Secure Container Platform for Unmanaged Device Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporate employees face challenges accessing corporate applications and data from unsecured personal devices due to compatibility issues with diverse hardware and software platforms, limiting their ability to perform job duties effectively and securely.

Innovation Solution

A method and system that provide a customized graphical user interface by modifying user interface configuration files based on user authentication and device characteristics, allowing secure access to corporate services on untrusted devices through a secure container, using HTTPS and encryption, enabling seamless access to applications and data across various devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees use personal devices to access corporate resources, then accessibility and convenience are improved, but security and control deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the user device environment by creating an isolated container that separates corporate resources from the untrusted device environment. This container acts as a secure boundary that allows access to corporate applications and data while preventing the device itself from being compromised, thus maintaining security while enabling accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure container acts as an intermediary layer between the untrusted personal device and corporate resources. This intermediary provides the necessary security controls, authentication mechanisms, and environment isolation, allowing employees to access corporate resources conveniently while maintaining enterprise security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If corporate applications are deployed on diverse personal devices, then device compatibility and user preference are improved, but system complexity and management difficulty worsen

Engineering Contradiction:
Improvedevice compatibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure container is designed as a universal solution that can run on multiple device types (smartphones, tablets, laptops) with different operating systems. The container provides a standardized environment for deploying corporate applications, eliminating the need to manage multiple device-specific configurations and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adapts to diverse devices by dynamically adjusting container parameters such as screen resolution, input methods, and interface layouts based on device characteristics. This parameter adaptation allows consistent application deployment across different form factors without increasing management complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a secure container is implemented on untrusted devices, then security control is improved, but device performance and resource availability worsen

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The secure container implements security controls selectively only for corporate resources rather than the entire device. By applying security measures partially - only where needed for corporate applications and data - the system maintains strong security control while minimizing impact on overall device performance and user experience.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11115211B2Secure container platform for resource access and placement on unmanaged and unsecured devices
Publication Date: 2021.09.07 51 MAPS INC
  • US11115211B2 patent drawing
  • US11115211B2 patent drawing
  • US11115211B2 patent drawing

AI summary

A first computing device receives a service access request to access a service provided by another computing device, the request including user authentication characteristics of a user. The first computing device forwards the service access request to the other computing device. The first computing device receives a user interface configuration file from the other computing device, that, when executed by the second computing device, enables the second computing device to display a user interface that provides access to the service. The first computing device modifies the user interface configuration file based on the user authentication characteristics to provide selective access to the service. The first computing device transmits the modified user interface configuration file to the second computing device, that, when executed by the second computing device, enables the second computing device to display a modified user interface that provides selective access to the service.