Componentized Provisioning for Mobile Security Policy Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional mobile device management solutions implement static, monolithic security policies that are inflexible and unable to dynamically control resource use and sharing based on the purpose of installed components and their context of use, leading to over-restrictive measures and challenges in maintaining security in complex, multi-purpose computing environments.

Innovation Solution

A modular, component-based approach using MILS (Multiple Independent Levels of Security) concepts and a provisioning subsystem that enables context-aware, peer-based policy enforcement, allowing individual components to operate without prior knowledge of other components' policies, and provides secure, purpose-specific resource management through isolation and information flow control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If static, monolithic security policies are implemented, then security control is simplified, but flexibility and adaptability to different purposes are lost

Engineering Contradiction:
Improvesecurity policy managementVSAvoidcontext-aware resource control
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments monolithic security policies into component-level policies, where each installed component (application, service, etc.) has its own security policy defined by its owner. This segmentation allows independent management and customization of security rules for each component based on its specific purpose and context, resolving the contradiction between simplified management and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic provisioning that allows security policies to be established, modified, and revoked at runtime based on component installation, updates, and removals. The system dynamically adapts security controls to the current state of the device, enabling context-aware resource management while maintaining manageable complexity through automated policy propagation.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If component owners define their own security policies, then policy flexibility and purpose-specific control improve, but system complexity and coordination overhead increase

Engineering Contradiction:
Improvecomponent-specific policy definitionVSAvoidpolicy coordination
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by automatically propagating component owner-defined security policies to the provisioning subsystem during component installation or update. This preliminary policy establishment eliminates the need for complex runtime coordination, as policies are pre-configured and enforced before security decisions are made, reducing system complexity while maintaining flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables component owners to self-define their own security policies without requiring system administrator intervention or complex coordination. Each component owner independently manages their component's security requirements, and the system automatically incorporates these policies into the overall security framework, reducing coordination overhead while maintaining adaptability.

Inventive Principle:
Principle #25Self-service

3Device complexity

If traditional monolithic architecture is used, then system simplicity is maintained, but security vulnerability isolation and mitigation become difficult

Engineering Contradiction:
Improvesystem architectureVSAvoidsecurity vulnerability containment
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the monolithic execution environment into isolated component instances, where each component runs in its own security context with enforced policy boundaries. This segmentation contains security vulnerabilities to specific components, preventing lateral movement and system-wide compromise, while maintaining architectural simplicity through virtualization-based isolation.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If security policies are enforced at the system level, then security control is centralized and simple, but fine-grained resource control for individual components is lost

Engineering Contradiction:
Improvesecurity enforcement mechanismVSAvoidfine-grained resource management
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments security enforcement from centralized system-level control to distributed component-level policies. Each component has its own policy defined by its owner, enabling fine-grained resource management specific to each component's needs. The provisioning subsystem automatically enforces these segmented policies, maintaining simple enforcement mechanisms while achieving fine-grained control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables component owners to self-define fine-grained security policies for their components without requiring complex system-level configuration. Each component autonomously manages its own resource access requirements, and the provisioning subsystem automatically enforces these self-defined policies, simplifying the enforcement mechanism while enabling detailed resource control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9922210B2Componentized provisioning
Publication Date: 2018.03.20 MAGMA SCIENTIFIC LLC
  • US9922210B2 patent drawing
  • US9922210B2 patent drawing
  • US9922210B2 patent drawing

AI summary

A provisioning system can separately and independently provision different components for different purposes on a computing platform, and enforce component-specific purposes associated with the use of the individual provisioned components during operation of the platform. Some versions of the provisioning subsystem may operate on a virtualized mobile computing device and networked devices under control of the computing device. In some embodiments, the provisioning subsystem can enforce a desired “purpose” of a provisioned component while simultaneously denying a corresponding “anti-purpose.”