Mobile Software Source Trust Determination via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing trend of mobile devices accessing applications from various sources, including untrusted channels like BitTorrent, poses a risk of malware installation, as existing mobile device management solutions lack effective mechanisms to differentiate between trusted and untrusted software sources, leading to potential data security breaches.

Innovation Solution

A system and method that determine the source of software on mobile devices by matching source identifiers with white and black lists, involving a side-load server and an administrator server to set application states as trusted or untrusted, enabling blocking or removal of untrusted software and notifying administrators of potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices allow applications to be installed from various sources including untrusted channels, then software availability and user flexibility improve, but security risk increases due to potential malware installation

Engineering Contradiction:
Improvesoftware source accessibilityVSAvoidmalware installation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an administrator server as an intermediary between the mobile device and software sources. The administrator server receives source identifiers from the mobile device, determines whether they are trusted or untrusted, and communicates the determination back to the mobile device. This intermediary mechanism enables the system to maintain flexible software installation capabilities while adding a security layer that filters out untrusted sources, thus resolving the contradiction between accessibility and security risk

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback loop where the mobile device sends source identifiers to the administrator server, receives trust determination results, and then enforces appropriate installation policies. This feedback mechanism allows the system to dynamically adjust software installation behavior based on real-time trust assessments, enabling both flexible access to diverse software sources and proactive prevention of malware installation through continuous security verification

Inventive Principle:
Principle #23Feedback

2Reliability

If mobile devices block applications from untrusted sources, then security improves, but software availability decreases

Engineering Contradiction:
Improvedevice securityVSAvoidsoftware installation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary trust determination actions before allowing software installation. The administrator server assesses source identifiers in advance and communicates trust status to the mobile device beforehand. This preliminary action enables the device to maintain high security by blocking untrusted sources while preserving software availability for trusted sources, as the trust assessment is completed prior to installation decisions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different trust levels and installation policies to different software sources based on their individual assessments. Rather than applying a blanket block to all external sources, the system evaluates each source identifier individually and applies localized trust determinations. This allows the device to maintain security through selective blocking while preserving software availability from verified trusted sources, thus resolving the contradiction between security and accessibility

Inventive Principle:
Principle #3Local quality

3Reliability

If the system implements source identification and trust determination mechanisms, then security management improves, but system complexity increases

Engineering Contradiction:
Improvesoftware source verificationVSAvoidsecurity management architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex trust determination logic from the mobile device and places it in a separate administrator server. The mobile device only needs to send source identifiers and receive simple trust determination results, while the administrator server handles the complex analysis of source identifiers against trusted and untrusted lists. This extraction reduces the complexity burden on the mobile device while maintaining comprehensive security verification capabilities through the dedicated administrator server

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If the system monitors and evaluates all application sources, then detection accuracy improves, but processing time increases

Engineering Contradiction:
Improvesource trust determination accuracyVSAvoidinstallation evaluation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The administrator server performs preliminary trust determination actions in advance, maintaining updated lists of trusted and untrusted source identifiers. When a mobile device requests evaluation, the server quickly compares the source identifier against these pre-prepared lists rather than performing comprehensive analysis from scratch. This preliminary action enables accurate trust determination while minimizing processing time, as the evaluation leverages pre-computed trust data

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12120519B2Determining a security state based on communication with an authenticity server
Publication Date: 2024.10.15 LOOKOUT INC
  • US12120519B2 patent drawing
  • US12120519B2 patent drawing
  • US12120519B2 patent drawing

AI summary

For increased security, a source is determined for software to be installed on a computing device. In one approach, a side-load server receives, from a mobile device, data regarding an application to be installed on the mobile device. The server determines a source of the application, then sends, to an authenticity server, data regarding the source. The server receives, from the authenticity server, a first state designation for the application. In response to receiving the first state designation, the server sets a second state designation, and sends the second state designation to the mobile device (e.g., to permit or block installation of the application).