Cloud Sync Profile for Mobile Security Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile computing platforms impose restrictions on applications, preventing them from scanning or modifying devices due to limitations on accessing the current state or executing resource-intensive operations, making it difficult to detect and remove malicious software or optimize device performance.
Innovation Solution
The system uses a cloud-based synchronization service to access a synchronization profile representing the mobile device's state, allowing operations to be performed indirectly on the profile, thereby circumventing platform restrictions and enabling scanning for malicious software or optimizing device performance without direct access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional scanning applications are implemented directly on mobile devices, then users can optimize device performance and detect malicious applications, but mobile computing platform restrictions prevent applications from accessing current device state information and executing resource-intensive operations
Solution Approach 1:
The patent introduces a cloud-based service as an intermediary between the user and the mobile device. The service retrieves synchronization profiles from cloud storage, performs scanning operations on the profile data in the cloud, and returns results to the user. This mediator approach allows resource-intensive scanning operations to occur outside the restricted mobile environment while still providing security analysis capabilities to the user.
Solution Approach 2:
The system creates a copy of the device state through synchronization profiles stored in the cloud. Instead of directly accessing the actual mobile device state (which is restricted), the application operates on a copied representation (the synchronization profile) that contains equivalent information about installed applications and device state. This copying enables analysis without violating platform restrictions.
2Measurement precision
If resource-intensive scanning operations are executed directly on the mobile device, then comprehensive security analysis can be performed, but mobile device resources are limited and platform restrictions block execution of such operations
Solution Approach 1:
The cloud-based service acts as an intermediary computing platform with abundant resources. The mobile device offloads resource-intensive scanning operations to this intermediary service, which performs comprehensive security analysis on synchronization profile data. This transfers the computational burden from the energy-constrained mobile device to the resource-rich cloud environment.
Solution Approach 2:
The patent extracts the resource-intensive scanning operations from the mobile device environment and relocates them to a cloud-based service. By separating the analysis function from the constrained mobile platform, the system eliminates the resource and permission limitations that would otherwise prevent comprehensive security scanning on mobile devices.
3Reliability
If applications are sandboxed from each other on mobile devices, then system security is improved, but legitimate scanning applications cannot access information about other installed applications
Solution Approach 1:
The system obtains a copy of the application installation information through the synchronization profile, which is already stored in cloud storage. This copying approach bypasses the sandbox restriction because the application is not directly accessing other applications' data on the device; instead, it retrieves a previously synchronized copy from the cloud, maintaining both security and functionality.
Solution Approach 2:
The synchronization profile is created and stored in the cloud in advance (preliminarily) before the scanning operation occurs. This preliminary action of syncing device state information to the cloud enables later retrieval and analysis without requiring direct inter-application access permissions at the time of scanning, thus working around sandbox restrictions.
Data Source
AI summary
The disclosed computer-implemented method for performing operations on restricted mobile computing platforms may include (1) receiving a request to perform an operation on a mobile device, (2) requesting access to a synchronization profile of the mobile device that represents the current state of the mobile device, (3) receiving access to the synchronization profile, and (4) performing the operation on the mobile device by performing an analogous operation on the synchronization profile. In some examples, the operation may require access to a current state of the mobile device, and a mobile computing platform of the mobile device may place a limitation on the ability of third-party software to (a) inspect the current state of the mobile device, (b) modify the current state of the mobile device, and/or (c) execute resource-intensive operations via the mobile device. Various other methods, systems, and computer-readable media are also disclosed.


