Mobile Device Management Segmentation for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to effectively limit access to mobile network devices while allowing local users limited control, and they do not provide different levels of filtering to various devices or connectivity requests on a network.

Innovation Solution

The method involves installing a mobile device management (MDM) system that allows a remote server to manage applications on the device, preventing local users from uninstalling certain applications while allowing them to uninstall others, and implementing a filtering system that applies different levels of filtering based on device signals and behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a remote server is given full control to manage applications on mobile devices, then network security and content filtering are improved, but user control and ease of operation deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoiduser control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments control authority by identifying specific applications as 'protected' versus 'non-protected'. The remote server controls only the protected applications (e.g., filtering, monitoring) while allowing users full control over non-protected applications. This segmentation resolves the contradiction by limiting remote control to only necessary functions for security while preserving user freedom for other applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality levels of control are applied to different applications. Protected applications receive remote server control for security and filtering, while non-protected applications maintain local user control. This local differentiation allows the system to achieve network security where needed without unnecessarily restricting user operation across the entire device.

Inventive Principle:
Principle #3Local quality

2Reliability

If all applications are restricted from local uninstallation, then network security is improved, but device versatility and adaptability deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidapplication management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Applications are segmented into two categories: protected applications that cannot be locally uninstalled (enforcing network security policies) and non-protected applications that can be freely managed by users. This segmentation allows the system to maintain network security for critical applications while preserving user adaptability for other applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically assigns protection status to applications based on their characteristics and network policies. Applications can be added to or removed from the protected category as needed, allowing the system to adapt to changing security requirements while maintaining flexibility in application management.

Inventive Principle:
Principle #15Dynamics

3Reliability

If uniform filtering is applied to all devices and content, then network security is improved, but user experience and adaptability deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidfiltering customization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements local quality by applying different filtering levels to different applications and content types. Critical applications receive strict filtering and monitoring, while less critical applications receive lighter filtering. This differentiated approach maintains network security for essential functions while improving user experience for other applications.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The filtering system dynamically adjusts filtering intensity based on application characteristics, user behavior patterns, and network conditions. The system can escalate filtering for suspicious applications while reducing filtering for trusted applications, providing adaptive security that balances network protection with user convenience.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12321444B2Partial limitation of a mobile network device
Publication Date: 2025.06.03 NETABPARK
  • US12321444B2 patent drawing
  • US12321444B2 patent drawing
  • US12321444B2 patent drawing

AI summary

In some embodiments, a local user is prevented from accessing certain content and/or capabilities of a mobile network device while allowing him control over other functions of the device. For example, an administrator may prevent certain undesired activities. Optionally, by means of an MDM server and/or a remote server, the local user controls other aspects of his device as he wills More specifically but not exclusively the method works on IOS devices. An aspect of some embodiments of the current invention relates to a method of selecting a level of filtering for individual members of a network and/or packets. Optionally, a device pertinent to aggressive filtering may signal to the server and/or other devices will be less aggressively filtered. Alternatively or additionally, a server may determine from certain behaviors and/or packet characteristics that a device and/or packet should be filtered aggressively or not.