Secure Area for Apps with Segmented Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices lack efficient access control mechanisms that allow users to restrict access to specific applications without requiring device-level authentication, leading to potential privacy issues and unnecessary authentication burdens.

Innovation Solution

A computing device provides a secure area, such as a folder or screen page, where users can associate and manage access to multiple applications, requiring authentication for access while making these applications invisible outside this area, thereby enabling granular control over app visibility and accessibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-level authentication is required for every app access, then security is improved, but user convenience deteriorates due to repeated authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the device interface into multiple screen areas with different access control levels. A first screen area is accessible without authentication, while a second screen area requires authentication. This segmentation allows frequent apps to be placed in the unrestricted area for convenient access, while sensitive apps remain in the restricted area, resolving the contradiction between security and convenience by spatial separation rather than uniform authentication requirements.

Inventive Principle:
Principle #1Segmentation

2Reliability

If app-specific authentication is implemented for each app, then privacy control is improved, but system complexity increases due to managing multiple credentials

Engineering Contradiction:
Improveprivacy controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication requirements into a single device-level authentication mechanism. Instead of requiring separate credentials for each app, the system implements one authentication process that grants access to the entire second screen area containing multiple authenticated apps. This consolidation maintains privacy control for sensitive apps while significantly reducing the complexity of managing multiple individual app credentials.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If all apps are made visible on the device, then accessibility is improved, but privacy protection deteriorates as sensitive apps become accessible

Engineering Contradiction:
Improveapp accessibilityVSAvoidprivacy protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the display into multiple screen areas where the first area contains frequently used apps accessible without authentication, and the second area contains sensitive apps requiring authentication. This spatial segmentation allows the system to maintain both high accessibility for common apps and strong privacy protection for sensitive apps simultaneously, as each area serves a different accessibility level based on its content requirements.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8881268B2Secure area for apps
Publication Date: 2014.11.04 CHOW EDMOND K
  • US8881268B2 patent drawing
  • US8881268B2 patent drawing
  • US8881268B2 patent drawing

AI summary

An invention for providing privacy and restricted access to functions available on a computing device. According to one embodiment, an area accessible to a user interface on a computing device is provided. A request from a user of the device is accepted, the request for associating with the area one or more functions available on the device. The one or more functions are then associated with the area, and the one or more functions are made invisible. Another request from the user is accepted, the other request for gaining access to the area. Authentication against the user is requested. Access to the one or more functions is granted if the authentication is successful, and access to the one or more functions is not granted if the authentication is not successful.