Database Security Analyzer for IoT App Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the IoT environment, personal information stored in communication devices is vulnerable to security incidents due to the lack of effective database security policies for applications, making it difficult to prevent leaks of personal information from malicious apps and external risks.

Innovation Solution

A method and apparatus for dynamically protecting information in a communication system by acquiring and outputting database security analysis results for applications, where a server receives and transmits these results to communication devices to enhance security policies based on analysis, allowing for real-time security assessments and policy applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If database encryption and security policies are applied to Apps, then personal information security is improved, but App development complexity and load increase significantly

Engineering Contradiction:
Improvepersonal information securityVSAvoidApp development complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a database security analyzer as an intermediary component that operates independently from Apps. This analyzer intercepts and analyzes database operations at the system level without requiring Apps to implement security logic, thereby improving personal information security while maintaining App development simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The database security analyzer automatically performs security analysis on database operations without requiring manual intervention or complex configuration by App developers. The system self-services by monitoring, analyzing, and protecting database operations transparently, reducing the burden on App development while enhancing security.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If security scanning and code static analysis are performed on Apps, then malicious App detection is improved, but new unknown malicious Apps cannot be prevented

Engineering Contradiction:
Improvemalicious App detection accuracyVSAvoidprotection against unknown malicious Apps
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent implements preliminary security analysis by examining database operations and authority files before Apps execute malicious actions. The database security analyzer proactively identifies potential security issues in database operations, enabling prevention of both known and unknown malicious Apps through advance detection mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where the database security analyzer continuously monitors database operations, compares them against security criteria, and dynamically adjusts security policies based on detected patterns. This feedback mechanism enables the system to adapt to new malicious Apps by learning from observed behaviors rather than relying solely on pre-defined signatures.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If database security analysis is performed for each App, then security policy accuracy is improved, but processing time and system load increase

Engineering Contradiction:
Improvesecurity policy accuracyVSAvoidsecurity analysis processing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The database security analyzer performs preliminary analysis of database operations and authority files when Apps are installed or request database access. By conducting security analysis in advance rather than in real-time during operations, the system achieves high security policy accuracy while minimizing processing time impact on App execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies security analysis selectively to database operations based on risk levels and operation types. Not all database operations require full security analysis - the system performs partial analysis on high-risk operations while using cached results or simplified checks for low-risk operations, thereby maintaining accuracy where needed while reducing overall processing time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3338216B1Apparatus and method for protecting information in communication system
Publication Date: 2019.12.11 SAMSUNG ELECTRONICS CO LTD
  • EP3338216B1 patent drawingFigure 1~2
  • EP3338216B1 patent drawingFigure 3
  • EP3338216B1 patent drawingFigure 4

AI summary

The present disclosure relates to a sensor network, machine type communication (MTC), machine-to-machine (M2M) communication, and technology for internet of things (IoT). The present disclosure may be applied to intelligent services based on the above technologies, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method, communication device, and server for protecting information in a communication device in a communication system are provided. The method includes acquiring a database security analysis result for an application (App) upon detecting that the App is run, and outputting the database security analysis result for the App.