Package Identifier Assignment for Application Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging to reliably identify and manage applications and their resources on computing devices, which hinders various operations that depend on application identities and resource access control.

Innovation Solution

Assigning a package identifier to each application package and using it to create security identifiers for processes, allowing controlled access to resources based on the package identifier, ensuring only authorized processes can access designated areas and communicate effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple applications are installed and run concurrently on a computing device, then the functionality and productivity of the system are improved, but the difficulty of reliably identifying applications and their resources increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidapplication identification
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the identification system by assigning unique package identifiers to each application package and creating distinct security identifiers for each process. This segmentation allows the system to track and identify individual applications and their resources even when multiple applications run concurrently, resolving the identification difficulty while maintaining system productivity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control to resources is implemented based on application identities, then the security and reliability of resource access are improved, but the complexity of the system increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces package identifiers and security identifiers as intermediary elements that mediate between application processes and system resources. These identifiers serve as a simplified interface for access control, allowing the system to enforce security policies without requiring complex direct tracking of application identities and their resource interactions, thus improving reliability while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If package identifiers are assigned to all processes and used for access control, then the precision of resource access control is improved, but the computational overhead and system complexity increase

Engineering Contradiction:
Improveaccess control precisionVSAvoididentifier management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates security identifiers as copies or derivatives of package identifiers and assigns them to processes. This copying approach allows the system to maintain precise access control information without requiring all processes to directly manage or store complete package identifier information, reducing the computational overhead and complexity of identifier management while preserving access control precision.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9679130B2Pervasive package identifiers
Publication Date: 2017.06.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9679130B2 patent drawing
  • US9679130B2 patent drawing
  • US9679130B2 patent drawing

AI summary

A package identifier for a package from which an application is installed on a computing device is obtained. The package identifier is assigned to each of one or more processes created for running the application and, for each of the one or more processes, whether the process is permitted to access a resource of the computing device is determined based at least in part on the package identifier.