Embedded Stub for Secured VMM Client Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices face security threats due to malicious applications and the need for secure access to privileged processes, especially for Virtual Mobile Management (VMM) clients, which require 'root' privileges but pose risks if not managed properly, and existing methods are inefficient for remote application management and secure key exchange.

Innovation Solution

An embedded stub with 'root' privilege is integrated into the mobile device's OS to authorize VMM clients and tools, enabling secure access to network interfaces through a Communication Endpoint Gateway (CEG) server using a secured key exchange algorithm, allowing communication via a secure link between the embedded stub and session mediation server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If VMM client is given root privilege to access privileged processes, then access capability is improved, but security risk increases

Engineering Contradiction:
Improveaccess capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an embedded stub as an intermediary component that mediates between the VMM client and the privileged processes. The stub is integrated into the mobile device OS and provides a controlled interface, allowing the VMM client to access privileged functions without obtaining full root privileges. This mediator approach enables the system to grant necessary access capabilities while maintaining security by preventing direct access to root-level processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the privileged access mechanism by separating the VMM client from direct root access. Instead of giving the client full root privileges, the system divides the access right into two parts: the embedded stub that holds the root privilege and the VMM client that uses the stub's interface. This segmentation allows privileged access to be granted selectively and controlledly, reducing the security risk associated with full root access.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If key exchange procedure is implemented for securing access, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-integrating the embedded stub into the mobile device operating system during the device manufacturing process. The stub is pre-configured with the necessary security credentials and communication protocols, eliminating the need for complex runtime key exchange procedures. This preliminary setup simplifies the overall system complexity while maintaining strong security, as the authentication mechanisms are already in place before the VMM client needs to access privileged functions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8782412B2Secured privileged access to an embedded client on a mobile device
Publication Date: 2014.07.15 OMNISSA LLC
  • US8782412B2 patent drawing
  • US8782412B2 patent drawing
  • US8782412B2 patent drawing

AI summary

Disclosed is an apparatus and method to access privileges of Virtual Mobile Management (VMM) client in mobile device. A disclosed example method contains an assigning embedded stub to raise the access privilege of the tool on a mobile device, the embedded stub is integrated by an operating system of the mobile device with “root” privilege, determining via a secured key exchange algorithm that the VMM client and tools is authorized to be installed on the mobile device then, the VMM client and tools of a mobile device are authorized to access a network interface of the Communication Endpoint Gateway (CEG) server, configuring the embedded stub to install the key exchange procedure for the shared certification between the embedded stub, VMM client and the session mediation server, enabling the embedded stub to communicate through a secure link via VMM client.