Application Sandbox Allocation via Metadata-Driven Environment Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices lack an automated mechanism to allocate applications to sandboxes based on application-specific data, requiring manual user intervention and failing to guarantee an independent execution space for applications.

Innovation Solution

An electronic device with a communication module, processor, and memory that automatically installs and allocates applications to specific environments without user input, based on metadata indicating the required execution environment, ensuring secure and independent operation of applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual user intervention is used to allocate applications to sandboxes, then user control over application placement is improved, but automation level deteriorates and user burden increases

Engineering Contradiction:
Improveuser controlVSAvoidautomatic allocation
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The application itself provides the necessary information (metadata indicating sandbox requirement) to enable the electronic device to automatically determine and allocate the application to the appropriate environment without requiring user intervention or manual configuration

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The metadata indicating sandbox execution requirements is prepared in advance within the application package before installation, allowing the electronic device to automatically identify and allocate the application to the appropriate environment during the installation process itself

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If applications are executed in a shared environment, then system simplicity is improved, but data isolation and security deteriorate

Engineering Contradiction:
Improveenvironment structureVSAvoiddata isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system divides the execution environment into distinct segments (first environment and second environment) with different security levels and data access permissions, allowing applications to be allocated to appropriate segments based on their sandbox requirements while maintaining overall system structure

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different execution environments are created with different local qualities - the first environment provides full data access while the second environment provides restricted access with data isolation, allowing each application to operate in the environment most suitable for its security requirements

Inventive Principle:
Principle #3Local quality

3Extent of automation

If automated allocation based on application data is implemented, then automation level and security are improved, but system complexity increases

Engineering Contradiction:
Improveautomatic allocationVSAvoidallocation mechanism
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The metadata indicating sandbox execution requirements is prepared in advance within the application package before installation, allowing the electronic device to automatically identify and allocate the application to the appropriate environment during the installation process itself, avoiding the need for complex post-installation analysis mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Metadata serves as an intermediary element that carries information about sandbox execution requirements from the application to the electronic device, enabling automated allocation without requiring the device to perform complex analysis of application code or data structures

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10146517B2Electronic device for installing application and method of controlling same
Publication Date: 2018.12.04 SAMSUNG ELECTRONICS CO LTD
  • US10146517B2 patent drawing
  • US10146517B2 patent drawing
  • US10146517B2 patent drawing

AI summary

An electronic device and method of controlling an electronic device are provided. The electronic device includes a communication module; a processor; and a memory that stores instructions to instruct the processor to install a first application operating only in a first environment, install a second application selectively operating in at least one of the first environment and a second environment, grant access to the first application to first data, the first data being generated while the second application operates in the first environment, deny access to the first application to second data, the second data being generated while the second application operates in the second environment, grant access to the second application to third data, the third data being generated while the first application operates in the first environment, and allocate the second application to at least the second environment without a user's input when the second application is installed.