Android App Policy Manager for Set Top Box Threat Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices running Android operating systems face challenges in monitoring and controlling applications, as the system kernel is locked, making it difficult for developers or operators to detect and manage malicious or unauthorized applications, and existing solutions violate Google policies by blocking apps that operators want to restrict.

Innovation Solution

A method and system that allow operators to monitor and control applications on Android devices by measuring resource usage against set thresholds, providing notifications, and taking actions such as restricting access or uninstalling apps, without blacklisting downloads, using a policy manager and server infrastructure to manage acceptable app behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional virus detection techniques are used, then virus detection capability is provided, but the system kernel lock prevents monitoring and control of application operations

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidapplication operation monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary layer between the locked kernel and application layer by implementing a policy manager that runs in user space but has privileged access to monitor application behavior. This mediator can detect violations without requiring kernel-level access, resolving the contradiction between kernel security and monitoring capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical virus detection methods with a software-based policy enforcement mechanism. Instead of relying on kernel-level virus scanners, the system uses a policy manager that monitors application operations through Android's existing API framework, substituting the detection mechanism while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If operators block unauthorized apps, then application security is improved, but Google policies are violated by blocking legitimate Play Store apps

Engineering Contradiction:
Improveapplication securityVSAvoidapp access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy enforcement where the policy manager can adjust access rights in real-time based on application behavior. Legitimate apps that exceed resource thresholds or exhibit suspicious patterns are temporarily restricted, while the system maintains the ability to access Play Store apps. This dynamic approach resolves the contradiction between security and flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors application behavior and provides feedback to the policy manager, which then adjusts access policies accordingly. This feedback loop allows the system to distinguish between legitimate apps that temporarily exceed thresholds and actually malicious applications, resolving the contradiction between blocking unauthorized apps and maintaining Google policy compliance.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If resource usage monitoring is implemented, then unauthorized data exposure and piracy are prevented, but system complexity increases

Engineering Contradiction:
Improveunauthorized data exposure and piracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent makes the policy manager a multi-functional component that handles various tasks including resource usage monitoring, virus detection, piracy prevention, and policy enforcement. By consolidating these functions into a single manager that leverages existing Android APIs, the system prevents harmful activities without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The policy manager automatically monitors application behavior and enforces policies without requiring manual intervention. The system self-adjusts based on predefined thresholds and patterns, reducing the operational complexity burden on administrators while maintaining effective protection against unauthorized data exposure and piracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230222185A1Threat control and prevention for android systems
Publication Date: 2023.07.13 THOMSON LICENSING SA
  • US20230222185A1 patent drawing
  • US20230222185A1 patent drawing
  • US20230222185A1 patent drawing

AI summary

A method is provided that determines whether to allow an application (app) for use or restrict the app on a set top box (STB). The method includes the steps of measuring at the STB, one or more resources used by the app; comparing at the STB, one or more thresholds set by an operator; and determining if the one or more resources used by the app exceed one or more thresholds set by the operator. Another method is provided that monitors applications (apps) that are installed a set top box (STB) for illegal or harmful activity by a policy manager. This method includes downloading and copying an app from an external source; installing or uninstalling the app into an application folder; providing a notification informing the policy manager of the installing or uninstalling of the app; and evaluating the app be installed or uninstalled.