Secure Virtualized Mobile Enterprise Access via Edge Node Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Providing secure and flexible mobile communication solutions for enterprises while addressing security concerns and reducing costs, as existing approaches often result in users carrying two phones and incurring high expenditures on locked-down devices.
Innovation Solution
A system utilizing a mobile cloud with a display protocol, a scrambler and descrambler pair for encryption, and a snap-on auxiliary data display and touch screen to enable secure access to virtualized mobile phone images, allowing employees to use their personal smartphones for both personal and business purposes while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If employees are provided with standardized smartphones with enterprise software installed, then security concerns are addressed, but device functionality is limited and users cannot use phones for personal purposes
Solution Approach 1:
The system segments the mobile device into two distinct virtual environments: a secure enterprise workspace and a personal workspace. Each environment operates independently with its own applications, data, and settings. The enterprise workspace is accessed through a virtualized desktop environment that can be securely configured with restricted permissions, while the personal workspace maintains full device functionality. This segmentation resolves the contradiction by allowing both security restrictions and personal usage within the same physical device.
Solution Approach 2:
The enterprise workspace is nested within the personal smartphone device as a virtualized environment. The secure enterprise desktop runs as a containerized application within the existing mobile operating system, creating a nested structure where the enterprise environment is embedded inside the personal device. This nesting allows the enterprise security policies to be enforced within the inner layer while the outer personal environment maintains full functionality.
2Reliability
If a separate locked phone is given to each employee for business use, then security is maintained, but users incur costs and frustration from carrying two phones
Solution Approach 1:
The system merges the enterprise workspace and personal workspace into a single unified mobile device. The virtualized enterprise desktop environment is combined with the personal mobile operating system, allowing both work and personal functions to coexist in one device. Users can switch between work and personal modes seamlessly, eliminating the need to carry or manage separate devices while maintaining security boundaries.
Solution Approach 2:
The mobile device is transformed into a universal platform that serves both enterprise and personal functions simultaneously. The same physical device can function as a secure corporate phone during work hours and as a personal smartphone for non-work activities. The virtualized enterprise environment provides multi-functionality for business purposes while the underlying mobile OS provides multi-functionality for personal use, all within one device.
3Reliability
If enterprises provide standardized locked-down smartphones to employees, then security is ensured, but capital expenditures and operating expenditures increase
Solution Approach 1:
Instead of provisioning separate physical devices for enterprise use, the system creates a virtual copy of an enterprise desktop environment that runs within the employee's personal smartphone. This virtual copy provides the necessary enterprise applications, data, and security policies without requiring additional hardware. The enterprise pays only for the software licensing and management infrastructure rather than purchasing and maintaining separate physical devices for each employee.
Data Source
AI summary
Secure virtualizing of a mobile cellular device uses a cellular communication network having base transceiver station edge node servers. A virtualized-instance host server contains a virtualized instance of an enterprise environment. Base station controllers are in communication with and control the base transceiver stations. A mobile switching center in communication with the base station controllers contains the virtualized-instance host server. A cellular communication device is in communication with an edge node server, and an auxiliary data display entry device is in communication with the cellular communication device such that the virtualized instance of the enterprise environment is on the edge node server. Communications between the auxiliary display and data entry device are encrypted. In addition, movement of the cellular communication device within the cellular communication network are anticipated so that additional remote virtualized instances of the enterprise environment are provided on candidate future edge servers.


