Secure Container SDK for BYOD Data Leakage Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies do not provide the necessary tools to enable secure content to remain secure when accessed, modified, or utilized on diverse mobile devices, limiting the implementation of Bring Your Own Device (BYOD) policies without compromising security.
Innovation Solution
A secure content platform with a software developer's kit (SDK) that provides a secure container and productivity suite, enabling secure access, manipulation, and collaboration of content across various devices and platforms, using robust authentication mechanisms and encryption to prevent data leaks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing enterprise solutions are used to access secure content, then security is maintained, but support for diverse user-owned devices is limited
Solution Approach 1:
The solution segments the secure content access system into multiple components: a secure container application that runs on diverse user devices, a cloud-based content management system, and authentication services. This segmentation allows the secure container to be deployed across different mobile operating systems and device types while maintaining centralized security controls, thereby resolving the contradiction between device compatibility and security.
Solution Approach 2:
The patent introduces a secure container as an intermediary layer between the user's diverse devices and the enterprise's secure content. This container acts as a mediator that enforces security policies, controls data access, and prevents data leakage regardless of the underlying device platform. The intermediary secure container enables support for user-owned devices while maintaining security boundaries.
2Reliability
If specialized secure devices are issued to users, then security is maintained, but device cost and complexity increase
Solution Approach 1:
The solution extracts the security functionality from the physical device itself and places it into a software-based secure container that can run on any device. Instead of requiring specialized hardware with built-in security features, the security capabilities are taken out and embedded as a portable application layer, reducing device complexity and management overhead while maintaining security.
Solution Approach 2:
The secure container is designed as a universal solution that can operate across multiple device types and operating systems. This multi-functional approach allows a single security platform to serve diverse devices without requiring specialized hardware for each device type, thereby reducing overall system complexity and device management burden.
3Adaptability or versatility
If secure content is accessed on diverse mobile devices, then device flexibility is improved, but data leakage risk increases
Solution Approach 1:
The secure container acts as a flexible software shell that wraps around and protects sensitive content on diverse mobile devices. This thin-film approach creates a protective layer that prevents data leakage through the device's operating system and applications while remaining adaptable to different device architectures and platforms.
Solution Approach 2:
The patent converts the potential harm of diverse device platforms into a benefit by using the secure container to enforce consistent security policies across all devices. The diversity of devices, which initially increases data leakage risk, becomes advantageous by allowing users to choose their preferred devices while the container neutralizes security risks and even provides broader platform testing and validation for the security model.
Data Source
AI summary
A system and method may be used to manipulate secure content on a first computing device through the use of a software developer's kit. The method may include defining a secure container as a subset of a data store of the first computing device. First instructions of the software developer's kit may be executed to retrieve the secure content from a first content source of a plurality of content sources managed by a plurality of different entities. The secure content may be stored in the secure container. At an input device, user input may be received to initiate manipulation of the secure content in a manner that avoids storage of any of the secure content on a portion of the data store outside the secure container.


