Privileged Operation Protection via Location and Connection Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growing number of mobile devices, particularly smartphones, poses a concern for theft and loss, as stolen devices can be easily reset and reconfigured, leading to unauthorized access and potential identity theft or data exposure, with existing security measures failing to effectively deter such incidents.

Innovation Solution

A method that uses GPS location and connection conditions with authorized devices to conditionally enable or disable privileged operations, such as factory reset, ensuring that the device remains secure by preventing unauthorized access and potentially rendering it useless to thieves by overwriting data or disabling functionality if unauthorized attempts are made.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If privileged operations are allowed on mobile devices, then device functionality and user convenience are improved, but device security and data protection deteriorate when devices are stolen

Engineering Contradiction:
Improvedevice functionalityVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system preemptively disables privileged operations by detecting unauthorized location changes before theft can be completed. When the device moves outside the predetermined geographic location, the system automatically prevents factory reset and other privileged operations, countering potential theft attempts before they succeed.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary security layer between the user and privileged operations. This intermediary system monitors device location continuously and acts as a gatekeeper, allowing privileged operations only when the device is at the predetermined location, thereby mediating between user convenience and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-based restrictions are implemented for privileged operations, then device security is improved, but ease of legitimate device recovery deteriorates

Engineering Contradiction:
Improvedevice securityVSAvoiddevice recovery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides multiple authorization pathways for device recovery. Legitimate users can recover devices through three methods: returning to the predetermined location, establishing connection with authorized devices, or providing biometric authentication. This multi-functional approach ensures security while maintaining ease of recovery for legitimate owners.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically changes security parameters based on device context. When the device is at the predetermined location or connected to authorized devices, security restrictions are relaxed to allow privileged operations. When location changes or connections are lost, security parameters tighten to prevent unauthorized operations, thereby adapting security levels to current conditions.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If connection conditions with authorized devices are required, then unauthorized access prevention is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidsecurity system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system automatically manages connection monitoring and authorization verification without requiring user intervention. The device continuously self-monitors for connections to authorized devices and automatically enforces security policies based on connection status, eliminating the need for complex manual security management while maintaining strong unauthorized access prevention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11528280B2Protection of privileged operation access of electronic devices
Publication Date: 2022.12.13 KYNDRYL INC
  • US11528280B2 patent drawing
  • US11528280B2 patent drawing
  • US11528280B2 patent drawing

AI summary

A method for preventing unauthorized access of privileged operations of a first device. The method provides for one or more processors to detect an initiating action of a privileged operation of a first device. The one or more processors receive a current location of the first device. The one or more processors determine whether a pre-determined location matches the current location of the first device. In response to determining the current location of the first device fails to match the predetermined location, the one or more processors determine whether a pre-determined connection condition exists between the first device and an authorized device, and in response to determining an absence of the pre-determined connection condition between the first device and the authorized device, the one or more processors perform a first action disabling the privileged operation of the first device.