Secure Container System for Mobile Data Vault Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack efficient methods for controlling mobile device access to secure data and managing encrypted data vaults, particularly in enterprise environments, leading to security and data management challenges.

Innovation Solution

Implementing an enterprise application store that provides secure containers or data vaults for managed applications, with each application assigned a private or shared vault, and using policy-defined encryption to manage data access and deletion, including selective wipe capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If mobile devices are provided to employees with full access capabilities, then productivity and ease of operation are improved, but security control and data protection become difficult to maintain

Engineering Contradiction:
Improveemployee productivityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the mobile device into managed and unmanaged partitions, with further segmentation into secure and non-secure areas within the managed partition. This allows employees to use the device freely while restricting access to enterprise data through the secure area, thus maintaining both productivity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A device management system acts as an intermediary between the employee and enterprise resources. This intermediary enforces security policies, controls data access, and manages applications without preventing legitimate business use, thereby maintaining productivity while ensuring security compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to protect data in secure containers, then data security is improved, but access complexity and device complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The device management system automatically handles key generation, distribution, and management without requiring user intervention. Encryption and decryption operations are performed automatically based on policy rules, reducing the perceived complexity for end users while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies, encryption keys, and container configurations are pre-configured and distributed to devices before data is accessed. This preliminary setup automates the complexity of encryption management, allowing users to access encrypted data without understanding the underlying cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If selective wipe capability is implemented to delete specific application data, then data security is improved through controlled deletion, but time and operational complexity increase

Engineering Contradiction:
Improvedata securityVSAvoiddata management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The selective wipe capability is automatically triggered by policy violations or user actions without requiring manual data identification. The system self-services the deletion process by identifying which data to remove based on pre-configured policies, reducing the time and effort required for secure data deletion.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual data identification and deletion processes are replaced with automated policy-based deletion mechanisms. The device management system uses digital policies to automatically determine and execute the deletion of specific data sets, replacing manual mechanical processes with automated digital control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9858428B2Controlling mobile device access to secure data
Publication Date: 2018.01.02 CITRIX SYSTEMS INC
  • US9858428B2 patent drawing
  • US9858428B2 patent drawing
  • US9858428B2 patent drawing

AI summary

Various aspects of the disclosure relate to providing secure containers or data vaults for data of one or more managed applications. In some embodiments, each managed application may be assigned its own private data vault and/or may be assigned a shared data vault that is accessible to at least one other managed application. As the managed application executes, calls for access to the data may be intercepted and redirected to the secure containers. Data stored in a secure container may be encrypted according to a policy. Other aspects relate to deleting data from a secure container, such as via a selective wipe of data associated with a managed application. Further aspects relate to configuring and creating the secure containers, retrieving key information required to encrypt/decrypt the data stored in the secure containers, and publishing the managed applications, policy information and key information for download to a mobile device.