Dynamic Security Framework for Telecommunications Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing trust model for security enforcement on telecommunications terminals with open operating systems is costly, particularly for open-source software, and has limitations in dynamic security management, as it relies on static certification and vulnerability assessment, which does not effectively prevent malware attacks.

Innovation Solution

A dynamic security framework that assigns varying security levels to software applications based on their reputation, calculated from multiple information sources, including vulnerability analysis and patch release times, allowing for periodic re-evaluation and real-time management of security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static certification models are used for security enforcement, then security levels can be assigned to applications, but the system becomes costly and cannot dynamically respond to new vulnerabilities or malware attacks

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security level assignment by continuously monitoring application behavior, vulnerability reports, and malware indicators. Security levels are not fixed but evolve over time based on real-time data, allowing the system to adapt to new threats while maintaining manageable complexity through automated decision-making

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes feedback loops where security information from multiple sources (vulnerability databases, malware reports, application behavior monitoring) is continuously fed back into the security level assessment process. This enables the system to learn from past security events and adjust future security decisions accordingly, improving effectiveness without proportionally increasing complexity

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If static security levels are assigned to applications, then access permissions can be controlled, but open-source software and rapidly evolving applications cannot receive timely security updates

Engineering Contradiction:
Improvesecurity level flexibilityVSAvoidsecurity update time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements continuous security assessment through automated monitoring that operates without interruption. Security levels are continuously updated based on new vulnerability information, malware reports, and application behavior, ensuring that both established and open-source applications receive timely security updates without manual intervention delays

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary security assessments by proactively monitoring vulnerability databases and malware indicators before they manifest as actual threats. This allows the system to preemptively update security levels for applications that may be targeted, reducing the time between vulnerability discovery and security response

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If comprehensive security monitoring is implemented, then malware attacks can be detected and prevented, but system performance and computational resources are consumed

Engineering Contradiction:
Improvemalware attack preventionVSAvoidcomputational resource consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by tailoring security monitoring intensity to individual application characteristics and risk profiles. Rather than uniformly monitoring all applications equally, the system adjusts monitoring depth and resource allocation based on each application's security level, functionality, and historical behavior, reducing overall computational burden while maintaining effective malware prevention

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial monitoring by focusing computational resources on the most critical security aspects and high-risk applications. Not all security indicators are monitored with equal intensity, and not all applications receive full monitoring coverage, allowing the system to achieve effective malware detection while conserving computational resources for where they matter most

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8474004B2System for implementing security on telecommunications terminals
Publication Date: 2013.06.25 TELECOM ITALIA SPA
  • US8474004B2 patent drawing
  • US8474004B2 patent drawing
  • US8474004B2 patent drawing

AI summary

A system includes at least one telecommunications terminal having data processing capabilities, the telecommunications terminal being susceptible of having installed thereon software applications, wherein each software application has associated therewith a respective indicator adapted to indicate a level of security of the software application, the level of security being susceptible of varying in time; a software agent executed by the at least one telecommunications terminal, the software agent being adapted to conditionally allow the installation of software applications on the telecommunications terminal based on the respective level of security; a server in communications relationship with the software agent, the server being adapted to dynamically calculate the level of security of the software applications, and to communicate to the software agent the calculated level of security of the software applications to be installed on the telecommunications terminal.