Dynamic Security Policy Management for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management systems for mobile devices are static, lacking an efficient method to update or change policy files once deployed, which restricts the ability to adapt to new security protocols or market conditions, such as enabling location-based services or updating API access rules.

Innovation Solution

Implementing a dynamic security policy mechanism that allows the device provider to push or pull a new policy file, managing memory and download functions, and enabling the application management system to update the policy file from a remote location, with features like provider-trusted signatures and permissions protocols to ensure secure updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a static policy file is implemented in the mobile device, then security management is simplified and device stability is maintained, but the device cannot adapt to new security protocols or market conditions after deployment

Engineering Contradiction:
Improveadaptability to new security protocolsVSAvoidsecurity stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transforms the static policy file into a dynamic, updatable component. The policy file can now be remotely updated through push or pull mechanisms, allowing the device to adapt to new security protocols while maintaining version control and backup mechanisms to ensure stability during transitions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by backing up the existing policy file before applying updates and verifying the new policy file's integrity through signature validation. This ensures that if an update fails or is malicious, the device can revert to the previous stable state.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the policy file is made updatable remotely, then the device can accommodate location-based services and updated API rules, but the risk of unauthorized or malicious policy changes increases

Engineering Contradiction:
Improveability to update policy rulesVSAvoidrisk of unauthorized changes
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary verification mechanism using provider-trusted signatures. Before a policy file is applied, it must be validated against a trusted signature, acting as an intermediary security check that prevents unauthorized or malicious policy changes while allowing legitimate updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback through signature verification and update validation mechanisms. The device checks whether incoming policy files have valid signatures and whether they meet security criteria before applying them, providing a feedback loop that prevents unauthorized changes.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the application management system implements dynamic policy updates, then new functionality can be enabled, but the system complexity increases

Engineering Contradiction:
Improvedynamic security managementVSAvoidupdate mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal update mechanism that handles multiple scenarios (push and pull updates, different update sources, various policy file formats) through a unified framework. The application management system uses a common set of procedures for backing up, validating, and applying policy files regardless of the update source or type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of manufacture

If Java ME MIDlets are compiled with static security policies, then deployment is simplified, but the policies cannot be changed or updated in the marketplace

Engineering Contradiction:
Improvedeployment simplicityVSAvoidpolicy update capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the security policy from the compiled application code. Instead of hardcoding static policies into MIDlets, the policy is separated into an external, updatable file that can be independently modified and pushed to devices without requiring application re-compilation or re-deployment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8272030B1Dynamic security management for mobile communications device
Publication Date: 2012.09.18 T MOBILE INNOVATIONS LLC
  • US8272030B1 patent drawing
  • US8272030B1 patent drawing
  • US8272030B1 patent drawing

AI summary

A method for dynamically changing the security protocol in a hand-held mobile communications device within a network includes providing an application management system in a respective mobile communications device for management of memory use and download functions, providing within the mobile communications device an embedded file system that contains executable files that are controlled by the application management system, providing a browser on the mobile communications device so that a user thereof may access websites available on the network, and providing a policy file that includes a set of rules for managing the download of applications from a remote location, the policy file being enabled to receive authorized updates over the network.