Dynamic Security Policy Management for Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems for mobile devices are static, lacking an efficient method to update or change policy files once deployed, which restricts the ability to adapt to new security protocols or market conditions, such as enabling location-based services or updating API access rules.
Innovation Solution
Implementing a dynamic security policy mechanism that allows the device provider to push or pull a new policy file, managing memory and download functions, and enabling the application management system to update the policy file from a remote location, with features like provider-trusted signatures and permissions protocols to ensure secure updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a static policy file is implemented in the mobile device, then security management is simplified and device stability is maintained, but the device cannot adapt to new security protocols or market conditions after deployment
Solution Approach 1:
The patent transforms the static policy file into a dynamic, updatable component. The policy file can now be remotely updated through push or pull mechanisms, allowing the device to adapt to new security protocols while maintaining version control and backup mechanisms to ensure stability during transitions.
Solution Approach 2:
The system performs preliminary actions by backing up the existing policy file before applying updates and verifying the new policy file's integrity through signature validation. This ensures that if an update fails or is malicious, the device can revert to the previous stable state.
2Adaptability or versatility
If the policy file is made updatable remotely, then the device can accommodate location-based services and updated API rules, but the risk of unauthorized or malicious policy changes increases
Solution Approach 1:
The patent introduces an intermediary verification mechanism using provider-trusted signatures. Before a policy file is applied, it must be validated against a trusted signature, acting as an intermediary security check that prevents unauthorized or malicious policy changes while allowing legitimate updates.
Solution Approach 2:
The system implements feedback through signature verification and update validation mechanisms. The device checks whether incoming policy files have valid signatures and whether they meet security criteria before applying them, providing a feedback loop that prevents unauthorized changes.
3Adaptability or versatility
If the application management system implements dynamic policy updates, then new functionality can be enabled, but the system complexity increases
Solution Approach 1:
The patent implements a universal update mechanism that handles multiple scenarios (push and pull updates, different update sources, various policy file formats) through a unified framework. The application management system uses a common set of procedures for backing up, validating, and applying policy files regardless of the update source or type.
4Ease of manufacture
If Java ME MIDlets are compiled with static security policies, then deployment is simplified, but the policies cannot be changed or updated in the marketplace
Solution Approach 1:
The patent segments the security policy from the compiled application code. Instead of hardcoding static policies into MIDlets, the policy is separated into an external, updatable file that can be independently modified and pushed to devices without requiring application re-compilation or re-deployment.
Data Source
AI summary
A method for dynamically changing the security protocol in a hand-held mobile communications device within a network includes providing an application management system in a respective mobile communications device for management of memory use and download functions, providing within the mobile communications device an embedded file system that contains executable files that are controlled by the application management system, providing a browser on the mobile communications device so that a user thereof may access websites available on the network, and providing a policy file that includes a set of rules for managing the download of applications from a remote location, the policy file being enabled to receive authorized updates over the network.


