Access Control List for Mobile Remote Support Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
During remote control sessions for mobile device troubleshooting, there is a concern about potential access to private user data by remote technicians, leading to privacy issues and legal risks for carriers and tech support organizations.
Innovation Solution
Implementing a Virtual Mobile Management (VMM) system that allows users to control access to their applications and data, with features like Access Control Lists (ACLs) and user consent mechanisms to restrict access, ensuring that only authorized applications can be viewed by remote technicians.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If remote technicians are granted full access to mobile devices for troubleshooting, then device diagnostic capability is improved, but user privacy protection deteriorates
Solution Approach 1:
The patent segments the mobile device's applications and data into distinct categories, creating an access control list that divides access permissions into granular units. Each application can be individually evaluated and permitted or restricted, allowing technicians to access only specific diagnostic applications while excluding private user data, thus resolving the contradiction between diagnostic capability and privacy protection.
Solution Approach 2:
The patent implements local quality by applying different access permissions to different applications and data types on the same device. Rather than uniform access control, the system assigns specific quality attributes (access permissions) to each application based on its diagnostic value and privacy sensitivity, enabling technicians to access diagnostic-critical applications while restricting access to private applications.
2Object-affected harmful factors
If access control restrictions are implemented during remote sessions, then user privacy protection is improved, but troubleshooting efficiency deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-establishing an access control list that identifies and categorizes applications before the remote troubleshooting session begins. The system proactively evaluates each application's diagnostic value and privacy sensitivity in advance, creating a permission framework that enables efficient troubleshooting while protecting privacy from the outset, rather than imposing restrictions that would slow down the process.
Solution Approach 2:
The patent introduces an intermediary mechanism (the access control list and permission management system) that mediates between the technician's diagnostic needs and the user's privacy protection requirements. This intermediary evaluates application characteristics, determines appropriate access levels, and enforces permissions dynamically, allowing efficient troubleshooting within privacy-boundaries without direct conflict between the two objectives.
3Adaptability or versatility
If dynamic access control lists are implemented to support new applications, then system adaptability is improved, but device complexity deteriorates
Solution Approach 1:
The patent implements dynamics by creating a dynamic access control list that automatically adapts to new applications installed on the device. The system continuously monitors application installations, evaluates their diagnostic value and privacy characteristics, and updates permissions in real-time. This dynamic approach enables the system to support new applications flexibly while managing complexity through automated evaluation criteria and structured permission frameworks.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A method of implementing access restrictions on mobile devices during a remote control session Network based restrictions; User controlled restrictions, or User controlled access list restrictions. A remote support technician connects to a mobile device to perform remote access to the mobile device. As part of the remote control session a policy can be pushed to the device that would have a list of applications that would need to be allowed by the user to be shared with remote technician. Alternatively no policy is pushed and the user must allow remote support technician access.