Mobile Application Gateway for Secure Device Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices lack the trusted connectivity and security measures of desktop platforms, limiting their use in secure transactions and business environments due to concerns about device misuse and control, especially as they become 'fat' clients with more computational roles.
Innovation Solution
An intermediate gateway is positioned between client devices and mobile application service providers to manage and secure access, enabling device authentication, data encryption, location-based tracking, and remote data erasure, while maintaining version control and providing an audit trail.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile devices are allowed to perform secure transactions and access confidential information, then the computational capabilities and business functionality of mobile devices are improved, but security risks and vulnerability to device misuse increase
Solution Approach 1:
The patent introduces a mobile application gateway as an intermediary component between the mobile device and the mobile application server. This gateway acts as a security mediator that authenticates the mobile device, manages application lifecycle, and controls access to confidential information without requiring the service provider to take direct control of the device. The gateway server mediates all communications and enforces security policies, allowing mobile devices to perform secure transactions while maintaining security through the intermediary layer.
2Reliability
If service providers implement strict device control and management, then security and data protection are improved, but user autonomy and ease of operation deteriorate
Solution Approach 1:
The mobile application gateway serves as an intermediary that enables service providers to enforce security policies and protect data without directly controlling the user's device. The gateway authenticates devices, manages application installation and updates, and controls access to confidential information while leaving the device itself under user control. This intermediary approach maintains user autonomy while ensuring data protection through the gateway's security enforcement.
Solution Approach 2:
The system implements self-service mechanisms where the mobile device automatically authenticates itself with the gateway using device-specific credentials, and the gateway automatically manages application lifecycle events. The device and gateway work together autonomously to enforce security policies without requiring continuous user intervention or direct service provider control, thus maintaining ease of operation while ensuring data protection.
3Reliability
If mobile devices operate as thin clients relying on servers, then security is improved, but computational capability and functionality are limited
Solution Approach 1:
The mobile application gateway acts as an intermediary that enables mobile devices to function as fat clients with enhanced computational capabilities while maintaining security. The gateway provides authentication and security services, allowing mobile devices to perform local computations and access confidential information without compromising security. This intermediary approach bridges the gap between thin-client security and fat-client functionality.
Data Source
AI summary
An intermediate gateway is positioned between a client device and a mobile application service provider. The intermediate gateway can assist in securing and managing accesses from a mobile application on the client device to the mobile application service provider. The intermediate gateway can store a client device identification associated with the client device, which can be used to authenticate the client device. Other parameters can also be used in device authentication.


