Secure Screenshot Capture in Mobile Workspace Containers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Previous Enterprise Mobility Management (EMM) technologies in mobile devices lack secure screenshot management for enterprise applications executing in protected workspace containers, leading to either complete disabling of screenshots or insecure storage outside the workspace container, which hinders sharing and debugging of enterprise application issues.

Innovation Solution

The technology processes screenshot capture requests by determining if the graphical user interface is generated by an enterprise application within the protected workspace container, performing a secure save operation that stores the screenshot within the container and encrypts it with a key accessible only to enterprise applications, preventing access by personal applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If screenshots are enabled for enterprise applications in the protected workspace container, then screenshot capture functionality is improved, but security is worsened because screenshots are stored in an unprotected folder outside the workspace container

Engineering Contradiction:
Improvescreenshot capture functionalityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the mobile device storage into two distinct partitions: a protected workspace container partition for enterprise applications and an unprotected personal partition for personal applications. Screenshots are stored in a dedicated secure folder within the workspace container partition, physically separating them from personal application access zones. This segmentation allows screenshot capture functionality to operate while maintaining security boundaries between enterprise and personal data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different locations within the mobile device storage system. The workspace container partition is configured with restricted access permissions that allow only enterprise applications to read/write screenshots, while the personal partition maintains open access for personal applications. This local quality differentiation enables screenshots to be captured and stored with enhanced security properties at their specific storage location without affecting overall system functionality.

Inventive Principle:
Principle #3Local quality

2Reliability

If screenshots are completely disabled for enterprise applications, then data security is improved, but debugging capability is worsened

Engineering Contradiction:
Improvedata securityVSAvoiddebugging capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary secure folder within the workspace container that acts as a controlled interface between the screenshot capture function and enterprise applications. This intermediary structure allows screenshots to be captured and stored securely, then accessed by enterprise applications through controlled mechanisms such as shared folders or integration with enterprise communication tools. This enables debugging capabilities while maintaining security, as screenshots can be viewed and shared through approved enterprise channels without exposing them to unauthorized personal application access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If screenshots are stored outside the protected workspace container, then accessibility for sharing is improved, but security is worsened

Engineering Contradiction:
Improvescreenshot sharing capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a nested structure where a secure screenshot folder is created within the protected workspace container partition. This nested arrangement allows screenshots to be stored in a secure environment while still enabling sharing capabilities through controlled access mechanisms. Enterprise applications can access screenshots through the nested folder structure, and screenshots can be shared via enterprise communication channels, all while remaining protected from personal application access. The nesting provides both security containment and controlled accessibility.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10762231B2Protecting screenshots of applications executing in a protected workspace container provided in a mobile device
Publication Date: 2020.09.01 CITRIX SYSTEMS INC
  • US10762231B2 patent drawing
  • US10762231B2 patent drawing
  • US10762231B2 patent drawing

AI summary

In response to determining that a graphical user interface displayed on the display device of a mobile device at the time a screenshot capture request is received is being generated at least in part by an enterprise application executing within a protected workspace container in the mobile device, a secure screenshot save operation is performed. The secure screenshot save operation includes i) storing, within the mobile device, a screenshot image of the graphical user interface displayed on the display device of the mobile device at the time the screenshot capture request is received, and ii) preventing the screenshot image from being accessed by any personal application executing on the mobile device outside of the protected workspace container.