Restricted Execution Modes for Secure Mobile Device Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Parents face challenges in allowing children to access mobile device features for entertainment without compromising sensitive personal or corporate data, as existing technologies lack effective mechanisms to restrict access to sensitive content without password authentication.
Innovation Solution
Implementing restricted execution modes on mobile devices, which activate a shared space user interface without requiring a PIN code, allowing limited access to device applications while restricting access to sensitive data through security capabilities and origin checks, ensuring only authorized applications can access protected resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a PIN code or authentication credential is required to access device features, then data security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent segments device access into multiple modes: a restricted execution mode accessible without authentication that allows only specific pre-designated applications, and a full access mode requiring PIN authentication. This segmentation resolves the contradiction by providing both easy access (for children's entertainment apps) and security (for sensitive data and apps).
Solution Approach 2:
The patent applies local quality by creating a shared space with specific properties different from the main device environment. Within this shared space, only certain applications have access rights to device content, while other applications are restricted. This localized approach allows children to easily access entertainment apps without compromising overall device security.
2Adaptability or versatility
If all device applications are allowed to access device content, then adaptability is improved, but data security deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism - the restricted execution service - that mediates between applications and device content. This service checks whether the current execution mode is restricted and whether the application has permission to access device content, thereby allowing adaptability for authorized apps while maintaining security through the intermediary's control.
Solution Approach 2:
The patent implements dynamic access control where application permissions change based on the execution mode. In restricted mode, only pre-designated applications can access device content; in full access mode, all applications have permission. This dynamic approach balances adaptability and security based on the current operational context.
Data Source
AI summary
In embodiments of restricted execution modes, a mobile device can display a device lock screen on an integrated display device, and transition from the device lock screen to display a shared space user interface of a shared space. The transition to display the shared space user interface is without receiving a PIN code entered on the device lock screen. The mobile device implements a restricted execution service that is implemented to activate a restricted execution mode of the mobile device, and restrict access of a device application to device content while the restricted execution mode is activated. The restricted execution service can also allow a shared device application that is included in the shared space access to the device content while the restricted execution mode is activated.


