Access Control List for Mobile Remote Support Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

During remote control sessions for mobile device troubleshooting, there is a concern about potential access to private user data by remote technicians, leading to privacy issues and legal risks for carriers and tech support organizations.

Innovation Solution

Implementing a Virtual Mobile Management (VMM) system that allows users to control access to their applications and data, with features like Access Control Lists (ACLs) and user consent mechanisms to restrict access, ensuring that only authorized applications can be viewed by remote technicians.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If remote technicians are granted full access to mobile devices for troubleshooting, then device diagnostic capability is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improvedevice diagnostic capabilityVSAvoiduser privacy exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the mobile device's applications and data into distinct categories, creating an access control list that divides access permissions into granular units. Each application can be individually evaluated and permitted or restricted, allowing technicians to access only specific diagnostic applications while excluding private user data, thus resolving the contradiction between diagnostic capability and privacy protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different access permissions to different applications and data types on the same device. Rather than uniform access control, the system assigns specific quality attributes (access permissions) to each application based on its diagnostic value and privacy sensitivity, enabling technicians to access diagnostic-critical applications while restricting access to private applications.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If access control restrictions are implemented during remote sessions, then user privacy protection is improved, but troubleshooting efficiency deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoidtroubleshooting efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-establishing an access control list that identifies and categorizes applications before the remote troubleshooting session begins. The system proactively evaluates each application's diagnostic value and privacy sensitivity in advance, creating a permission framework that enables efficient troubleshooting while protecting privacy from the outset, rather than imposing restrictions that would slow down the process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (the access control list and permission management system) that mediates between the technician's diagnostic needs and the user's privacy protection requirements. This intermediary evaluates application characteristics, determines appropriate access levels, and enforces permissions dynamically, allowing efficient troubleshooting within privacy-boundaries without direct conflict between the two objectives.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If dynamic access control lists are implemented to support new applications, then system adaptability is improved, but device complexity deteriorates

Engineering Contradiction:
Improveapplication support flexibilityVSAvoidaccess control management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by creating a dynamic access control list that automatically adapts to new applications installed on the device. The system continuously monitors application installations, evaluates their diagnostic value and privacy characteristics, and updates permissions in real-time. This dynamic approach enables the system to support new applications flexibly while managing complexity through automated evaluation criteria and structured permission frameworks.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2832125B1Access control list for applications on mobile devices during a remote control session
Publication Date: 2021.11.03 VMWARE INC
  • EP2832125B1 patent drawingFigure 1
  • EP2832125B1 patent drawingFigure 2
  • EP2832125B1 patent drawingFigure 3~4

AI summary

A method of implementing access restrictions on mobile devices during a remote control session Network based restrictions; User controlled restrictions, or User controlled access list restrictions. A remote support technician connects to a mobile device to perform remote access to the mobile device. As part of the remote control session a policy can be pushed to the device that would have a list of applications that would need to be allowed by the user to be shared with remote technician. Alternatively no policy is pushed and the user must allow remote support technician access.