Smart Container Security for Mobile Device Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in securing, managing, and controlling access to corporate resources on mobile devices, particularly due to the 'bring your own device' (BYOD) philosophy, where personal and corporate data are at risk from security breaches, malware, and loss or theft of devices, existing solutions failing to unify security and access management across diverse resources.

Innovation Solution

Implementing smart containers around mobile device resources, which apply enhanced security access policies based on real-time monitoring of metrics, allowing for intelligent, automated adjustments to access controls, such as encryption and multi-factor authentication, to protect resources without requiring modifications to the operating system or third-party applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are applied to mobile device resources, then security protection is provided, but device complexity and ease of operation deteriorate due to system modifications and application restrictions

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A smart container is introduced as an intermediary layer between the resource and the access requestor. The smart container includes a container interface that receives access requests and a policy engine that evaluates policies and makes access decisions, thereby mediating security control without modifying the underlying resource or requiring system-wide changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security management system is segmented into independent components: the smart container, container interface, policy engine, and metrics collector. Each component performs a specific function and can be independently deployed and managed, reducing overall system complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If existing security solutions are implemented, then access control is provided, but adaptability deteriorates due to inability to respond to changing security conditions

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity policy adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security access policy is made dynamic through continuous monitoring of metrics by the metrics collector and real-time evaluation by the policy engine. The policy engine can adjust access decisions based on changing security conditions, user behavior patterns, and threat levels, enabling the system to adapt to evolving security requirements without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback loop where the metrics collector continuously gathers security-relevant data, the policy engine evaluates current policies against this data, and access decisions are adjusted accordingly. This closed-loop feedback mechanism enables automatic adaptation to changing security conditions while maintaining consistent access control.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual security management is used, then policy control is maintained, but productivity deteriorates due to time-consuming security decisions

Engineering Contradiction:
Improvepolicy controlVSAvoidsecurity decision speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The smart container autonomously manages security decisions by automatically collecting metrics, evaluating policies, and making access control determinations without requiring manual administrator intervention. The system self-adjusts security policies based on monitored conditions, freeing administrators from routine security management tasks while maintaining precise policy control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security policies are pre-configured and stored in the policy engine before access requests occur. The policy engine has these policies ready for immediate evaluation, eliminating delays associated with real-time policy creation or modification. The system performs preliminary security setup and maintains ready-to-evaluate policies, enabling rapid automated decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9268935B2Smart containerization of mobile computing device resources
Publication Date: 2016.02.23 CA TECH INC
  • US9268935B2 patent drawing
  • US9268935B2 patent drawing
  • US9268935B2 patent drawing

AI summary

A method includes monitoring metrics at a mobile computing device. A substantive change in operating conditions is identified, based upon the monitored metrics. In response to the substantive change in the operating conditions, a smart container is automatically applied to a particular resource of the computing device. The smart container may define an enhanced security access policy. In accordance with a particular embodiment of the disclosure, the enhanced security access policy increases the level of protection to the resource.