Mobile Device Management System for Secure VR Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual reality devices managed by third parties face security concerns due to direct communication with external networks, compromising security and resource management, especially when hard-wired connections are used.

Innovation Solution

A system that provides staging information including a digital certificate, PIN, and protocol for virtual reality devices to connect securely to an internal network, performs safety testing on software and content updates, and controls data transmission to prevent unauthorized access, allowing wireless management and secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual reality devices connect directly to external networks via hard-wired hub, then network connectivity and data transmission are enabled, but security risks and unauthorized access increase

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an internal network as an intermediary layer between virtual reality devices and external networks. Devices connect to the internal network first, which then selectively communicates with external networks through controlled gateways. This mediator architecture enables network connectivity while filtering out unauthorized access attempts, thus resolving the contradiction between enabling network access and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network architecture is segmented into multiple isolated zones: device-level networks, internal corporate networks, and external public networks. Firewalls and security protocols create virtual segmentation that allows controlled data flow between segments while preventing direct access. This segmentation enables devices to maintain network connectivity within their secure zone while blocking harmful external factors.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If third parties directly manage virtual reality devices, then device functionality and content delivery are improved, but device security and data protection deteriorate

Engineering Contradiction:
Improvedevice management capabilityVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system employs multiple intermediary layers including secure enclaves within devices, encrypted communication channels, and authenticated API gateways. These intermediaries enable third parties to manage devices and deliver content while preventing direct access to sensitive device resources. The mediator architecture maintains device security while preserving third-party management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different security policies and access controls are applied to different device components and data types. Critical security functions maintain local control within the device, while less sensitive functions allow third-party access. This localized quality approach enables selective management capability while protecting core security functions from external interference.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If wireless connectivity is implemented for virtual reality devices, then ease of deployment and mobility are improved, but security control and network stability worsen

Engineering Contradiction:
Improvedeployment convenienceVSAvoidconnection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Security credentials, authentication tokens, and encryption keys are pre-configured in devices during manufacturing or initial setup. Wireless connection parameters and security policies are established in advance before devices are deployed to users. This preliminary action enables easy wireless deployment while maintaining pre-established security controls that prevent connection to unauthorized networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback mechanisms including authentication verification, connection monitoring, and security anomaly detection for wireless connections. Devices continuously verify they are connected to authorized internal networks and report security status to management systems. This real-time feedback maintains connection security while allowing flexible wireless operation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11785018B2Mobile device management system for securely managing device communication
Publication Date: 2023.10.10 BANK OF AMERICA CORP
  • US11785018B2 patent drawing
  • US11785018B2 patent drawing
  • US11785018B2 patent drawing

AI summary

Systems, computer program products, and methods are described herein for securely managing device communication. The present invention may be configured to provide, to another system, staging information including a digital certificate, a PIN, and a protocol for storing on a device, receive from the device a request to connect to an internal network after user input of the PIN, receive a digital certificate from the device, establish a wireless connection between the device and the internal network, and cause the device to delete the PIN. In some embodiments, the system is configured to permit communication from the device to the other system for a predetermined time window. In some embodiments, the system receives updates from the other system, via an external network, and the system sends the updates to the device, via the internal network.