Operating System State Transition for Controlled Application Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication terminals lack flexibility in managing access to personal data when lending the device, as they either provide full access or require predefined access rights, making it difficult to temporarily restrict access to specific applications and data.

Innovation Solution

A portable computer terminal with an operating system that switches between normal and restricted states based on user commands, allowing controlled access to applications and data, with access conditions determined dynamically, enabling users to limit access without predefining rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the user provides full access to all personal data when lending the terminal, then the borrower can use any application and resource, but the user's privacy and security are compromised

Engineering Contradiction:
Improveaccess flexibilityVSAvoidprivacy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments access rights by introducing a restricted state where only specific applications are accessible rather than all applications. The system divides the set of applications into accessible and non-accessible subsets, allowing selective sharing of functionality while protecting privacy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes access rights dynamic by allowing the user to define which applications are accessible when transitioning to the restricted state, rather than having fixed predefined access rights. The access conditions are determined at the moment of state transition based on the first command, enabling flexible adaptation to different lending scenarios.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If the user uses a multi-session operating system to manage access rights, then access control is improved, but the operating system load and complexity increase

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the access control functionality from the operating system core by implementing it as a state management mechanism at the application layer. Instead of requiring a full multi-session OS with user management infrastructure, the invention implements restricted access through a simplified state transition system that works within the existing OS framework.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter of access control from a structural OS feature to a runtime state parameter. The system transitions between a first state (full access) and a second state (restricted access), where access rights are defined by parameters set at state transition rather than by OS architecture.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If the user deletes login information to allow someone else to log in, then the borrower can access applications requiring authentication, but the user must re-enter credentials after returning the phone

Engineering Contradiction:
Improvelending convenienceVSAvoidtime to re-enter credentials
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-defining the set of accessible applications when transitioning to the restricted state. The system prepares the access configuration in advance based on the user's selection of which applications to make accessible, so that when the borrower uses the terminal, the appropriate applications are already configured for use without requiring credential manipulation.

Inventive Principle:
Principle #10Preliminary action

4Object-affected harmful factors

If the user defines access rights in advance using a multi-session system or private memory sections, then security is improved, but flexibility in configuring access rights is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaccess configuration flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent makes access rights dynamic by allowing the user to define which applications are accessible when transitioning to the restricted state, rather than having fixed predefined access rights. The access conditions are determined at the moment of state transition based on the first command, enabling flexible adaptation to different lending scenarios while maintaining security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2605496B1Access restriction to the resources of a terminal
Publication Date: 2020.04.08 IDEMIA FRANCE SAS
  • EP2605496B1 patent drawingFigure 1~3

AI summary

The terminal (1) has an operating system (OS) configured to switch from a first state to a second state in response to a first command from a user and switch from the second state to the first state in response to a second command from the user. The system causes an execution of an application selected from a set of applications (A1-A3) in an interactive manner, in the first state. The system causes execution of one of the applications in compliance with an access condition in the second state, where the condition is determined as a function of the first command. An independent claim is also included for a method for operating an operating system of a portable computer terminal.