Secure Virtualized Mobile Enterprise Access via Edge Node Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Providing secure and flexible mobile communication solutions for enterprises while addressing security concerns and reducing costs, as existing approaches often result in users carrying two phones and incurring high expenditures on locked-down devices.

Innovation Solution

A system utilizing a mobile cloud with a display protocol, a scrambler and descrambler pair for encryption, and a snap-on auxiliary data display and touch screen to enable secure access to virtualized mobile phone images, allowing employees to use their personal smartphones for both personal and business purposes while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If employees are provided with standardized smartphones with enterprise software installed, then security concerns are addressed, but device functionality is limited and users cannot use phones for personal purposes

Engineering Contradiction:
ImprovesecurityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the mobile device into two distinct virtual environments: a secure enterprise workspace and a personal workspace. Each environment operates independently with its own applications, data, and settings. The enterprise workspace is accessed through a virtualized desktop environment that can be securely configured with restricted permissions, while the personal workspace maintains full device functionality. This segmentation resolves the contradiction by allowing both security restrictions and personal usage within the same physical device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The enterprise workspace is nested within the personal smartphone device as a virtualized environment. The secure enterprise desktop runs as a containerized application within the existing mobile operating system, creating a nested structure where the enterprise environment is embedded inside the personal device. This nesting allows the enterprise security policies to be enforced within the inner layer while the outer personal environment maintains full functionality.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If a separate locked phone is given to each employee for business use, then security is maintained, but users incur costs and frustration from carrying two phones

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges the enterprise workspace and personal workspace into a single unified mobile device. The virtualized enterprise desktop environment is combined with the personal mobile operating system, allowing both work and personal functions to coexist in one device. Users can switch between work and personal modes seamlessly, eliminating the need to carry or manage separate devices while maintaining security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device is transformed into a universal platform that serves both enterprise and personal functions simultaneously. The same physical device can function as a secure corporate phone during work hours and as a personal smartphone for non-work activities. The virtualized enterprise environment provides multi-functionality for business purposes while the underlying mobile OS provides multi-functionality for personal use, all within one device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If enterprises provide standardized locked-down smartphones to employees, then security is ensured, but capital expenditures and operating expenditures increase

Engineering Contradiction:
ImprovesecurityVSAvoidenterprise expenditures
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of provisioning separate physical devices for enterprise use, the system creates a virtual copy of an enterprise desktop environment that runs within the employee's personal smartphone. This virtual copy provides the necessary enterprise applications, data, and security policies without requiring additional hardware. The enterprise pays only for the software licensing and management infrastructure rather than purchasing and maintaining separate physical devices for each employee.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10009322B2Secure virtualized mobile cellular device
Publication Date: 2018.06.26 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10009322B2 patent drawing
  • US10009322B2 patent drawing
  • US10009322B2 patent drawing

AI summary

Secure virtualizing of a mobile cellular device uses a cellular communication network having base transceiver station edge node servers. A virtualized-instance host server contains a virtualized instance of an enterprise environment. Base station controllers are in communication with and control the base transceiver stations. A mobile switching center in communication with the base station controllers contains the virtualized-instance host server. A cellular communication device is in communication with an edge node server, and an auxiliary data display entry device is in communication with the cellular communication device such that the virtualized instance of the enterprise environment is on the edge node server. Communications between the auxiliary display and data entry device are encrypted. In addition, movement of the cellular communication device within the cellular communication network are anticipated so that additional remote virtualized instances of the enterprise environment are provided on candidate future edge servers.