Cloud Sync Profile for Mobile Security Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile computing platforms impose restrictions on applications, preventing them from scanning or modifying devices due to limitations on accessing the current state or executing resource-intensive operations, making it difficult to detect and remove malicious software or optimize device performance.

Innovation Solution

The system uses a cloud-based synchronization service to access a synchronization profile representing the mobile device's state, allowing operations to be performed indirectly on the profile, thereby circumventing platform restrictions and enabling scanning for malicious software or optimizing device performance without direct access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional scanning applications are implemented directly on mobile devices, then users can optimize device performance and detect malicious applications, but mobile computing platform restrictions prevent applications from accessing current device state information and executing resource-intensive operations

Engineering Contradiction:
Improveability to detect and remove malicious softwareVSAvoidaccess to current device state
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based service as an intermediary between the user and the mobile device. The service retrieves synchronization profiles from cloud storage, performs scanning operations on the profile data in the cloud, and returns results to the user. This mediator approach allows resource-intensive scanning operations to occur outside the restricted mobile environment while still providing security analysis capabilities to the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the device state through synchronization profiles stored in the cloud. Instead of directly accessing the actual mobile device state (which is restricted), the application operates on a copied representation (the synchronization profile) that contains equivalent information about installed applications and device state. This copying enables analysis without violating platform restrictions.

Inventive Principle:
Principle #26Copying

2Measurement precision

If resource-intensive scanning operations are executed directly on the mobile device, then comprehensive security analysis can be performed, but mobile device resources are limited and platform restrictions block execution of such operations

Engineering Contradiction:
Improvecompleteness of security scanVSAvoidmobile device processing resources
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The cloud-based service acts as an intermediary computing platform with abundant resources. The mobile device offloads resource-intensive scanning operations to this intermediary service, which performs comprehensive security analysis on synchronization profile data. This transfers the computational burden from the energy-constrained mobile device to the resource-rich cloud environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the resource-intensive scanning operations from the mobile device environment and relocates them to a cloud-based service. By separating the analysis function from the constrained mobile platform, the system eliminates the resource and permission limitations that would otherwise prevent comprehensive security scanning on mobile devices.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If applications are sandboxed from each other on mobile devices, then system security is improved, but legitimate scanning applications cannot access information about other installed applications

Engineering Contradiction:
Improvesystem security through sandboxingVSAvoidaccess to application installation information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system obtains a copy of the application installation information through the synchronization profile, which is already stored in cloud storage. This copying approach bypasses the sandbox restriction because the application is not directly accessing other applications' data on the device; instead, it retrieves a previously synchronized copy from the cloud, maintaining both security and functionality.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The synchronization profile is created and stored in the cloud in advance (preliminarily) before the scanning operation occurs. This preliminary action of syncing device state information to the cloud enables later retrieval and analysis without requiring direct inter-application access permissions at the time of scanning, thus working around sandbox restrictions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9773108B1Systems and methods for performing operations on restricted mobile computing platforms
Publication Date: 2017.09.26 CA TECH INC
  • US9773108B1 patent drawing
  • US9773108B1 patent drawing
  • US9773108B1 patent drawing

AI summary

The disclosed computer-implemented method for performing operations on restricted mobile computing platforms may include (1) receiving a request to perform an operation on a mobile device, (2) requesting access to a synchronization profile of the mobile device that represents the current state of the mobile device, (3) receiving access to the synchronization profile, and (4) performing the operation on the mobile device by performing an analogous operation on the synchronization profile. In some examples, the operation may require access to a current state of the mobile device, and a mobile computing platform of the mobile device may place a limitation on the ability of third-party software to (a) inspect the current state of the mobile device, (b) modify the current state of the mobile device, and/or (c) execute resource-intensive operations via the mobile device. Various other methods, systems, and computer-readable media are also disclosed.