Secure Provisioning of COTS Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial off-the-shelf (COTS) mobile devices lack secure configurations, making them vulnerable to unauthorized access and data breaches, which can lead to data loss and confidentiality issues, especially in organizational settings.

Innovation Solution

A system and method for securely provisioning COTS devices by providing secure configuration software that prevents unauthorized access and removes unwanted features, using a provisioning device to configure the device based on user and organizational requirements, via a network, enabling the device to access only secure content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If COTS devices are used without customization, then device cost is reduced, but security protection capability deteriorates

Engineering Contradiction:
Improvedevice costVSAvoidsecurity protection capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring security policies, application whitelists, and restricted profiles on COTS devices before they are deployed to users. The provisioning system automatically installs security configurations, removes unwanted applications, and configures device policies in advance, transforming standard devices into secure organizational devices without requiring custom hardware or manual setup by users.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If COTS devices include all default features, then device functionality is improved, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improvedevice functionalityVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the extraction principle by removing unwanted applications, services, and features from COTS devices through automated provisioning. The system extracts malicious or unnecessary software, disables unwanted device features, and removes applications that could compromise security, thereby reducing the attack surface while maintaining essential organizational functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by implementing differentiated security configurations for different device types, user roles, and organizational requirements. The provisioning system tailors security policies, application allowances, and restricted profiles to specific local contexts, ensuring each device receives appropriate security measures based on its intended use rather than applying uniform restrictions across all devices.

Inventive Principle:
Principle #3Local quality

3Reliability

If secure configuration software is provided to COTS devices, then unauthorized access is prevented, but device complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the intermediary principle by introducing a provisioning system that acts as a mediator between organizational security requirements and COTS devices. This intermediary automatically generates, distributes, and manages security configuration software, application whitelists, and device policies, eliminating the need for users to manually configure complex security settings while ensuring consistent security enforcement across all devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9047470B2Secure provisioning of commercial off-the-shelf (COTS) devices
Publication Date: 2015.06.02 VERIZON PATENT & LICENSING INC
  • US9047470B2 patent drawing
  • US9047470B2 patent drawing
  • US9047470B2 patent drawing

AI summary

A device receives identification information associated with a mobile commercial off-the-shelf (COTS) device, and receives configuration and security requirements defined for the mobile COTS device. The device creates secure configuration software for the mobile COTS device based on the identification information and the configuration and security requirements, and provides the secure configuration software to the mobile COTS device for installation.