Android Application Security Management via Source-Based Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing application security technologies struggle to effectively classify and manage applications installed from untrusted sources on Android devices, leading to potential security vulnerabilities and risks of malicious code execution.

Innovation Solution

An electronic device is equipped with a security management module that classifies applications based on their source type during installation. If an application is from an untrusted source, the module performs predetermined security functions, such as notifying the user of potential risks and managing permissions to mitigate threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If applications from various sources are allowed to be installed through sideloading, then adaptability and user freedom are improved, but security reliability deteriorates due to potential malicious code execution

Engineering Contradiction:
Improveapplication installation flexibilityVSAvoidsecurity reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments applications into different categories based on their source: trusted applications (from official stores) and untrusted applications (from other sources). This segmentation allows the system to apply different security policies to different application groups, maintaining flexibility for trusted apps while enforcing stricter controls on untrusted apps to ensure security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security measures locally to different application sources. Trusted applications receive standard installation permissions, while untrusted applications are subjected to additional security functions such as source type recording, risk notification, and permission management restrictions. This local quality approach resolves the contradiction by tailoring security intensity to the specific risk level of each application source.

Inventive Principle:
Principle #3Local quality

2Reliability

If security functions are performed for untrusted applications, then security reliability is improved, but device complexity increases due to additional classification and management mechanisms

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions during the application installation process by recording the source type of untrusted applications before they are fully installed and executed. This preliminary classification allows the system to establish security controls in advance, reducing the need for complex ongoing monitoring and management mechanisms, thereby improving security reliability without proportionally increasing device complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service security management by automatically classifying applications based on their installation source and applying appropriate security functions without requiring manual user configuration. The system autonomously manages untrusted applications through automatic source type recording, risk notification, and permission control, reducing the complexity burden on users while maintaining high security reliability.

Inventive Principle:
Principle #25Self-service

3Reliability

If source type recording and security functions are implemented, then security reliability is improved, but ease of operation deteriorates due to additional user notifications and permission management

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms that notify users of potential security risks associated with untrusted applications. The system provides clear information about the application source and associated risks, allowing users to make informed decisions. This feedback approach balances security reliability with ease of operation by enabling users to understand and manage risks without overly complicating the installation process.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies security functions selectively rather than universally. Full security measures such as source type recording, risk notifications, and permission management are applied only to untrusted applications, while trusted applications from official stores receive standard treatment. This partial action approach maintains security reliability for high-risk applications without unnecessarily complicating the operation of trusted applications.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12277217B2Method for application security and electronic device for performing the same
Publication Date: 2025.04.15 SAMSUNG ELECTRONICS CO LTD
  • US12277217B2 patent drawing
  • US12277217B2 patent drawing
  • US12277217B2 patent drawing

AI summary

A method for application security and an electronic device for performing the method are provided. The electronic device includes a memory configured to store computer-executable instructions and at least one processor configured to execute the instructions by accessing the memory, wherein the at least one processor is configured to, in response to the instructions being executed by the at least one processor, record a source type of an application based on the source type of the application when installing the application on the electronic device, determine whether the application corresponds to an untrusted application based on the source type of the application, and in response to the application corresponding to an untrusted application, perform one or more of security functions set for the untrusted application.