UI Proxy Application for Secure Mobile Environment Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in providing seamless user interface switching between personal and business environments on mobile devices while maintaining security and data partitioning, as employees increasingly bring personal devices into the workplace, necessitating a 'Bring Your Own Device' (BYOD) strategy.
Innovation Solution
A method is implemented to configure mobile devices to switch between personal and business environments using a UI proxy application, which initiates a request to wake up a virtual machine-based guest environment, allowing access to display data and maintaining security through a hypervisor and hardware emulation layer, ensuring seamless transitions and data separation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a BYOD strategy is implemented to allow employees to use personal devices for work purposes, then IT costs are reduced and productivity is improved, but security risks increase and data partitioning becomes more difficult
Solution Approach 1:
The patent segments the mobile device into distinct personal and business environments using virtualization technology. A hypervisor creates isolated virtual machines for each environment, ensuring that personal applications and business applications run in separate secure containers. This segmentation allows employees to use personal devices for work purposes while maintaining strict security boundaries between personal and corporate data.
Solution Approach 2:
The patent introduces a UI proxy application as an intermediary layer between the user and the dual-environment system. This proxy manages the complexity of environment switching, application launching, and data access transparently. The intermediary handles security policies, application permissions, and environment transitions, allowing employees to seamlessly access work resources on personal devices without directly managing the underlying security infrastructure.
2Reliability
If separate personal and business mobile devices are provided to employees, then security and data partitioning are maintained, but IT costs increase and device management becomes more complex
Solution Approach 1:
The patent merges the functionality of separate personal and business mobile devices into a single unified device. By using virtualization to create isolated environments within one physical device, the system maintains the security benefits of separate devices while eliminating the need for employees to manage multiple devices. The hypervisor and UI proxy work together to provide a unified user experience with automatic environment switching.
Solution Approach 2:
The patent makes the mobile device universal by enabling it to function as both a personal device and a business device simultaneously. The virtualized environment allows the same physical device to run personal applications and business applications with appropriate security controls. This multi-functionality eliminates the need for separate devices while maintaining security boundaries through the hypervisor-based isolation architecture.
3Reliability
If virtualization technology is used to create separate business environment on personal device, then data partitioning and security are maintained, but device performance overhead increases
Solution Approach 1:
The patent implements partial virtualization where only the necessary business environment components are virtualized rather than the entire device. The hypervisor creates a lightweight virtual machine that hosts only the required business applications and data, while the personal environment runs natively. This partial approach reduces the performance overhead compared to full virtualization while still maintaining adequate security and data partitioning for business purposes.
Data Source
AI summary
One or more embodiments of the invention facilitate switching between a host environment of a mobile device and a guest environment of the mobile device. One method comprises configuring the host environment to launch a user interface (UI) proxy application upon receiving an indication by a user on a user interface (UI) of the mobile device of a desire to switch from the host environment to the guest environment. Upon a launch of the UI proxy application as a result of receiving the indication, the UI proxy application initiates a request to wake-up the guest environment and facilitates access by a hardware framebuffer of the mobile device to contents of a memory buffer that is updated with display data for the guest environment as a result of a waking-up of the guest environment.


