Application Virtualization Layer for Secure Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The consumerization of IT poses challenges in protecting sensitive data as traditional enterprise IT infrastructures are no longer feasible, as employees use personal devices for both work and personal tasks, increasing the risk of unauthorized access to financial and confidential data.
Innovation Solution
Implementing systems and methods that utilize virtualization layers to control access to data by determining if the computing device meets specific access-control policies, such as location, security applications, and network connections, to ensure safe and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional enterprise IT infrastructures strictly control devices to access sensitive data, then data security is improved, but device flexibility and employee autonomy deteriorate
Solution Approach 1:
The patent introduces a virtualization layer as an intermediary between the computing device and sensitive data. This layer acts as a mediator that can dynamically control access based on security policies while allowing multiple device types to connect. The virtualization layer includes components such as a virtual file system, virtual registry, and application virtualization that enable secure data access without requiring strict control over the underlying hardware device
Solution Approach 2:
The patent segments the system into distinct layers: the computing device layer, the virtualization layer, and the data layer. By dividing the access control mechanism into separate virtualization components (virtual file system, virtual registry, application virtualization), the system can enforce security policies at the virtualization layer while maintaining device flexibility at the user layer
2Ease of operation
If personal devices are allowed for work tasks, then employee autonomy and work-life integration are improved, but unauthorized access risk to sensitive data increases
Solution Approach 1:
The patent implements dynamic access control through the virtualization layer, which can adapt security policies in real-time based on the computing device's state. The system dynamically evaluates security conditions (such as whether prohibited applications are running, security software status, network connection state) and adjusts data access permissions accordingly, allowing personal devices to be used while maintaining security through runtime policy enforcement
Solution Approach 2:
The system continuously monitors the state of the computing device and provides feedback to the virtualization layer to adjust access control decisions. The virtualization layer receives information about the device's security state (prohibited applications, security software, network connection) and uses this feedback to dynamically enable or disable data access, creating a closed-loop security system that responds to changing conditions
3Reliability
If access control policies are enforced through device restrictions, then data protection is improved, but system complexity increases
Solution Approach 1:
The virtualization layer serves as an intermediary that centralizes access control logic, simplifying the overall system architecture. Instead of implementing complex control mechanisms at multiple levels (device driver, operating system, application), the patent consolidates security enforcement in the virtualization layer, which manages the complexity of policy evaluation and access control in a unified manner
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A computer-implemented method for controlling access to data is. A request to access data is received. A determination is made that an access-control policy of the data is satisfied. A virtualization layer is activated to allow access to the data after determining that the access-control policy is satisfied. Various other methods, systems, and computer-readable media are also disclosed.