Mobile Device Function Control via Location-Based Access Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for preventing information leakage from mobile devices, such as those using camera functions, are inefficient in terms of power consumption and communication load, and require cumbersome installations like entrance-exit gates, and do not adequately address leakage through other functions like sound recording or personal access to business applications.
Innovation Solution
A mobile device connected via a network to an information management system that prohibits certain function units from operating unless explicitly allowed based on location information and access permissions, allowing these units to function only for a predetermined duration when in a permission zone.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the camera device is constantly monitored and the imaging enable signal is transmitted at predetermined time intervals, then information leakage through camera can be prevented, but power consumption and communication load increase
Solution Approach 1:
The system dynamically adjusts the monitoring state of the camera device based on location information. When the mobile device enters a prohibition zone, the camera is restricted; when outside, normal operation is allowed. This dynamic control based on real-time location data prevents information leakage while avoiding constant monitoring, thus reducing power consumption and communication load.
2Reliability
If the imaging enable signal is transmitted at predetermined time intervals, then the mobile device location can be detected, but communication load increases
Solution Approach 1:
The system obtains location information in advance through various means (GPS, base station triangulation, Wi-Fi positioning) before the mobile device actually needs to use the camera function. This preliminary location acquisition allows the server to determine whether the device is in a prohibition zone before authorizing camera operation, eliminating the need for continuous periodic signaling and reducing communication load.
3Reliability
If only camera function is monitored, then information leakage through imaging can be prevented, but leakage through other functions like sound recording or applications remains unchecked
Solution Approach 1:
The system extends the prohibition mechanism from solely camera function to multiple function units including sound recording devices, sensors, and various applications. The server comprehensively controls whether these function units can operate based on location information, providing universal protection against information leakage through any of these functions while maintaining system versatility.
4Ease of operation
If company-owned mobile devices are provided to employees for both business and private use, then employee convenience is improved, but information leakage and security risks increase
Solution Approach 1:
The system segments the control of different function units (camera, sound recording, sensors, applications) independently. Each function unit can be selectively restricted or authorized based on its specific security requirements and the employee's location. This segmentation allows employees to use their personal devices conveniently for both business and private purposes while the organization maintains granular control over each function to prevent information leakage.
Data Source
AI summary
A location information acquisition unit (25) acquires location information for pointing a current location. A first transmission unit (21) sends, via a network to a management device (100), access request information used for requesting access to information acquisition units (23), (24), attached with the location information acquired by the location information acquisition unit (25). A first reception unit (22) receives, from the management device (100) via the network, access permission information or access prohibition information in response to the access request information. A control unit (20) leaves the information acquisition units (23), (24) prohibited to operate, if the access permission information has not been received yet by the first reception unit (22), and controls the information acquisition units (23), (24) to operate only for a predetermined duration to acquire information, upon reception of the access permission information by the first reception unit (22).


