Secure Mobile Framework Segmentation for Enterprise Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Companies face security risks due to unauthorized access to enterprise services through mobile devices, especially when devices are lost or unmanaged, leading to potential data breaches and compliance issues with existing mobile device management (MDM) policies that are cumbersome for users.

Innovation Solution

A secure mobile framework that generates and manages framework authentication tokens and security policies to ensure authorized access to enterprise services, using a gateway to authenticate and authorize applications, and monitors interactions for fraud detection, ensuring secure connections and data storage within a secure container.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If MDM policies are implemented to restrict control of mobile devices, then security risks are reduced, but user convenience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments mobile devices into two distinct environments: a secure container for enterprise services with full MDM control, and a personal environment with user autonomy. This segmentation allows security policies to be applied only where needed while preserving user convenience in personal spaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security control levels are applied to different parts of the mobile device. The secure container receives strict MDM policy enforcement for enterprise services, while the personal environment maintains relaxed controls, achieving local optimization of both security and usability.

Inventive Principle:
Principle #3Local quality

2Reliability

If strict MDM policies are enforced, then data protection is improved, but device functionality is restricted

Engineering Contradiction:
Improvedata protectionVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The mobile device is divided into a secure container for enterprise data and services with strict protection, and a personal environment with full functionality. This allows data protection to be enforced where critical while maintaining device versatility elsewhere.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure container acts as an intermediary layer between enterprise services and the mobile device. It provides controlled access to enterprise resources while isolating personal applications and data, enabling both protection and functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication and authorization processes are implemented, then access security is improved, but system complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The framework introduces an intermediary authentication layer that manages security credentials and policies centrally. This intermediary handles complex authentication flows between mobile devices and enterprise services, shielding users from complexity while maintaining strong access security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication framework provides universal security mechanisms that work across multiple enterprise services and applications. By establishing once, the authentication credentials are reused across services, reducing overall system complexity while maintaining comprehensive access security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9565212B2Secure mobile framework
Publication Date: 2017.02.07 SYNCHRONOSS TECHNOLOGIES INC
  • US9565212B2 patent drawing
  • US9565212B2 patent drawing
  • US9565212B2 patent drawing

AI summary

Systems and methods for a secure mobile framework to securely connect applications running on mobile devices to services within an enterprise are provided. Various embodiments provide mechanisms of securitizing data and communication between mobile devices and end point services accessed from a gateway of responsible authorization, authentication, anomaly detection, fraud detection, and policy management. Some embodiments provide for the integration of server and client side security mechanisms, binding of a user/application/device to an endpoint service along with multiple encryption mechanisms. For example, the secure mobile framework provides a secure container on the mobile device, secure files, a virtual file system partition, a multiple level authentication approach (e.g., to access a secure container on the mobile device and to access enterprise services), and a server side fraud detection system.