Secure Container System for Mobile Data Vault Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack efficient methods for controlling mobile device access to secure data and managing encrypted data vaults, particularly in enterprise environments, leading to security and data management challenges.
Innovation Solution
Implementing an enterprise application store that provides secure containers or data vaults for managed applications, with each application assigned a private or shared vault, and using policy-defined encryption to manage data access and deletion, including selective wipe capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If mobile devices are provided to employees with full access capabilities, then productivity and ease of operation are improved, but security control and data protection become difficult to maintain
Solution Approach 1:
The system segments the mobile device into managed and unmanaged partitions, with further segmentation into secure and non-secure areas within the managed partition. This allows employees to use the device freely while restricting access to enterprise data through the secure area, thus maintaining both productivity and security.
Solution Approach 2:
A device management system acts as an intermediary between the employee and enterprise resources. This intermediary enforces security policies, controls data access, and manages applications without preventing legitimate business use, thereby maintaining productivity while ensuring security compliance.
2Reliability
If encryption is applied to protect data in secure containers, then data security is improved, but access complexity and device complexity increase
Solution Approach 1:
The device management system automatically handles key generation, distribution, and management without requiring user intervention. Encryption and decryption operations are performed automatically based on policy rules, reducing the perceived complexity for end users while maintaining strong security.
Solution Approach 2:
Security policies, encryption keys, and container configurations are pre-configured and distributed to devices before data is accessed. This preliminary setup automates the complexity of encryption management, allowing users to access encrypted data without understanding the underlying cryptographic operations.
3Reliability
If selective wipe capability is implemented to delete specific application data, then data security is improved through controlled deletion, but time and operational complexity increase
Solution Approach 1:
The selective wipe capability is automatically triggered by policy violations or user actions without requiring manual data identification. The system self-services the deletion process by identifying which data to remove based on pre-configured policies, reducing the time and effort required for secure data deletion.
Solution Approach 2:
Manual data identification and deletion processes are replaced with automated policy-based deletion mechanisms. The device management system uses digital policies to automatically determine and execute the deletion of specific data sets, replacing manual mechanical processes with automated digital control.
Data Source
AI summary
Various aspects of the disclosure relate to providing secure containers or data vaults for data of one or more managed applications. In some embodiments, each managed application may be assigned its own private data vault and/or may be assigned a shared data vault that is accessible to at least one other managed application. As the managed application executes, calls for access to the data may be intercepted and redirected to the secure containers. Data stored in a secure container may be encrypted according to a policy. Other aspects relate to deleting data from a secure container, such as via a selective wipe of data associated with a managed application. Further aspects relate to configuring and creating the secure containers, retrieving key information required to encrypt/decrypt the data stored in the secure containers, and publishing the managed applications, policy information and key information for download to a mobile device.


