Application Identifier Table for Mobile Resource Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure code execution environments in cellular telephony, such as those using virtual machines, fail to effectively manage access to mobile phone resources by unspecific programs and require extensive memory for security policy updates, limiting independent rights management for specific applications.
Innovation Solution
Associating a unique identifier with each application, managing resource access through an operating system that scans an application identifier table to determine access rights, with a dynamic table for each application and owner authorization, enabling centralized and flexible management of resource access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If domain-based security policies are implemented where each application belongs to a domain, then access rights to functionalities can be precisely defined, but memory capacity is occupied excessively and rights cannot be updated for specific applications independently
Solution Approach 1:
The patent segments the security policy management by creating separate authorization lists for each application instead of grouping applications into domains. Each application gets its own identifier and independent authorization list, allowing granular control over access rights without the overhead of domain-based grouping. This segmentation enables independent updates of rights for specific applications while reducing memory usage compared to managing all applications within domain structures.
2Reliability
If a virtual machine layer is implemented to execute specific programs, then secured code execution is achieved, but the security policy is confined to the mobile telephone and no interaction with external security elements is planned
Solution Approach 1:
The patent implements a universal security policy management system that operates at the operating system level rather than being confined to a specific virtual machine layer. The authorization lists and identifier-based security model can work with any application type and can interact with various security elements including SIM cards, making the security system adaptable and versatile across different execution environments and external security components.
3Reliability
If all applications must belong to a domain with redefined rights for all functionalities, then comprehensive access control is achieved, but it is impossible to update rights for a specific application independently from other applications
Solution Approach 1:
The patent divides the security management structure into application-specific authorization lists rather than domain-based groupings. Each application identifier has its own dedicated authorization list that can be independently modified. This segmentation allows the operating system to update access rights for a single application without affecting other applications, providing both comprehensive access control and operational flexibility.
4Reliability
If domain-based security management is implemented, then access rights to precisely defined functionalities are controlled, but a large memory capacity is occupied by redefining rights for all functionalities
Solution Approach 1:
The patent extracts only the necessary access rights information for each application from a comprehensive domain-based security model. Instead of storing and managing authorization data for all functionalities across all applications within domains, the system extracts and stores only the specific rights needed for each application in its own authorization list. This extraction significantly reduces memory usage while maintaining precise access rights control.
Data Source
AI summary
To secure the execution of an application on an intelligent mobile telephone, each application is identified by an identifier and a table or rights is associated with each resource on the mobile telephone. Through a table of rights, access rights to the resource can be associated with an application identifier. This makes it possible to manage, for each resource, the applications that are allowed to invoke the resource. Moreover, the rights associated with a resource can only be modified by the owner of the resource.


