Mobile Device Security Mechanism for Database Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, it is challenging to securely manage access to database records on mobile devices, particularly when third-party information is required, as these devices are vulnerable to theft or unauthorized access due to their mobility and small form factor.

Innovation Solution

Implementing a security mechanism on mobile devices that activates upon performing actions on database records, such as requiring alpha-numeric, graphical, or biometric passwords, to restrict access and ensure data security, even when the device is used by unauthorized users for tasks like obtaining signatures from customers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security mechanism is implemented on mobile devices to restrict access to database records, then data security is improved, but device usability and ease of operation deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system establishes a security context in advance by detecting when a mobile device is used in an untrusted environment (such as when another user possesses the device). This preliminary detection and context establishment enables automatic security measures to be activated before any database access occurs, ensuring data protection without requiring manual security interventions during normal operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security context as an intermediary mechanism that mediates between the mobile device and database access. This security context acts as a gatekeeper that evaluates the trustworthiness of the device environment and controls whether database operations can proceed, thereby providing security without directly blocking legitimate users from accessing data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security mechanisms are activated on mobile devices, then unauthorized access is prevented, but operational complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device performs self-assessment of its security context by automatically detecting whether it is being used in an untrusted environment. The device independently determines when security measures should be activated without requiring manual configuration or complex operational procedures from the user, thereby simplifying the overall system operation while maintaining strong access control

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures security contexts and access control policies before actual database operations occur. By establishing these security frameworks in advance, the system avoids the need for complex real-time security decisions during data access, thereby reducing operational complexity while maintaining robust unauthorized access prevention

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9544307B2Providing a security mechanism on a mobile device
Publication Date: 2017.01.10 SALESFORCE INC
  • US9544307B2 patent drawing
  • US9544307B2 patent drawing
  • US9544307B2 patent drawing

AI summary

Disclosed are methods, apparatus, systems, and computer program products for providing a security mechanism on a mobile device before performing an action on a database record in an on-demand database service. The action to be performed can be identified for requesting third-party information. When the third-party information is provided by a user who does not have authorization to access data locally or remotely from the mobile device, the action is performed on the database record but the security mechanism can be activated for display on the mobile device. When the security mechanism is traversed, the mobile device can be unlocked and a user can access the database record in the on-demand database service.