Dynamic Mobile Security State Assessment for Conditional Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile security systems for devices like smartphones are inadequate as they employ an all-or-nothing approach, failing to consider the device's security state and the varying access levels required by service providers, thus limiting users' access to online services and exposing both users and providers to security risks.
Innovation Solution
A system and method that dynamically assesses the security state of mobile communications devices, integrating with service providers to offer customizable access levels based on the device's security state, using local and remote software components to manage secure communications and access requests, and providing a secure platform for trusted transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an all-or-nothing security approach is used to secure mobile devices, then security reliability is improved, but access versatility to online services deteriorates
Solution Approach 1:
The patent segments the all-or-nothing security approach into granular security state parameters (e.g., lock screen status, app permission settings, security patch levels). Each parameter is independently assessed and weighted to determine an overall security state score, enabling differentiated access decisions for different services rather than a single binary security determination.
Solution Approach 2:
The patent applies local quality by allowing different services to have different security requirements and access thresholds. Each service provider can define specific security state parameters and weightings relevant to their needs, enabling tailored security assessments rather than a uniform security policy across all services.
2Reliability
If strict security standards are enforced on mobile devices, then security reliability is improved, but service availability deteriorates
Solution Approach 1:
The patent implements a dynamic security assessment system that continuously monitors security state parameters and adjusts access decisions in real-time. The security state is not static but evolves as users change device configurations or as new security events occur, allowing services to remain available when security requirements are met while maintaining high security standards.
Solution Approach 2:
The patent changes the security assessment from binary (pass/fail) to a multi-parameter scoring system where different security attributes (lock screen, permissions, patches) are evaluated independently and combined with weighted scores. This allows flexible adjustment of security thresholds and parameter weights to balance security requirements with service availability.
3Measurement precision
If comprehensive security monitoring is implemented, then security state assessment accuracy is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service by having the mobile device automatically monitor and report its own security state parameters to service providers. The device maintains local security state information and can independently assess its own security posture, reducing the need for complex external monitoring infrastructure while improving assessment accuracy.
Solution Approach 2:
The patent creates a universal security assessment framework that can be applied across multiple services and device types. The same security state parameters and assessment methodology are used by different service providers, reducing overall system complexity through standardization while maintaining comprehensive monitoring capabilities.
Data Source
AI summary
Methods for assessing the current security state of a mobile communications device to determine access to specific tasks is presented. A security component on a server is configured to receive a request to access services from a mobile communications device for a specific task. The security component on the server is further configured to determine whether a security state for the mobile communications device is acceptable for access to the services. Based on the security state for the mobile device being determined to be acceptable for access to the services, access to the services is granted and a determination is whether the security state is acceptable for access to the specific task requested. Based on the security state being determined to be acceptable for access to the specific task requested, access to the specific task requested is granted by the server security component.


