal data, and maintains seamless device usability. This multi-functionality resolves the contradiction by achieving all three goals simultaneously rather than requiring separate systems.
3Reliability
If comprehensive device monitoring is implemented, then security compliance is improved, but user autonomy is reduced
Solution Approach 1:
The patent segments monitoring and control capabilities into public and private domains. Comprehensive monitoring is implemented only for enterprise-related activities in public mode, while personal activities in private mode are excluded from monitoring. This segmentation maintains security compliance for enterprise operations while preserving user autonomy for personal matters.
Solution Approach 2:
The patent introduces a mode-switching mechanism as an intermediary between security policies and user activities. This intermediary dynamically determines which policies apply based on the current context, allowing comprehensive monitoring when needed for security compliance while blocking monitoring when it would infringe on user autonomy for personal activities.
Data Source
AI summary
An operating system of a mobile device defines an interface for an MDM to ensure security of the device. A private personal MDM (PPMDM) instead interfaces with the operating systems and one or more enterprise MDMs (EMDM) implement security policies through the PPMDM subject to user control. Data may be flagged as associated with an EMDM based on source or location to enable deletion due to theft or disassociation with an enterprise. Blocks or threat detection according to an EMDM policy may be reported to an EMDM in a non-invasive manner.


