Device Configuration Access Control via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management systems face challenges in securely controlling access to configuration data sets across multiple configurations in devices, particularly in corporate environments, where sensitive information needs to be protected from unauthorized access.

Innovation Solution

A method and system that utilize access control information originated and controlled by an external managing entity to define and enforce access rights to configuration data sets, ensuring that only authorized applications can access specific service contexts, thereby securing sensitive user and corporate data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple configuration data sets are stored in the device for different management purposes, then the device can access diverse services (corporate IT services, operator services, personal services), but the risk of unauthorized access to sensitive configuration data increases

Engineering Contradiction:
Improvedevice service access capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments configuration data into multiple configuration data sets, each associated with a specific service context (corporate IT services, operator services, personal services). Each configuration data set is independently protected by access control information, allowing the device to access diverse services while preventing unauthorized access to specific configuration segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control properties to different configuration data sets based on their security requirements. Corporate IT service configurations have stricter access controls than personal service configurations, allowing each data set to have customized security characteristics matched to its specific protection needs.

Inventive Principle:
Principle #3Local quality

2Reliability

If access control information is implemented for each configuration data set, then security is improved by limiting access to authorized applications only, but the device complexity increases due to multiple access control mechanisms

Engineering Contradiction:
Improveconfiguration access securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control framework that can be applied to multiple configuration data sets using the same basic mechanism. The access control information follows a consistent structure with service context identifiers and access rights, allowing the device to enforce security across diverse configurations without requiring separate complex mechanisms for each data set.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If corporate IT personnel need to control access to configurations for security purposes, then data protection is improved, but the ease of operation for application developers decreases due to access control restrictions

Engineering Contradiction:
Improvecorporate data protectionVSAvoidapplication development simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces access control information as an intermediary layer between applications and configuration data. This intermediary contains service context identifiers and access rights that automatically mediate access requests, allowing corporate IT personnel to control access to sensitive configurations while transparently enabling authorized applications to access required data without direct intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8140650B2Use of configurations in device with multiple configurations
Publication Date: 2012.03.20 NOKIA TECHNOLOGIES OY
  • US8140650B2 patent drawing
  • US8140650B2 patent drawing
  • US8140650B2 patent drawing

AI summary

The invention relates to a method for arranging use of configurations in a device with multiple configuration data sets manageable by one or more external managing entities. The device comprises access control information originated and/or controlled by an external managing entity for defining a right to access a configuration data set. The access control information is checked in response to an indication from an application requiring access to a configuration data set. If the application is, on the basis of the access control information, entitled to access the configuration data set, access to the configuration data set is arranged for the application.