Evaluation Server Quarantine for Mobile Software Authenticity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device management solutions lack effective mechanisms for continuously monitoring and reporting security threats, and providing real-time security information to users and administrators, which hinders early detection and remediation of security issues.

Innovation Solution

A system and method for security evaluation that involves analyzing software on mobile devices for security risks, receiving data from computing devices, and performing security assessments to identify threats, with actions taken based on the assessment results, such as quarantining malicious software or adjusting access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile device management solutions implement continuous security monitoring and real-time threat detection, then security posture is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity postureVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an evaluation server as an intermediary component that performs security assessments of computing devices. The evaluation server receives data from devices, performs authenticity analysis, determines risk levels, and communicates results back to devices and administrators. This intermediary approach allows continuous security monitoring without requiring complex security systems to be embedded in each mobile device, thus improving security posture while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security monitoring system is segmented into separate functional components: client components running on mobile devices that collect local security data, an evaluation server that performs centralized risk assessment and authenticity analysis, and administrative interfaces for monitoring. This segmentation allows the heavy computational burden of security analysis to be distributed, reducing the complexity burden on individual devices while maintaining comprehensive security monitoring capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security assessments are performed continuously on all computing devices, then early detection of security threats is improved, but loss of time and processing resources increases

Engineering Contradiction:
Improveearly detection capabilityVSAvoidassessment processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The evaluation server dynamically adjusts its assessment frequency and depth based on risk levels. Devices that pass initial assessments are moved to a trusted state with reduced monitoring frequency, while devices showing suspicious behavior trigger more frequent and detailed assessments. This dynamic approach enables early detection of security threats when they occur, while avoiding continuous full-scale assessments that would consume excessive time and resources.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs partial security assessments by focusing on specific risk indicators and device states rather than进行全面 checks continuously. The evaluation server selectively analyzes device data based on the current context, such as focusing on authentication credentials when login attempts are detected, or on device configuration when policy violations are suspected. This partial action approach maintains early detection capability while reducing overall processing time and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12026261B2Quarantine of software by an evaluation server based on authenticity analysis of user device data
Publication Date: 2024.07.02 LOOKOUT INC
  • US12026261B2 patent drawing
  • US12026261B2 patent drawing
  • US12026261B2 patent drawing

AI summary

In one approach, a request for software evaluation is received by an evaluation server from a user device. The request relates to software to be installed on the user device. In response to receiving the request, the evaluation server sends data associated with the software to an authenticity server. The evaluation server receives, from the authenticity server, a result from the evaluation of the software. The evaluation server determines based on the result whether a security threat is associated with the software. In response to determining that there is a security threat, the evaluation server sends a communication to the user device that causes the software to be quarantined.