Network Security Authorization List for Application Data Transfer Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing devices often interrupt user experiences by requiring explicit consent for transferring sensitive information, such as video signals, to external devices, which can be distracting and unnecessary, especially for applications that do not need internet connectivity.
Innovation Solution
Implementing a Network Security Authorization List (NSAL) that determines whether an application can communicate with external devices, allowing sensitive information to be provided without user consent if no connectivity is possible, and prompting consent only when connectivity is available, thus preventing unintended data transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the computing device requires explicit user consent before transferring information to external devices, then information security is improved, but user experience deteriorates due to interruptions and distractions
Solution Approach 1:
The system performs preliminary analysis of the application's network capabilities and authorization status before presenting consent requests to users. By checking the NSAL and determining external device accessibility in advance, the system only prompts for consent when actually necessary, eliminating unnecessary interruptions while maintaining security for applications that can externally communicate.
2Reliability
If the computing device checks network authorization for every application, then information security is improved, but device complexity increases
Solution Approach 1:
The system utilizes the application's own NSAL (Network Security Authorization List) to determine its external communication capabilities. Instead of implementing a complex centralized authorization system, the application self-declares its network access requirements through the NSAL, which the operating system then verifies. This self-service approach maintains security while minimizing system complexity.
3Ease of operation
If the application is allowed to access external devices without user consent, then ease of operation is improved, but information security deteriorates due to potential unintended data transfer
Solution Approach 1:
The operating system acts as an intermediary between the application and external devices. It intercepts the information transfer process and checks the application's NSAL authorization status. Only when the NSAL explicitly authorizes external communication does the operating system allow the transfer to proceed, thereby securing information while maintaining application functionality.
Data Source
AI summary
The technology includes a method for a computing device (console) to restrict transferring information to others on the Internet. A user does not have to explicitly make a choice of having the console restrict the transferring of information to an external computing device because the technology determines that such information cannot be transferred. When an application is loaded, a NSAL is read to determine whether the application will communicate with an external computing device. A NSAL may include authorized network addresses that an application may communicate with when executing on a computing device. When the NSAL does not include any network addresses, there is no need to obtain consent from a user regarding transferring the information externally because the application does not have the capability to do so. When one or more network addresses are includes in a NSAL, consent from a user is obtained.


