Virtual Phone Image Provisioning for Secure Mobile Workspaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in provisioning a secure work environment on personal mobile devices while maintaining data partitioning between personal and business use, as employees increasingly bring their own devices into the workplace, requiring a balance between access and security.

Innovation Solution

The implementation of virtualization technology allows personal and business uses to coexist on a single device, with the user's work environment being platform-independent and securely managed by IT departments, using a hypervisor and management service to create a virtual phone image and enforce security policies, ensuring isolation and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises provide business mobile devices to employees, then productivity and mobile access are improved, but hardware costs and device management complexity increase

Engineering Contradiction:
Improveworkforce productivityVSAvoiddevice provisioning complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal virtualization platform that can run on multiple types of personal mobile devices (iOS, Android, Windows Phone). The virtual phone image creates a standardized business environment that works across different device types, eliminating the need for enterprise-provided hardware while maintaining consistent functionality and management policies across all devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates a virtual copy of a business mobile device environment that runs on top of the personal device's existing operating system. This virtual phone image replicates the functionality of a physical business device without requiring actual hardware provisioning, thereby reducing costs while maintaining productivity.

Inventive Principle:
Principle #26Copying

2Quantity of substance

If employees use personal devices for work, then device cost is reduced, but security control and data partitioning become more difficult

Engineering Contradiction:
Improvehardware costVSAvoidsecurity control
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the personal device into two distinct environments: the host personal environment and the guest virtual business environment. The hypervisor creates strict isolation between these environments, ensuring that business data and applications remain secure and separate from personal data, while still allowing the employee to use their personal device for work.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hypervisor as an intermediary layer between the personal device's operating system and the business applications. This intermediary enforces security policies, controls data flow, and manages the virtual business environment, providing enterprise-grade security control without requiring physical device provisioning.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If enterprises support multiple personal device types, then employee choice and satisfaction are improved, but IT support complexity and costs increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidIT support complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent develops a universal virtual phone image that can execute on multiple mobile operating systems including iOS, Android, and Windows Phone. This single virtualized business environment provides consistent functionality and management across all device types, eliminating the need for separate IT support configurations for each device platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10708656B2Provisioning work environments using virtual phone images
Publication Date: 2020.07.07 VMWARE INC
  • US10708656B2 patent drawing
  • US10708656B2 patent drawing
  • US10708656B2 patent drawing

AI summary

In some aspects, a mobile application package is bound to a privileged component of a mobile device operating system. The mobile application package includes a software virtualization layer and a management service component. The software virtualization layer and the management service component are enabled to execute in a privileged mode based on the privileged component. A virtual phone image is downloaded from a management server. A virtual machine based on the virtual phone image is launched by the software virtualization layer.