Authenticated Component Permissions Framework for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current permission management systems in computing devices burden users with complex decision-making, leading to errors in approving or denying access requests from third-party applications, and often require a single entity to manage permissions for multiple applications, limiting innovation and control.
Innovation Solution
An authenticated component permissions framework that allows applications to request access to resources based on predefined permissions, where a signing authority reviews and digitally signs permission requests, reducing user intervention and enabling efficient management of permissions through device and application permission descriptors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manually audit and decide on permission requests, then users have control over application access, but users require high knowledge of sub-systems and services leading to errors
Solution Approach 1:
The patent introduces an automated permission management system that acts as an intermediary between applications and users. This system includes permission policies, permission review entities, and automated approval mechanisms that evaluate permission requests without requiring direct user intervention. The intermediary system uses predefined policies and automated review processes to make accurate permission decisions while eliminating the need for users to have deep knowledge of sub-systems and services.
Solution Approach 2:
The patent implements self-service mechanisms where the permission management system automatically handles permission requests through predefined policies and automated review entities. The system serves itself by using automated approval processes, policy-based access control, and machine-reviewed permission requests, eliminating the need for manual user audit and decision-making for each permission request.
2Extent of automation
If system provider defines and audits all permissions, then permission management is centralized, but a single entity bears the burden of managing permissions for multiple applications
Solution Approach 1:
The patent segments the permission management system into distinct components: permission policies, permission review entities, automated approval mechanisms, and application-specific permission descriptors. This segmentation distributes the management burden across multiple specialized components rather than concentrating it in a single entity. Each component handles specific aspects of permission management, reducing overall complexity while maintaining high automation levels.
Solution Approach 2:
The patent creates a universal permission management framework that can handle multiple applications and diverse sub-systems through a common architecture. The permission review entities and automated approval mechanisms serve multiple functions across different applications and resources, eliminating the need for separate manual management for each application while maintaining centralized control and consistency.
3Reliability
If closed environment is used, then provider has control over system, but innovation in utilization of sub-systems and services is limited
Solution Approach 1:
The patent implements a dynamic permission management system that adapts to different applications and use cases while maintaining security control. The system uses configurable permission policies, flexible review entity assignments, and automated approval mechanisms that can be adjusted based on application requirements. This dynamic approach allows third-party applications to access sub-systems and services through automated permission processes, fostering innovation while maintaining provider control through policy-based access management.
Data Source
AI summary
Various embodiments set forth techniques for managing access to a resource at a device. In one aspect, a method includes receiving a request by an application to access a resource, determining that an application permission associated with the application and the resource grants the application access to the resource, where the application permission includes a signature of a permission review entity associated with the resource, and granting the request to access the resource based on the application permission. The permission review entity associated with the resource may be authorized through device permissions specified by an implementer or provider of the device.


