Owner Application Control via Digital Signature Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Corporate employees often misuse electronic devices provided for work purposes, as users and owners have different perceptions of acceptable use, and existing control methods can be circumvented by deleting or altering policy files, leading to a lack of effective owner control over application installation and device usage.
Innovation Solution
A system and method for inserting and managing owner information and control information on electronic devices, including digital signatures to authenticate and verify the integrity of owner control information, ensuring that only authorized applications are installed and operations are permitted, thereby maintaining owner control even when devices are used outside the corporate network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an owner loads a policy file onto a device to restrict operations or software applications, then owner control over device usage is improved, but the control can be circumvented by users deleting or replacing the policy file with a user policy file having fewer restrictions
Solution Approach 1:
The patent introduces a security mechanism as an intermediary between the owner policy file and the device operations. This mechanism includes a security token embedded in the policy file that contains a cryptographic signature, and a verification module that checks this signature before applying policy restrictions. The intermediary prevents users from simply deleting or replacing policy files, as the security mechanism validates the authenticity and integrity of the policy before execution, thereby resolving the contradiction between owner control reliability and user ability to circumvent control.
2Adaptability or versatility
If a user is provided with an electronic device for work purposes, then device availability to users is improved, but users may misuse the device for personal purposes that conflict with owner policies
Solution Approach 1:
The patent implements preliminary action by embedding security tokens and cryptographic verification mechanisms into the device's operating system before the user receives the device. The owner policy file is pre-configured with digital signatures and security credentials that automatically authenticate and enforce restrictions. This preliminary setup ensures that when users access the device, the security mechanisms are already in place to prevent misuse, while still allowing legitimate work-related personal use that doesn't violate policy constraints.
3Loss of information
If company policies specify acceptable uses of electronic devices, then guidance on proper usage is improved, but policies alone cannot prevent users from violating them
Solution Approach 1:
The patent implements feedback mechanisms through automated monitoring and verification systems. The security mechanism continuously monitors device operations against the owner policy file, and the cryptographic verification system provides feedback by accepting or rejecting policy file modifications. When users attempt to violate policies or modify restricted settings, the system detects these actions and enforces corrections automatically. This closed-loop feedback system transforms static policy documents into dynamic, self-enforcing controls that reliably prevent policy violations.
Data Source
AI summary
Systems and methods of owner application control of an electronic device are provided. Owner application control information is stored on the electronic device and/or one or more remote servers. Owner application control information is consulted to determine if one or more required applications are available for execution on the electronic device. If not, one or more required applications not available are downloaded and installed. This could be in a manner transparent to the user of the electronic device. If one or more required applications are not available on the electronic device, the device can be functionally disabled in whole, or in part, until one or more required applications are available.


