On-Device Policy Enforcement for Open Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

It is challenging to control programs and services on devices and networks as they become more open, leading to a loss of control for network providers, with existing solutions imposing either closed devices or networks, which restrict user freedom but do not effectively manage open platforms.

Innovation Solution

Implementing a policy enforcement mechanism that intercepts service requests, checks usage policies, and dynamically presents advertisements or restricts access to ensure compliance, allowing users to receive services at reduced fees while maintaining network security by monitoring and enforcing policies on both devices and networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If closed devices or networks are imposed to control programs and services, then network provider control is improved, but user freedom and device openness deteriorate

Engineering Contradiction:
Improvenetwork provider controlVSAvoiduser freedom
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A policy enforcement program is introduced as an intermediary component installed on user devices. This program acts as a mediator between the network provider's control requirements and the user's device operations, enabling automated policy compliance checking without requiring closed devices or networks. The intermediary validates programs and services against enforced policies while maintaining device openness and user freedom.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The policy enforcement mechanism enables devices to self-monitor and self-regulate their own program and service operations against network policies. Instead of requiring external closed-system control, each device autonomously enforces policies locally, eliminating the need for provider-imposed restrictions while maintaining compliance through self-service validation.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If open devices and networks are allowed to increase user freedom, then device versatility is improved, but network provider control deteriorates

Engineering Contradiction:
Improvedevice opennessVSAvoidprovider control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The policy enforcement program implements continuous feedback mechanisms by monitoring device operations and automatically reporting policy compliance status to the network provider. This feedback loop enables providers to maintain control over open networks by receiving real-time information about program and service operations without requiring closed systems or imposing restrictions on device openness.

Inventive Principle:
Principle #23Feedback

3Reliability

If policy enforcement is implemented to maintain network security, then network integrity is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork integrityVSAvoidenforcement mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex policy enforcement functionality is extracted from the network infrastructure and embedded as a lightweight program component directly on user devices. This extraction distributes the enforcement complexity across individual devices rather than concentrating it in the network, reducing overall system complexity while maintaining network integrity through localized policy validation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9467858B2On device policy enforcement to secure open platform via network and open network
Publication Date: 2016.10.11 ORACLE INT CORP
  • US9467858B2 patent drawing
  • US9467858B2 patent drawing
  • US9467858B2 patent drawing

AI summary

Embodiments of the invention provide methods and systems for using policy enforcement for securing open devices and networks. The method includes accessing, by a policy enforcer, a plurality of policies configured to enforce network integrity and monitoring programs and/or services running on a device. The method further includes based on at least one of the plurality of policies, comparing the programs and/or services running on the device against the programs and/or services allowed by the at least one of the plurality of policies, and based on the comparison, determining that the device is running at least one program and/or service disallowed by the at least one policy. Further, the method includes in response, prohibiting access of the device to the network.