Mobile App Security Management via Risk Profiling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

User devices often have unauthorized applications installed, which can degrade performance and damage both the device and network security, due to untrusted sources and malicious software.

Innovation Solution

A system and method that allows a server device to monitor and control applications on user devices by generating user and application profiles, identifying unauthorized applications, and transmitting notifications for removal or disabling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users install applications from untrusted sources or unknown developers, then application variety and user choice increase, but device security and network security deteriorate

Engineering Contradiction:
Improveapplication varietyVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by obtaining application profiles and identifying unauthorized applications before they can cause harm. The server device proactively scans, analyzes, and flags potentially malicious applications, and can prevent their installation or execution, thereby securing the device before security incidents occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security management system between users and applications. This system acts as a mediator that evaluates applications through profiling, assesses security risks, and controls application installation/execution, thereby protecting devices while still allowing legitimate application variety.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If applications are monitored and controlled by a server device, then device security and network security improve, but system complexity increases

Engineering Contradiction:
Improvedevice securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The security management system provides self-service capabilities by automatically obtaining application profiles, analyzing applications, identifying unauthorized software, and managing application installations without requiring extensive manual configuration or intervention. The system serves itself through automated security assessments and enforcement actions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The server device performs multiple functions within a single integrated system: it obtains application profiles, analyzes application behavior, identifies unauthorized applications, manages installations, and enforces security policies. This multi-functional approach consolidates complexity into a unified security management platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If application profiles and user profiles are obtained and analyzed, then unauthorized applications are identified accurately, but processing time and computational resources increase

Engineering Contradiction:
Improveunauthorized application identification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system applies partial action by focusing security analysis on specific critical aspects of applications rather than examining every detail. It obtains application profiles and analyzes key security-relevant information to identify unauthorized applications, achieving sufficient accuracy without exhaustive processing of all application data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8832840B2Mobile application security and management service
Publication Date: 2014.09.09 VERIZON PATENT & LICENSING INC
  • US8832840B2 patent drawing
  • US8832840B2 patent drawing
  • US8832840B2 patent drawing

AI summary

A system is configured to receive a list of applications installed on a user device; obtain application profiles that identify risk levels associated with the applications; obtain a user profile that identifies a job level, security risk level, or an access level to confidential information associated with the user of the user device; identify a highest risk level authorized for the user device based on whether the job level is greater than a first threshold, the security risk level is greater than a second threshold, or the access level is greater than a third threshold; determine whether any of the risk levels are greater than the highest risk level; and transmit a notification that one of the applications is to be removed from the user device when one of the risk levels, associated with the one of the applications, is greater than the highest risk level.