Automated Mobile App Certification Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing mobile applications on devices used for work purposes due to the sheer number of applications released daily, making manual white-listing and black-listing approaches impractical, as they become outdated and overly restrictive, leading to security threats and reduced business value.
Innovation Solution
A platform that applies automatic certification and categorization of mobile applications through third-party certification and automated static and dynamic testing, providing a ranked list of secure and privacy-aware applications for users to select from, thus reducing the need for explicit white-lists and black-lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual white-listing or black-listing approaches are used to control mobile applications, then security control is achieved, but the approach becomes outdated and overly restrictive due to the sheer number of applications released daily
Solution Approach 1:
The patent implements automated certification services that self-evaluate mobile applications against security criteria without requiring manual review. The system automatically certifies applications as secure or insecure based on predefined security standards, enabling the enterprise system to serve itself in the certification process and adapt to new applications without manual intervention
Solution Approach 2:
The patent transforms the security control mechanism from static manual lists to dynamic automated certification parameters. By changing the control parameter from explicit allow/deny lists to automated security assessment criteria, the system can adapt to new applications automatically while maintaining security standards
2Reliability
If manual white-listing or black-listing approaches are used to control mobile applications, then security control is achieved, but the effort for updating lists is extremely high
Solution Approach 1:
The automated certification service continuously and automatically evaluates new mobile applications against security criteria without requiring manual updates. The system performs self-service certification by automatically assessing applications, generating certification results, and maintaining the certification database, thereby eliminating the time-consuming manual update process
Solution Approach 2:
The patent implements continuous automated certification that operates ongoing without interruption. The system continuously monitors, certifies, and updates the status of mobile applications in real-time, ensuring security control is maintained without periodic manual intervention or list updates
3Adaptability or versatility
If automated certification and categorization is implemented, then application availability is improved, but system complexity increases
Solution Approach 1:
The patent segments the certification system into distinct functional modules: certification service, testing module, database module, and interface module. Each module performs a specific function (certification assessment, security testing, data storage, user interaction), reducing overall system complexity by dividing the complex certification process into manageable, independent components
Solution Approach 2:
The patent introduces a certification database as an intermediary layer between the certification service and the mobile device management system. This intermediary stores certification results and provides them on-demand, simplifying the interaction between the automated certification process and the application deployment system
Data Source
AI summary
Implementations for managing mobile devices associated with enterprise operations include actions of receiving a request to access information regarding a mobile application for download to and installation on a mobile device of a user, the request including an enterprise identifier, receiving a tenant-specific configuration based on the identifier, the tenant-specific configuration including criteria for mobile applications to be available for download to and installation on mobile devices associated with the enterprise, transmitting a request for a list of available mobile applications to an application and certification database, the request including the tenant-specific configuration, receiving the list of available mobile applications, which includes a subset of mobile applications of a superset of mobile applications, the subset of mobile applications being provided based on the tenant-specific configuration, and providing graphical representations of each mobile application in the list of available mobile applications for display to the user.


