Dynamic Security Profiles for Mobile Device Identity Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for mobile devices face challenges in efficiently and flexibly securing data across varying operating environments due to complexities in supporting multiple hardware and software platforms, limited memory, and processing resources, leading to a need for an efficient and flexible system for enforcing security policies.

Innovation Solution

A system and method that dynamically generates security profiles based on unique identity statuses of mobile devices, using a security policy engine to enforce real-time security and data protection policies across mobile devices and computing nodes, incorporating static and dynamic attributes for platform-independent security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security software is deployed across multiple mobile device platforms, then security coverage is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security profile format that can be deployed across multiple mobile device platforms (Palm OS, Windows CE, Symbian, etc.) without requiring platform-specific security software. The security profile contains platform-independent security parameters that can be enforced on any mobile device, eliminating the need for separate security solutions for each platform and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates a virtual copy of the security policy from the desktop environment and transfers it to the mobile device in the form of a security profile. This copied security configuration allows the mobile device to enforce the same security policies without requiring the complex security software infrastructure present on desktop systems, thereby reducing device complexity while maintaining security coverage.

Inventive Principle:
Principle #26Copying

2Reliability

If comprehensive security policies are enforced on mobile devices, then data security is improved, but available memory and processing resources are consumed

Engineering Contradiction:
Improvedata securityVSAvoidmemory resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential security parameters from the comprehensive desktop security policy and places them in a compact security profile on the mobile device. By taking out only the critical security enforcement elements rather than implementing the entire security suite, the system maintains data security while minimizing memory and processing resource consumption on resource-constrained mobile devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security policy is segmented into a compact profile structure that separates security parameters from the full security software infrastructure. The security profile contains only the necessary configuration data (encryption requirements, access control policies, etc.) that can be stored in limited mobile device memory, while the heavy lifting of security enforcement is distributed to the device's existing security mechanisms rather than requiring additional resource-intensive software components.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If platform-specific security solutions are developed for each mobile device type, then security adaptability is improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
Improveplatform compatibilityVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a single universal security profile format that works across multiple mobile device platforms including Palm OS, Windows CE, Symbian, and others. The security profile uses platform-independent parameters that can be interpreted and enforced by security agents on different platforms, eliminating the need to develop and deploy separate security solutions for each device type and significantly simplifying the deployment process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8635661B2System and method for enforcing a security policy on mobile devices using dynamically generated security profiles
Publication Date: 2014.01.21 TRUST DIGITAL
  • US8635661B2 patent drawing
  • US8635661B2 patent drawing
  • US8635661B2 patent drawing

AI summary

A system and method for enforcing security parameters that collects information from a source relating to a mobile device (104). Based on the collected information, an identity status for the mobile device (104) is determined that uniquely identifies the mobile device (104) and distinguishes it from other mobile devices. The identity status of the mobile device (104) can be determined when the mobile device (104) connects to a computing node source (102) or when the mobile device (104) accesses a resource (124) within the network. A security profile based on the identity status of the mobile device (104) is generated and the security profile is applied to the mobile device (104).