Mobile Device TrustScore Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise IT departments face challenges in managing and securing diverse mobile devices brought into the workplace due to the lack of control over OS updates, leading to increased security risks and vulnerabilities across various mobile platforms.

Innovation Solution

An enterprise access control system that integrates a TrustService and TrustCatalog to provide real-time visibility and control over mobile devices, using TrustScores to assess and manage risks by tracking vulnerabilities and automating access control decisions based on device configurations and OS updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises allow personal mobile devices to be integrated with enterprise networks for work activities, then employee productivity and flexibility improve, but security risks and vulnerability exposure increase

Engineering Contradiction:
Improveemployee productivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system that sits between mobile devices and enterprise networks, acting as a security gateway. This intermediary assesses device trustworthiness through vulnerability scanning and risk evaluation, then mediates access decisions. Devices can maintain productivity benefits while the intermediary filters out security threats before they reach enterprise resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops where device vulnerability states are constantly monitored and assessed. Trust scores are dynamically updated based on vulnerability scans, OS update status, and security configuration changes. This feedback mechanism allows the system to adapt access controls in real-time based on current device security postures.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If enterprises support multiple mobile device platforms and types, then device choice flexibility improves, but device complexity and management difficulty increase

Engineering Contradiction:
Improvedevice choice flexibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal assessment framework that works across all mobile device platforms (iOS, Android, Windows Phone, etc.) and device types. The vulnerability scanning and trust evaluation mechanisms are platform-agnostic, applying the same security criteria universally. This allows enterprises to support diverse devices without creating separate management systems for each platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system evaluates devices based on configurable security parameters such as OS version, vulnerability presence, update status, and security configuration settings. By making these parameters adjustable, the system can adapt its assessment criteria to match enterprise security requirements across different device types, simplifying management through standardized parameter-based control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If enterprises implement comprehensive device security monitoring and control, then security posture improves, but loss of information about device visibility and status increases

Engineering Contradiction:
Improvesecurity postureVSAvoiddevice visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system continuously collects and processes feedback about device security states through vulnerability scans, OS update checks, and configuration assessments. This feedback provides real-time visibility into device trustworthiness, maintaining comprehensive information about device status while enabling security control. The TrustScore mechanism synthesizes this feedback into actionable visibility data.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual device inventory and status tracking mechanisms with automated scanning and assessment systems. Instead of relying on administrative records or device registration processes, the system automatically discovers devices on the network, scans for vulnerabilities, and evaluates security postures. This substitution eliminates information loss associated with manual tracking while maintaining security control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Stability of the object's composition

If mobile operating systems use manufacturer and carrier controlled update processes, then device compatibility and stability improve, but update speed and vulnerability patching increase

Engineering Contradiction:
Improvedevice stabilityVSAvoidupdate time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system performs preliminary vulnerability assessments and risk evaluations to identify devices that are vulnerable to known threats. By proactively identifying at-risk devices before exploits are deployed, the system can prioritize security updates and patching efforts. This preliminary action allows enterprises to address critical vulnerabilities faster while maintaining the stability benefits of manufacturer-controlled update processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides continuous feedback about device vulnerability states and update statuses, enabling enterprises to monitor and accelerate the patching process. When vulnerability scans identify devices running outdated OS versions with known vulnerabilities, the system can trigger alerts and notifications to prompt faster update deployment, reducing the time window for exploitation while preserving update stability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10198581B2Controlling enterprise access by mobile devices
Publication Date: 2019.02.05 RAPID7 INC
  • US10198581B2 patent drawing
  • US10198581B2 patent drawing
  • US10198581B2 patent drawing

AI summary

A system comprising at least one component running on at least one server and receiving vulnerability data and, for each device of a plurality of devices, device data that includes data of at least one device component. The system includes a trust score corresponding to each device of the plurality of devices and representing a level of security applied to the device. The trust score is generated using a severity of the vulnerability data. The system includes an access control component coupled to the at least one component and controlling access of the plurality of devices to an enterprise using the trust score.