Proxy-Based Access Control for Mobile Web Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless service providers and device manufacturers face challenges in providing efficient and secure access to mobile web services due to limited resources and risks associated with accessing malicious web content, particularly in mobile devices with limited bandwidth and processing power.

Innovation Solution

A proxy-based access control system is introduced, where a monitoring client designates access policies and manages access to resources, using crowd-sourced information and third-party lists to enforce access controls, thereby reducing exposure to malicious content and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If direct access to web services is allowed on mobile devices, then ease of operation is improved, but security against malicious content deteriorates

Engineering Contradiction:
Improveease of access to web servicesVSAvoidexposure to malicious web content
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a proxy server as an intermediary between mobile devices and web services. The proxy server mediates all web traffic, filtering malicious content before it reaches the mobile device while maintaining seamless access for users. This resolves the contradiction by providing both ease of operation (users access web services normally) and security (proxy filters malicious content).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary security checks and content filtering at the proxy server before traffic reaches the mobile device. By pre-processing and filtering web content upstream, the system prevents malicious content from ever reaching the user's device, thus providing security without affecting the ease of operation.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If resource-intensive security measures are implemented on mobile devices, then security against malicious content is improved, but device performance deteriorates

Engineering Contradiction:
Improveprotection from malicious contentVSAvoiddevice processing power consumption
Core Design Contradiction:
Object-affected harmful factorsVSPower

Solution Approach 1:

The patent extracts the resource-intensive security functions from the mobile device and relocates them to the proxy server. The proxy server handles all complex security scanning, filtering, and content analysis, while the mobile device only needs to route traffic through the proxy. This resolves the contradiction by providing strong security without consuming mobile device processing power or battery life.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The proxy server acts as an intermediary that absorbs the computational burden of security measures. By performing all resource-intensive security operations remotely, the system protects mobile devices from malicious content while avoiding the need for local security processing that would drain device power and processing resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If comprehensive access control policies are enforced, then security is improved, but device complexity increases

Engineering Contradiction:
Improverisk reduction from malicious contentVSAvoidaccess control system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The proxy server serves as an intermediary that implements all complex access control policies and security rules. The mobile device simply connects to the proxy server, which handles authentication, authorization, content filtering, and policy enforcement. This resolves the contradiction by providing comprehensive security controls without adding complexity to the mobile device itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts complex access control functionality from the mobile device and consolidates it at the proxy server. All policy management, rule enforcement, and security configuration are centralized remotely, leaving the mobile device with minimal complexity while still providing comprehensive protection against malicious content.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9838392B2Method and apparatus for providing proxy-based access controls
Publication Date: 2017.12.05 NOKIA TECHNOLOGIES OY
  • US9838392B2 patent drawing
  • US9838392B2 patent drawing
  • US9838392B2 patent drawing

AI summary

An approach is provided for proxy-based access controls. A proxy platform causes, at least in part, designation of at least one monitoring client of a proxy server. The proxy platform receives an input for associating one or more accessing clients with the at least one monitoring client. The at least one monitoring client manages access to one or more resources of the proxy server by the one or more accessing clients.