Mobile Permission Classification via Intent Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity of managing permissions on mobile devices is increased by sophisticated applications and third-party libraries, making it difficult for users to determine which permissions to grant or deny, and there is a risk of security threats from hijacked applications requesting spurious permissions.
Innovation Solution
A system and method for classifying permissions on mobile devices by determining the intended use of applications and comparing it to the requested permissions, using intent categories to analyze and report potential security risks to the user through a graphical interface, which can be performed on the device or with a backend server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If applications request multiple permissions to provide sophisticated functionality, then application capability is improved, but user confusion and security risk increase
Solution Approach 1:
The patent segments permission analysis into distinct components: (1) identifying the permission request, (2) determining application intent category, (3) identifying expected permissions for that category, (4) comparing requested permissions against expected permissions, and (5) presenting results to the user. This segmentation transforms a complex, overwhelming decision into manageable, structured steps that users can follow.
Solution Approach 2:
The patent introduces an intermediary security system that acts as a mediator between the application and the user. This security system analyzes permission requests, determines whether they align with expected application behavior, and presents the analysis results to the user. The intermediary translates technical permission requests into understandable security implications, reducing user confusion.
2Reliability
If users are provided with detailed permission information, then security awareness is improved, but information complexity and user burden increase
Solution Approach 1:
The patent applies local quality by providing different levels of information detail to different users based on their needs and the specific context. The security system analyzes each permission request individually and presents only the relevant security implications to each user, rather than overwhelming them with all possible information. This allows users to receive tailored security information that is appropriate to their specific situation.
Solution Approach 2:
The patent performs preliminary analysis of permission requests before presenting information to users. The security system pre-determines the application's intent category, identifies expected permissions, and compares requested permissions against expectations in advance. This preliminary action organizes and structures the information before user presentation, reducing the cognitive burden on users while maintaining security awareness.
3Reliability
If permission analysis is performed by the operating system, then security control is improved, but system complexity and processing overhead increase
Solution Approach 1:
The patent introduces a security system as an intermediary layer between the operating system and applications. This security system handles the complex task of analyzing permission requests, determining application intent, and comparing against expected permissions. The operating system itself remains relatively simple, delegating the sophisticated analysis to the specialized security system, thereby maintaining security control without significantly increasing core OS complexity.
Solution Approach 2:
The security system is designed as a universal component that can analyze permission requests from any application across different categories. Rather than requiring separate analysis mechanisms for each application type, the security system provides multi-functional capability to handle diverse permission scenarios through a unified approach, reducing overall system complexity.
Data Source
AI summary
The disclosed computer-implemented method for classifying permissions on mobile devices may include (1) detecting that an application executing on a mobile device is issuing a request for one or more requested permissions to access one or more components of the mobile device, (2) determining an intended use of the application, (3) performing, through a security system distinct from the application and the operating system, an analysis of the request issued by the application at least in part by determining whether the intended use of the application corresponds to an expected use of the requested permission, and (4) providing, via a graphical user interface, a result of the analysis to an end user of the mobile device that indicates a security implication caused by granting the one or more requested permissions to the application. Various other methods, systems, and computer-readable media are also disclosed.


