Perimeter-Based Permission Management for Mobile Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing permission settings on devices lack efficient mechanisms to logically separate and securely manage multiple perimeters, such as personal and enterprise data, leading to potential data breaches and access control issues.
Innovation Solution
Implementing a perimeter architecture that uses logical and physical separation of file systems, with each perimeter having its own management policies and encryption, and a centralized policy engine to determine priority rankings for multiple management policies associated with applications, ensuring secure access and separation of resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple perimeters are managed without logical separation, then device complexity is reduced, but security and data protection deteriorate
Solution Approach 1:
The patent implements logical separation of perimeters by creating distinct permission sets for different data types (e.g., personal data, enterprise data, cloud data). Each perimeter has its own management policies and access controls, allowing secure isolation of sensitive information while maintaining a unified permission management framework that resolves the contradiction between security and complexity.
Solution Approach 2:
The patent introduces a centralized permission management system as an intermediary that mediates between multiple perimeters and applications. This intermediary component handles the complexity of policy evaluation and permission resolution, enabling secure multi-perimeter management without requiring complex distributed decision-making logic across individual perimeters.
2Reliability
If strict access controls are enforced between perimeters, then data breach prevention is improved, but application functionality and user experience deteriorate
Solution Approach 1:
The patent applies local quality by allowing different permission settings and access policies for different perimeters and data types. Each perimeter can have customized access controls tailored to its specific security requirements, while applications can request and receive appropriate permissions to access needed resources. This enables strict security where needed while maintaining functional flexibility where required.
Solution Approach 2:
The patent implements dynamic permission management where access rights are not static but can be adjusted based on context, user roles, and policy changes. The system dynamically evaluates permission requests against current policies, allowing applications to function seamlessly while maintaining strong access controls that adapt to changing security requirements without compromising user experience.
3Measurement precision
If multiple management policies are applied to applications, then permission control precision is improved, but policy conflict resolution complexity increases
Solution Approach 1:
The patent merges multiple management policies into a unified permission evaluation framework that processes all applicable policies systematically. By combining policy evaluation in a centralized manner with clear precedence rules and conflict resolution mechanisms, the system achieves precise permission control across multiple perimeters while managing the complexity of policy interaction through structured consolidation rather than distributed decision-making.
Data Source
AI summary
Some aspects of what is described here relate to managing permission settings applied to applications on a mobile device. Multiple management policies that apply to an application associated with a perimeter on a device are identified. A priority ranking for each management policy is determined for the application based on the perimeter with which the application is associated. A permission setting based on the priority rankings is applied to the application.


