Out-of-band Security Notifications for Mobile Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile applications often cannot display Hypertext Transfer Protocol (HTTP) response messages, making it difficult for users to be notified of security events, such as blocked transactions, leading to poor user experience and increased support calls.

Innovation Solution

A cloud-based security system that authenticates mobile devices, monitors user requests, detects security threats, and sends out-of-band notifications to users via the mobile operating system, providing information about security events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If HTTP response messages are used for security notifications, then web browsers can display security information, but mobile applications cannot display these messages

Engineering Contradiction:
Improvesecurity notification deliveryVSAvoidcompatibility with mobile applications
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent introduces a mobile operating system notification system as an intermediary between the cloud-based security system and mobile applications. This mediator delivers security notifications through the device's native notification framework, which all mobile applications can access, thereby solving the compatibility issue without requiring changes to the security system's core architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from HTTP-based web page notifications (two-dimensional: browser-display model) to a mobile operating system notification dimension (three-dimensional: OS-level notification model). This dimensional shift enables security notifications to be delivered at the operating system level, making them accessible to all applications regardless of their specific rendering capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If mobile applications use HTTP for application logic, then applications can function, but they cannot display HTTP response messages to users

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity event information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The mobile operating system notification system serves as an intermediary layer that decouples the HTTP communication used by applications from the notification delivery mechanism. Applications continue using HTTP for their logic, while the OS notification system handles security event communication, preventing information loss about security events.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system establishes a feedback loop where the cloud-based security system monitors application traffic, detects security events, and sends notifications through the mobile operating system. This feedback mechanism ensures users receive security information even though applications cannot directly display HTTP responses.

Inventive Principle:
Principle #23Feedback

3Reliability

If cloud-based security systems monitor all user requests, then security threats can be detected, but data privacy concerns arise

Engineering Contradiction:
Improvesecurity threat detectionVSAvoiddata privacy risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary security monitoring function from comprehensive data collection. The cloud-based security system monitors specifically for security threats and security events rather than storing all user data, thereby maintaining reliable threat detection while minimizing data privacy risks through selective monitoring.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile operating system notification system acts as an intermediary that processes and delivers security notifications locally on the device. This reduces the amount of sensitive data that needs to be transmitted to and stored in the cloud, as only security event information is processed through the notification system rather than all user request data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9621574B2Out of band end user notification systems and methods for security events related to non-browser mobile applications
Publication Date: 2017.04.11 ZSCALER INC
  • US9621574B2 patent drawing
  • US9621574B2 patent drawing
  • US9621574B2 patent drawing

AI summary

A cloud based security method includes authenticating a mobile device through a cloud based security system; associating the mobile device with a user of the cloud based security system based on the authenticating; monitoring user requests from the mobile device by the cloud based security system; detecting security threats based on the monitoring; and sending an out of band end user notification to the mobile device responsive to detecting a security threat, wherein the out of band end user notification comprises information for the user related to the security threat.