Private Personal Mobile Device Management for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need to balance the security of enterprise data on personal devices used by employees, ensuring protection while respecting user privacy, as existing device management solutions often compromise privacy to enforce security policies.

Innovation Solution

The implementation of Private Personal Mobile Device Management (PPMDM) which allows users to control access to their devices, enforcing enterprise security policies while protecting personal data and privacy through user-defined permissions and conditional access, using APIs to manage device functions and data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional device management solutions are used to enforce enterprise security policies, then data security is improved, but user privacy is compromised

Engineering Contradiction:
Improvedata securityVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments device management into two distinct modes: public mode for enterprise data and resources where full security policies apply, and private mode for personal data where user privacy is preserved. This segmentation allows simultaneous enforcement of security policies for enterprise data while protecting personal information from surveillance and control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different management qualities to different parts of the device based on data type and usage context. Enterprise applications and data receive full security policy enforcement, while personal applications and data operate under relaxed privacy-protective policies. This local differentiation resolves the contradiction by applying strict security only where necessary.

Inventive Principle:
Principle #3Local quality

2Reliability

If strict security policies are enforced on personal devices, then enterprise data protection is improved, but device usability is reduced

Engineering Contradiction:
Improveenterprise data protectionVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic policy enforcement that adapts to the current usage context. The system automatically switches between public and private modes based on which application is active and what type of data is being accessed. This dynamic approach maintains strict security when enterprise data is involved while providing full usability when personal applications are used.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The device management system serves multiple functions through a single unified framework: it enforces security policies for enterprise data protection, preserves user privacy for personal data, and maintains seamless device usability. This multi-functionality resolves the contradiction by achieving all three goals simultaneously rather than requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive device monitoring is implemented, then security compliance is improved, but user autonomy is reduced

Engineering Contradiction:
Improvesecurity complianceVSAvoiduser autonomy
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments monitoring and control capabilities into public and private domains. Comprehensive monitoring is implemented only for enterprise-related activities in public mode, while personal activities in private mode are excluded from monitoring. This segmentation maintains security compliance for enterprise operations while preserving user autonomy for personal matters.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a mode-switching mechanism as an intermediary between security policies and user activities. This intermediary dynamically determines which policies apply based on the current context, allowing comprehensive monitoring when needed for security compliance while blocking monitoring when it would infringe on user autonomy for personal activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11741245B2Self-management of devices using personal mobile device management
Publication Date: 2023.08.29 LOOKOUT INC
  • US11741245B2 patent drawing
  • US11741245B2 patent drawing
  • US11741245B2 patent drawing

AI summary

An operating system of a mobile device defines an interface for an MDM to ensure security of the device. A private personal MDM (PPMDM) instead interfaces with the operating systems and one or more enterprise MDMs (EMDM) implement security policies through the PPMDM subject to user control. Data may be flagged as associated with an EMDM based on source or location to enable deletion due to theft or disassociation with an enterprise. Blocks or threat detection according to an EMDM policy may be reported to an EMDM in a non-invasive manner.