Mobile Device Application Execution Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional area-based control systems face challenges in securely managing application execution on mobile devices, particularly in high-security environments, due to the unpredictable nature of third-party applications and the lack of strict verification procedures, which can lead to security violations.

Innovation Solution

A method and system that control application execution in mobile devices by periodically transmitting signals to a base station to receive an application execution policy, which includes an identifier field, network administrator ID, and application execution policy field, allowing only designated applications to be executed in restricted areas, thereby ensuring compliance with security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional area-based control systems use listing-based restrictions to control application execution in restricted areas, then application execution control is achieved, but security cannot be ensured because third-party applications developed without strict verification procedures may violate security policies

Engineering Contradiction:
ImprovesecurityVSAvoidapplication execution control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary verification of applications before allowing execution in restricted areas. The mobile device checks whether an application is designated for execution in a restricted area before permitting it to run, preventing unauthorized applications from executing while allowing authorized ones. This preliminary action ensures security without restricting legitimate application execution.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the mobile device periodically transmits signals to the base station to receive application execution policy, then application execution security is enhanced, but communication overhead and system complexity increase

Engineering Contradiction:
Improveapplication execution securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device periodically transmits signals to the base station to receive updated application execution policies. This periodic action ensures the device has the latest security information without requiring continuous communication, reducing overhead while maintaining security. The device only communicates when policy updates are needed or at scheduled intervals.

Inventive Principle:
Principle #19Periodic action

3Ease of operation

If all applications are allowed to execute without strict verification, then ease of operation is maintained, but security violations occur in high-security environments

Engineering Contradiction:
Improveapplication executionVSAvoidsecurity violations
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary verification mechanism between application installation and execution. The mobile device acts as an intermediary that checks whether an application is designated for execution in the current restricted area before allowing it to run. This intermediary layer maintains ease of operation for authorized applications while blocking unauthorized ones, preventing security violations without user intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2367130B1Method and system for executing applications in a mobile device
Publication Date: 2019.08.14 SAMSUNG ELECTRONICS CO LTD
  • EP2367130B1 patent drawingFigure 1
  • EP2367130B1 patent drawingFigure 2~4
  • EP2367130B1 patent drawingFigure 5

AI summary

A method and system for executing applications in a mobile device including receiving a request for execution of the application; determining whether the mobile device is located in a restricted area where execution of the application is controlled; and determining, when the mobile device is located in a restricted area, whether to execute the application requested for execution, according to a application execution policy that allows for execution of the application in the restricted area.