Virtual Phone Image Provisioning for Secure Mobile Workspaces
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in provisioning a secure work environment on personal mobile devices while maintaining data partitioning between personal and business use, as employees increasingly bring their own devices into the workplace, requiring a balance between access and security.
Innovation Solution
The implementation of virtualization technology allows personal and business uses to coexist on a single device, with the user's work environment being platform-independent and securely managed by IT departments, using a hypervisor and management service to create a virtual phone image and enforce security policies, ensuring isolation and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If enterprises provide business mobile devices to employees, then productivity and mobile access are improved, but hardware costs and device management complexity increase
Solution Approach 1:
The patent implements a universal virtualization platform that can run on multiple types of personal mobile devices (iOS, Android, Windows Phone). The virtual phone image creates a standardized business environment that works across different device types, eliminating the need for enterprise-provided hardware while maintaining consistent functionality and management policies across all devices.
Solution Approach 2:
The patent creates a virtual copy of a business mobile device environment that runs on top of the personal device's existing operating system. This virtual phone image replicates the functionality of a physical business device without requiring actual hardware provisioning, thereby reducing costs while maintaining productivity.
2Quantity of substance
If employees use personal devices for work, then device cost is reduced, but security control and data partitioning become more difficult
Solution Approach 1:
The patent segments the personal device into two distinct environments: the host personal environment and the guest virtual business environment. The hypervisor creates strict isolation between these environments, ensuring that business data and applications remain secure and separate from personal data, while still allowing the employee to use their personal device for work.
Solution Approach 2:
The patent introduces a hypervisor as an intermediary layer between the personal device's operating system and the business applications. This intermediary enforces security policies, controls data flow, and manages the virtual business environment, providing enterprise-grade security control without requiring physical device provisioning.
3Adaptability or versatility
If enterprises support multiple personal device types, then employee choice and satisfaction are improved, but IT support complexity and costs increase
Solution Approach 1:
The patent develops a universal virtual phone image that can execute on multiple mobile operating systems including iOS, Android, and Windows Phone. This single virtualized business environment provides consistent functionality and management across all device types, eliminating the need for separate IT support configurations for each device platform.
Data Source
AI summary
In some aspects, a mobile application package is bound to a privileged component of a mobile device operating system. The mobile application package includes a software virtualization layer and a management service component. The software virtualization layer and the management service component are enabled to execute in a privileged mode based on the privileged component. A virtual phone image is downloaded from a management server. A virtual machine based on the virtual phone image is launched by the software virtualization layer.


