Application Identifier Table for Mobile Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure code execution environments in cellular telephony, such as those using virtual machines, fail to effectively manage access to mobile phone resources by unspecific programs and require extensive memory for security policy updates, limiting independent rights management for specific applications.

Innovation Solution

Associating a unique identifier with each application, managing resource access through an operating system that scans an application identifier table to determine access rights, with a dynamic table for each application and owner authorization, enabling centralized and flexible management of resource access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If domain-based security policies are implemented where each application belongs to a domain, then access rights to functionalities can be precisely defined, but memory capacity is occupied excessively and rights cannot be updated for specific applications independently

Engineering Contradiction:
Improveaccess rights managementVSAvoidmemory capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the security policy management by creating separate authorization lists for each application instead of grouping applications into domains. Each application gets its own identifier and independent authorization list, allowing granular control over access rights without the overhead of domain-based grouping. This segmentation enables independent updates of rights for specific applications while reducing memory usage compared to managing all applications within domain structures.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a virtual machine layer is implemented to execute specific programs, then secured code execution is achieved, but the security policy is confined to the mobile telephone and no interaction with external security elements is planned

Engineering Contradiction:
Improvesecured code executionVSAvoidsecurity policy interaction
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal security policy management system that operates at the operating system level rather than being confined to a specific virtual machine layer. The authorization lists and identifier-based security model can work with any application type and can interact with various security elements including SIM cards, making the security system adaptable and versatile across different execution environments and external security components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If all applications must belong to a domain with redefined rights for all functionalities, then comprehensive access control is achieved, but it is impossible to update rights for a specific application independently from other applications

Engineering Contradiction:
Improveaccess controlVSAvoidrights update flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the security management structure into application-specific authorization lists rather than domain-based groupings. Each application identifier has its own dedicated authorization list that can be independently modified. This segmentation allows the operating system to update access rights for a single application without affecting other applications, providing both comprehensive access control and operational flexibility.

Inventive Principle:
Principle #1Segmentation

4Reliability

If domain-based security management is implemented, then access rights to precisely defined functionalities are controlled, but a large memory capacity is occupied by redefining rights for all functionalities

Engineering Contradiction:
Improveaccess rights controlVSAvoidmemory capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary access rights information for each application from a comprehensive domain-based security model. Instead of storing and managing authorization data for all functionalities across all applications within domains, the system extracts and stores only the specific rights needed for each application in its own authorization list. This extraction significantly reduces memory usage while maintaining precise access rights control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7623846B2Process for the secure management of the execution of an application
Publication Date: 2009.11.24 SOC FR DU RADIOTELEPHONE SFR
  • US7623846B2 patent drawing
  • US7623846B2 patent drawing
  • US7623846B2 patent drawing

AI summary

To secure the execution of an application on an intelligent mobile telephone, each application is identified by an identifier and a table or rights is associated with each resource on the mobile telephone. Through a table of rights, access rights to the resource can be associated with an application identifier. This makes it possible to manage, for each resource, the applications that are allowed to invoke the resource. Moreover, the rights associated with a resource can only be modified by the owner of the resource.