Selective Policy Enforcement for Mobile Enterprise Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in securing enterprise data on personal devices used for both work and personal purposes, as existing solutions often result in the loss or theft of personal data when enterprise policies are enforced, leading to unintended data deletion.
Innovation Solution
A system that allows for the selective application and sharing of remote policies on personal devices, enabling enterprise applications to connect to an enterprise server, receive policies, and apply them selectively, ensuring that only enterprise data is erased in case of security breaches or policy violations, while preserving personal data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprise policies are enforced on personal devices, then enterprise data security is improved, but personal data may be lost or deleted
Solution Approach 1:
The system segments the device data into enterprise data and personal data, applying policies selectively to enterprise data only. The policy enforcement mechanism distinguishes between data types and applies erasure or protection actions only to enterprise-associated data, preventing collateral damage to personal data.
Solution Approach 2:
Different quality attributes are applied to different data portions: enterprise data receives strict security policies including remote erasure capability, while personal data is excluded from policy enforcement. This localized approach ensures security measures are applied only where necessary.
2Reliability
If remote policy enforcement is implemented, then enterprise data protection is improved, but device functionality and user convenience may be reduced
Solution Approach 1:
An enterprise application acts as an intermediary between the policy enforcement mechanism and the device data. This intermediary selectively applies policies only to enterprise data portions, transparently managing security enforcement without requiring user intervention or affecting personal data operations.
Solution Approach 2:
The system automatically identifies and applies policies to enterprise data without requiring user action. The policy enforcement occurs autonomously through the enterprise application, which manages the distinction between enterprise and personal data and applies appropriate security measures without user involvement.
3Productivity
If personal devices are used for work purposes, then employee efficiency and convenience are improved, but security risks and data loss challenges increase
Solution Approach 1:
The system segments data and policy application to allow personal device usage while protecting enterprise data. By dividing the data space into enterprise and personal portions and applying security policies only to enterprise data, employees can use personal devices freely without compromising enterprise security.
Solution Approach 2:
The system establishes preliminary protective measures by implementing policy enforcement mechanisms before security breaches can occur. Remote wipe capabilities and selective policy application are pre-configured to automatically protect enterprise data if the device is lost or stolen, counteracting potential security threats in advance.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques to apply and share remote policies on personal devices are described. In an embodiment, a technique includes contacting an enterprise server from an enterprise application operating on a personal device. The enterprise application may receive policies from the enterprise server. The policies may be applied to the enterprise application. When a second enterprise application on the personal device is launched, the policies may also be applied to the second enterprise application. When a policy is changed on the enterprise server, notification is pushed to the personal device and all related enterprise applications on the personal device may be updated to enforce the policy change. Other embodiments are described and claimed.