Device Configuration Access Control via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management systems face challenges in securely controlling access to configuration data sets across multiple configurations in devices, particularly in corporate environments, where sensitive information needs to be protected from unauthorized access.
Innovation Solution
A method and system that utilize access control information originated and controlled by an external managing entity to define and enforce access rights to configuration data sets, ensuring that only authorized applications can access specific service contexts, thereby securing sensitive user and corporate data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple configuration data sets are stored in the device for different management purposes, then the device can access diverse services (corporate IT services, operator services, personal services), but the risk of unauthorized access to sensitive configuration data increases
Solution Approach 1:
The patent segments configuration data into multiple configuration data sets, each associated with a specific service context (corporate IT services, operator services, personal services). Each configuration data set is independently protected by access control information, allowing the device to access diverse services while preventing unauthorized access to specific configuration segments.
Solution Approach 2:
The patent applies different access control properties to different configuration data sets based on their security requirements. Corporate IT service configurations have stricter access controls than personal service configurations, allowing each data set to have customized security characteristics matched to its specific protection needs.
2Reliability
If access control information is implemented for each configuration data set, then security is improved by limiting access to authorized applications only, but the device complexity increases due to multiple access control mechanisms
Solution Approach 1:
The patent implements a universal access control framework that can be applied to multiple configuration data sets using the same basic mechanism. The access control information follows a consistent structure with service context identifiers and access rights, allowing the device to enforce security across diverse configurations without requiring separate complex mechanisms for each data set.
3Reliability
If corporate IT personnel need to control access to configurations for security purposes, then data protection is improved, but the ease of operation for application developers decreases due to access control restrictions
Solution Approach 1:
The patent introduces access control information as an intermediary layer between applications and configuration data. This intermediary contains service context identifiers and access rights that automatically mediate access requests, allowing corporate IT personnel to control access to sensitive configurations while transparently enabling authorized applications to access required data without direct intervention.
Data Source
AI summary
The invention relates to a method for arranging use of configurations in a device with multiple configuration data sets manageable by one or more external managing entities. The device comprises access control information originated and/or controlled by an external managing entity for defining a right to access a configuration data set. The access control information is checked in response to an indication from an application requiring access to a configuration data set. If the application is, on the basis of the access control information, entitled to access the configuration data set, access to the configuration data set is arranged for the application.


