Mobile Device Security via Time-Sensitive Identity Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device security methods are inadequate for remote protection, as they lack secure communication, are susceptible to interception, and fail to provide feedback on command execution status, leading to potential loss of information and device functionality.

Innovation Solution

A system that generates a time-sensitive server identity token (TSIT) for secure communication between a server and mobile device, allowing for remote security actions to be processed and executed even when the device is dormant, with status updates and job queue management to ensure effective protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing mobile device security methods are used, then basic security functions are provided, but they lack secure communication and are susceptible to interception

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidinterception vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A server acts as an intermediary between the user and the mobile device. The server receives security commands from the user, processes them through secure authentication protocols (TSIT verification), and executes them on the mobile device. This intermediary architecture prevents direct interception between user and device while maintaining secure communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the mobile device sends status information back to the server after executing security commands. The server verifies execution status and provides confirmation to the user, creating a closed-loop security system that prevents unauthorized actions and ensures command reliability.

Inventive Principle:
Principle #23Feedback

2Reliability

If remote security commands are sent to mobile devices, then protection capabilities are enhanced, but feedback on command execution status is lost

Engineering Contradiction:
Improveremote protection capabilityVSAvoidcommand execution status
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The mobile device automatically sends status information to the server after executing security commands. The server receives, processes, and stores this execution status information, then provides feedback to the user interface. This ensures complete visibility of command execution status without requiring continuous user-device connection.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-establishes communication channels and authentication protocols before security commands are executed. The server maintains session information and device status in advance, enabling immediate feedback on command execution without requiring real-time connection during the actual security operation.

Inventive Principle:
Principle #10Preliminary action

3Speed

If security actions are executed immediately upon receipt, then response time is reduced, but the device must be actively connected

Engineering Contradiction:
Improvesecurity response timeVSAvoiddevice availability requirement
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The mobile device maintains a local queue of security commands and authentication credentials in advance. When commands are received from the server, the device can execute them immediately from the local queue without requiring active connection to the server, enabling fast response even when dormant or offline.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device autonomously executes security commands from its local queue and automatically sends execution status to the server. This self-service capability allows the device to respond to security threats immediately without waiting for server confirmation or requiring continuous connection, while still maintaining centralized control through status reporting.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8510819B2System and method for managing and securing mobile devices
Publication Date: 2013.08.13 ASSURANT INC
  • US8510819B2 patent drawing
  • US8510819B2 patent drawing
  • US8510819B2 patent drawing

AI summary

Systems and methods are provided for securing at least one mobile device. A server includes a controller and a non-transitory computer readable medium storing instructions executable by the controller. The executable instructions are configured to perform a method in which a secure communications session is established with a user and the user is allowed to input a list of a plurality of security actions to be performed at a mobile device associated with the user. A secure communications session is established with the mobile device, and the list of the plurality of security actions is provided to the mobile device simultaneously as a single instruction set.