Virtual Mobile Infrastructure Containerization for Secure BYOD Data Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing popularity of BYOD policies in enterprises, while enhancing mobility and convenience, poses risks of confidential data leakage due to the portability of personal mobile devices, which existing MDM solutions fail to adequately address without compromising user convenience.
Innovation Solution
A method and system utilizing Virtual Mobile Infrastructure (VMI) architecture, where a mobile operating system and applications are deployed and controlled remotely through a client application, administration console, and data center, allowing for secure execution on a platform cluster, enabling secure and flexible switching between applications while maintaining data isolation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MDM (Mobile Device Management) is used for overall-device protection and real-time monitoring, then security is improved, but user convenience deteriorates
Solution Approach 1:
The patent segments the device into two distinct environments: a work container for enterprise applications and data, and a personal container for user applications and data. This segmentation allows MDM policies to be applied selectively only to the work container, protecting enterprise resources while leaving the personal container untouched, thus maintaining user convenience in their personal space while ensuring security for enterprise operations.
Solution Approach 2:
The patent introduces a containerization mechanism as an intermediary layer between the device hardware and the applications. This container acts as a mediator that enforces security policies, isolates enterprise data from potential threats in the personal environment, and manages application execution. The container framework provides the necessary security controls without requiring direct intervention in the user's personal device operations.
2Reliability
If VMI (Virtual Mobile Infrastructure) is used to separate the operating system and application from a client device, then security is improved, but device complexity increases
Solution Approach 1:
The patent creates a virtual copy of the mobile operating system environment within the container on the client device. Instead of requiring a separate physical device or complex virtualization infrastructure, the system copies and emulates the necessary OS components and application runtime environment locally. This virtual environment provides the security isolation of VMI while running on standard mobile device hardware, avoiding the need for complex external virtualization infrastructure.
3Reliability
If remote mobile virtualization is implemented to execute applications on a platform, then data isolation is improved, but service performance deteriorates
Solution Approach 1:
The patent implements a dynamic container activation mechanism where containers are created, activated, and deactivated based on real-time application requirements. When an enterprise application needs to run, its dedicated container is activated with appropriate resources allocated. When not in use, the container is deactivated or shared with other applications. This dynamic resource management ensures data isolation when needed while optimizing resource utilization and performance by avoiding continuous allocation of resources to idle containers.
Data Source
AI summary
A method for deploying and controlling a mobile operating system on a platform comprises sending a first deployment message to the platform by an administration console; establishing a first communicable connection to the platform by a mobile communication device; getting at least an image file of a mobile operating system and an image file of a first mobile application from a data center, activating the mobile operating system by the platform and executing the first mobile application; executing a remounting procedure by the administration console according to another instruction sent from the mobile communication device; wherein the remounting procedure is configured to disconnect the first communicable connection and establish a second communicable connection between the mobile communication device and the platform or another platform that the mobile operating system and a second mobile application can be executed on the platform or on said another platform.


