Context-Based Mobile Feature Control for Secure Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure access policies for mobile devices are overly restrictive, preventing authorized access to non-sensitive features in secure locations, necessitating more granular control over device features to balance security and functionality.
Innovation Solution
Implementing context-based feature control methods that determine contexts such as location, network connectivity, and proximity to security beacons to enforce permission settings at a feature level, allowing access to non-security-threatening features like telephony and health monitoring while restricting sensitive functions like photography and data copying.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure access policies restrict all mobile device features in secure locations, then information security is improved, but device functionality and user convenience deteriorate
Solution Approach 1:
The patent segments device control from whole-device restriction to feature-level control. It identifies and categorizes individual device features (camera, microphone, speaker, display, sensors, etc.) and applies security policies selectively to specific features rather than restricting all features uniformly. This allows non-sensitive features to remain accessible while sensitive features are restricted, resolving the contradiction between security and functionality.
Solution Approach 2:
The patent implements local quality by applying different security control levels to different spatial locations within a facility. It uses location detection (GPS, WiFi triangulation, RFID beacons) to determine the device's precise location and applies context-appropriate security profiles. For example, the camera may be restricted in a secure server room but allowed in a general office area, allowing functionality to be preserved where security risks are lower while maintaining security where needed.
2Reliability
If mobile devices are surrendered before entry to secure locations, then unauthorized data capture is prevented, but legitimate business needs and productivity are lost
Solution Approach 1:
Instead of surrendering the entire device, the patent segments control to the feature level. It allows employees to retain possession of their mobile devices and continue using non-sensitive features (telephone, messaging, note-taking, health monitoring) while only restricting sensitive features (camera, microphone, speaker, display, file system access) in secure locations. This maintains productivity by preserving legitimate business functions while ensuring security through selective feature restriction.
Solution Approach 2:
The patent implements dynamic security controls that automatically adjust feature permissions based on the device's real-time location and context. As the device moves between different locations (e.g., from a secure area to a general office area), the security profile dynamically changes, enabling or disabling specific features accordingly. This dynamic approach allows continuous productivity while maintaining security posture appropriate to each location.
3Measurement precision
If granular feature-level control is implemented, then security precision is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal security management system that handles multiple security policies, locations, and device features through a single integrated platform. The system provides a centralized interface for defining security profiles that can simultaneously control multiple features across multiple locations. This multi-functional approach reduces complexity by consolidating what would otherwise require separate control mechanisms for each feature and location into a unified system.
Solution Approach 2:
The patent incorporates automatic location detection and context-based security profile selection that operates without manual intervention. The system automatically determines the device's location using available sensors (GPS, WiFi, RFID), selects the appropriate security profile, and applies the correct feature restrictions. This self-service automation reduces operational complexity by eliminating the need for manual policy configuration and enforcement, allowing the system to autonomously manage granular feature-level controls.
Data Source
AI summary
Methods and systems for context-based mobile device feature control are provided. One method comprises determining, with a mobile device, one or more contexts corresponding to the mobile device; selecting, from a predetermined set of security protocols, a security protocol corresponding to the determined one or more contexts; and adjusting a permission setting for one or more functional features of the mobile device based upon the selected security protocol. One apparatus comprises one or more features configure to input data, output data, transform data, or a combination thereof; and a controller configured to: determine one or more contexts corresponding to the mobile computing device, to select, from a predetermined set of security protocols, a security protocol corresponding to the determined one or more contexts, and to adjust a permission setting for the one or more functional features based upon the selected security protocol.


