Secure Screenshot Capture in Mobile Workspace Containers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Previous Enterprise Mobility Management (EMM) technologies in mobile devices lack secure screenshot management for enterprise applications executing in protected workspace containers, leading to either complete disabling of screenshots or insecure storage outside the workspace container, which hinders sharing and debugging of enterprise application issues.
Innovation Solution
The technology processes screenshot capture requests by determining if the graphical user interface is generated by an enterprise application within the protected workspace container, performing a secure save operation that stores the screenshot within the container and encrypts it with a key accessible only to enterprise applications, preventing access by personal applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If screenshots are enabled for enterprise applications in the protected workspace container, then screenshot capture functionality is improved, but security is worsened because screenshots are stored in an unprotected folder outside the workspace container
Solution Approach 1:
The patent segments the mobile device storage into two distinct partitions: a protected workspace container partition for enterprise applications and an unprotected personal partition for personal applications. Screenshots are stored in a dedicated secure folder within the workspace container partition, physically separating them from personal application access zones. This segmentation allows screenshot capture functionality to operate while maintaining security boundaries between enterprise and personal data.
Solution Approach 2:
The patent applies different security qualities to different locations within the mobile device storage system. The workspace container partition is configured with restricted access permissions that allow only enterprise applications to read/write screenshots, while the personal partition maintains open access for personal applications. This local quality differentiation enables screenshots to be captured and stored with enhanced security properties at their specific storage location without affecting overall system functionality.
2Reliability
If screenshots are completely disabled for enterprise applications, then data security is improved, but debugging capability is worsened
Solution Approach 1:
The patent introduces an intermediary secure folder within the workspace container that acts as a controlled interface between the screenshot capture function and enterprise applications. This intermediary structure allows screenshots to be captured and stored securely, then accessed by enterprise applications through controlled mechanisms such as shared folders or integration with enterprise communication tools. This enables debugging capabilities while maintaining security, as screenshots can be viewed and shared through approved enterprise channels without exposing them to unauthorized personal application access.
3Adaptability or versatility
If screenshots are stored outside the protected workspace container, then accessibility for sharing is improved, but security is worsened
Solution Approach 1:
The patent implements a nested structure where a secure screenshot folder is created within the protected workspace container partition. This nested arrangement allows screenshots to be stored in a secure environment while still enabling sharing capabilities through controlled access mechanisms. Enterprise applications can access screenshots through the nested folder structure, and screenshots can be shared via enterprise communication channels, all while remaining protected from personal application access. The nesting provides both security containment and controlled accessibility.
Data Source
AI summary
In response to determining that a graphical user interface displayed on the display device of a mobile device at the time a screenshot capture request is received is being generated at least in part by an enterprise application executing within a protected workspace container in the mobile device, a secure screenshot save operation is performed. The secure screenshot save operation includes i) storing, within the mobile device, a screenshot image of the graphical user interface displayed on the display device of the mobile device at the time the screenshot capture request is received, and ii) preventing the screenshot image from being accessed by any personal application executing on the mobile device outside of the protected workspace container.


