Mobile Device Application Enforcing Local Access Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional mobile device management systems lack fine-grained control over access in corporate environments, particularly in sublocations within premises, and expose user location and behavior information to external security servers, posing privacy and regulatory compliance risks.

Innovation Solution

Implementing a system where a mobile device application enforces authorization and additional access security policies locally on personal mobile devices, allowing them to function as access cards, with dynamic sublocation-specific conditions applied without exposing detailed location information to external servers, thereby enhancing privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional mobile device management systems are used to control access in corporate environments, then access control functionality is provided, but fine-grained control over sublocations is lacking and user location information is exposed to external servers

Engineering Contradiction:
Improveaccess control granularityVSAvoiduser location privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts the security policy enforcement functionality from the external server and places it directly on the mobile device through a native application. This allows the device to independently evaluate and enforce sublocation-specific security policies without transmitting detailed location information to external servers, thereby achieving fine-grained access control while preserving user privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device acts as an intermediary between the user and the corporate network infrastructure. The device's native application serves as a local mediator that enforces security policies autonomously, eliminating the need for continuous server verification and preventing exposure of detailed location data while maintaining access control functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Extent of automation

If detailed location information is transmitted to external security servers for access control verification, then centralized security management is achieved, but user privacy and regulatory compliance are compromised

Engineering Contradiction:
Improvecentralized security managementVSAvoidprivacy exposure
Core Design Contradiction:
Extent of automationVSObject-affected harmful factors

Solution Approach 1:

The mobile device performs self-service by locally enforcing security policies through its native application. The device autonomously evaluates security conditions, determines access permissions, and enforces policies without requiring centralized server verification for each location change, thus maintaining security management while protecting user privacy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security management system is segmented into distributed components on each mobile device rather than relying on centralized server control. Each device independently manages its own security policy enforcement, allowing automated security control at the device level while eliminating the need to transmit sensitive location data to external servers.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If mobile devices are allowed to function as access cards without verification, then user convenience is improved, but security risks increase

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity assurance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification by installing and configuring a native security application on the mobile device before it can function as an access card. This pre-configuration ensures that security policies are enforced locally on the device, combining the convenience of mobile access with reliable security verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the access card functionality with the mobile device's existing hardware and operating system through a native application. This integration combines the convenience of using a personal device with the reliability of enforced security policies, creating a unified system that maintains both ease of operation and security assurance.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10783728B1Systems and methods for controlling access
Publication Date: 2020.09.22 GEN DIGITAL INC
  • US10783728B1 patent drawing
  • US10783728B1 patent drawing
  • US10783728B1 patent drawing

AI summary

The disclosed computer-implemented method for controlling access may include (i) installing on a personal mobile device a mobile device application that enforces an authorization security policy for protected premises, (ii) checking, by the mobile device application and in response to installing the mobile device application, whether the personal mobile device satisfies a condition of the authorization security policy, (iii) granting authorization for the personal mobile device to function as an access card based on a result of checking whether the personal mobile device satisfies the condition of the authorization security policy, and (iv) enforcing an additional access security policy on the personal mobile device after granting authorization for the personal mobile device to function as the access card. Various other methods, systems, and computer-readable media are also disclosed.