Mobile Device Access Control via TrustScore Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise IT departments face challenges in managing and securing diverse mobile devices due to the rapid proliferation of mobile operating systems and platforms, leading to increased security risks and vulnerabilities, as they lack control over OS updates and visibility into device configurations.

Innovation Solution

An enterprise access control system that integrates a TrustService and TrustCatalog to assess and manage mobile device risks by using a TrustScore, which evaluates device configurations and vulnerabilities, and controls access through a blocklist and network traffic filter, ensuring only secure devices can connect to enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises allow diverse mobile devices to access corporate networks, then employee productivity and flexibility improve, but security risks and vulnerability exposure increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security assessments by evaluating device configurations against security policies before granting network access. The TrustScore is calculated in advance based on device attributes, OS versions, and security configurations, allowing enterprises to preemptively identify and block vulnerable devices before they can compromise the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary access control system that sits between mobile devices and enterprise networks. This intermediary evaluates device trustworthiness through configuration assessment and TrustScore calculation, acting as a mediator that allows secure devices to access the network while blocking potentially harmful devices without requiring enterprises to restrict device diversity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If enterprises support multiple mobile platforms, then employee choice and satisfaction improve, but device management complexity increases

Engineering Contradiction:
Improveplatform supportVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control system implements a universal evaluation framework that works across all mobile platforms (iOS, Android, Windows Phone, etc.). The TrustScore calculation methodology and configuration assessment mechanisms are platform-agnostic, allowing enterprises to manage diverse devices through a single unified system rather than requiring separate management approaches for each platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages complexity by transforming device evaluation into a standardized parameter-based approach. Instead of dealing with the inherent complexity of multiple platforms, the system converts diverse device attributes into comparable parameters (OS version, security configurations, update status) that are evaluated against standardized policies, simplifying management through parameter standardization.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If enterprises implement comprehensive device security monitoring, then network security posture improves, but system resource consumption and processing time increase

Engineering Contradiction:
Improvesecurity postureVSAvoidprocessing resource
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements partial monitoring by focusing evaluation efforts on the most critical security parameters rather than analyzing every device attribute in detail. The TrustScore calculation prioritizes high-impact factors such as OS version, security update status, and fundamental configuration settings, providing adequate security monitoring while consuming fewer processing resources than comprehensive analysis of all device parameters.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9706410B2Controlling enterprise access by mobile devices
Publication Date: 2017.07.11 RAPID7 INC
  • US9706410B2 patent drawing
  • US9706410B2 patent drawing
  • US9706410B2 patent drawing

AI summary

A system comprising at least one component running on at least one server and receiving vulnerability data and, for each device of a plurality of devices, device data that includes data of at least one device component. The system includes a trust score corresponding to each device of the plurality of devices and representing a level of security applied to the device. The trust score is generated using a severity of the vulnerability data. The system includes an access control component coupled to the at least one component and controlling access of the plurality of devices to an enterprise using the trust score.