Secure Communication Event Isolation via Workspace Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices supporting both secure and non-secure applications pose a risk of unauthorized exposure of enterprise data, as interactions between secure and non-secure content can inadvertently share sensitive information, especially if the device is lost or stolen.

Innovation Solution

A method and system that intercept communication events from external networks or devices, determine if they are secure, and process them using a secure application while preventing processing by non-secure applications, ensuring secure communication events are kept isolated from non-secure environments by comparing contact information with secure databases and prioritizing secure contacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a mobile device supports both secure and non-secure applications, then the device provides versatility and ease of operation, but the risk of unauthorized exposure of enterprise data increases

Engineering Contradiction:
Improvesupport for both secure and non-secure applicationsVSAvoidrisk of unauthorized exposure of enterprise data
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the mobile device into separate secure and non-secure workspaces with distinct application environments. Secure applications run in an isolated secure workspace while non-secure applications run in a separate non-secure workspace, preventing unauthorized access between the two environments while maintaining both types of applications on the same device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that intercepts communication events and determines whether they are secure or non-secure. This intermediary layer acts as a gatekeeper, routing secure communication events to secure applications and preventing them from being processed by non-secure applications, thus resolving the contradiction between versatility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If secure and non-secure applications interact on the same device, then ease of operation is improved, but information security deteriorates

Engineering Contradiction:
Improveaccess to both enterprise and personal contentVSAvoidinformation security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the device into secure and non-secure workspaces that can be accessed independently. Users can easily access personal content in the non-secure workspace and enterprise content in the secure workspace without compromising information security, as the two environments are isolated from each other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The intermediary component monitors and controls communication events between workspaces. It ensures that secure information remains within the secure workspace while allowing non-secure applications to access non-secure content, thus maintaining information security while preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the device is lost or stolen, then access to personal content may be protected, but secure enterprise data becomes vulnerable to unauthorized collection

Engineering Contradiction:
Improveprotection of personal contentVSAvoidunauthorized exposure of enterprise data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates physically isolated secure and non-secure workspaces within the device. Even if the device is lost or stolen, an unauthorized party can only access the non-secure workspace containing personal content, while the secure workspace containing enterprise data remains protected through isolation and requires additional authentication mechanisms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10311247B2Method and system for isolating secure communication events from a non-secure application
Publication Date: 2019.06.04 OMNISSA LLC
  • US10311247B2 patent drawing
  • US10311247B2 patent drawing

AI summary

A system and method for isolating secure communication events from a non-secure application are described herein. The method can include the steps of intercepting a communication event from an external communications network or an external communications device and determining whether the communication event is a secure communication event. If the communication event is a secure communication event, the secure communication event can be processed by a secure application. In addition, the secure communication event can be prevented from being processed by the non-secure application.