Dynamic Security Posture via Tailored Trustworthy Spaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device security solutions lack the ability to dynamically adjust security measures based on varying environmental and operational conditions, failing to provide real-time contextual awareness and secure data transfer between devices with different trust levels.

Innovation Solution

The implementation of Tailored Trustworthy Spaces (TTS) using onboard and peripheral sensors to assess the security posture of devices, allowing for dynamic adjustment of application features and data access, and enabling unidirectional secure data transfer between secure and insecure systems through digital credential management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If binary security levels are used in existing MDM systems, then device security management is simplified, but the ability to respond to varying security conditions is limited

Engineering Contradiction:
Improveability to respond to varying security conditionsVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security postures that transition between multiple states (e.g., trusted, suspicious, compromised) based on real-time sensor data and environmental conditions. This replaces static binary security levels with a dynamic framework that automatically adjusts security measures according to current device state and context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters (such as access controls, authentication requirements, and data encryption levels) based on measured device parameters including location, environmental conditions, device state, and user behavior. This enables fine-grained security adaptation without requiring complex manual configuration.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple sensor readings and contextual data are processed in near real-time, then contextual awareness and predictive support are improved, but system processing requirements and complexity increase

Engineering Contradiction:
Improvecontextual awareness precisionVSAvoidsystem processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the security assessment process into distinct modules: sensor data collection, contextual analysis, risk prediction, and security response. Each module processes specific types of data independently, reducing overall processing complexity while maintaining comprehensive contextual awareness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system continuously monitors device state and environmental conditions, using sensor feedback to update security postures in near real-time. This feedback loop enables predictive support by comparing current conditions against historical data and security policies, adjusting security measures proactively rather than reactively.

Inventive Principle:
Principle #23Feedback

3Reliability

If unidirectional data transfer is implemented from secure to insecure systems, then data protection is improved, but system interoperability and flexibility are reduced

Engineering Contradiction:
Improvedata protection reliabilityVSAvoidsystem interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a security gateway or mediator that facilitates controlled data transfer between secure and insecure systems. This intermediary layer maintains unidirectional protection by filtering and validating data before it enters the insecure system, while still enabling necessary interoperability for legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies different security measures to different data and communication channels based on their specific risk characteristics. Critical data receives stronger protection through unidirectional transfer, while less sensitive data can use bidirectional communication, allowing flexible interoperability where appropriate without compromising security where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10185835B2Methods of dynamically securing electronic devices and other communications through environmental and system measurements leveraging tailored trustworthy spaces and continuous authentication
Publication Date: 2019.01.22 INTERNET INFRASTRUCTURE SERVICES CORP
  • US10185835B2 patent drawing
  • US10185835B2 patent drawing
  • US10185835B2 patent drawing

AI summary

This invention is for a system capable of securing one or more fixed or mobile computing device and connected system. Each device is configured to change its operating posture by allowing, limiting, or disallowing access to applications, application features, devices features, data, and other information based on the current Tailored Trustworthy Space (TTS) definitions and rules which provided for various situationally dependent scenarios. Multiple TTS may be defined for a given deployment, each of which specifies one or more sensors and algorithms for combining sensor data from the device, other connected devices, and/or other data sources from which the current TTS is identified. The device further achieves security by loading digital credentials through a unidirectional multidimensional physical representation process which allows for the device to obtain said credentials without the risk of compromising the credential issuing system through the data transfer process. This secure system methodology may be used to create a Mobile Secure Compartmentalized Information Facility (M-SCIF), among other applications.