Security Agent Scanning for Malicious Apps on Lightweight Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Lightweight computing devices, such as wearables and IoT devices, are vulnerable to security threats due to limited communication capabilities and the inability to directly connect to networks, making them susceptible to malicious applications that can capture data or render devices unusable.

Innovation Solution

A security agent is deployed on these devices when paired with a gateway device, which scans for installed applications, identifies potential threats, and remediates them by deleting malicious apps or blocking access to network and input devices, using a reputation service to determine trusted or untrusted applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If lightweight computing devices connect to gateway devices for network access, then network communication capability is improved, but security vulnerability increases due to inability to directly connect to networks and limited communication capabilities

Engineering Contradiction:
Improvenetwork communication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security agent as an intermediary component installed on the lightweight computing device. This agent acts as a local security gateway that mediates between the device's limited communication capabilities and network security requirements. The security agent scans installed applications, identifies malicious components, and remediates threats locally, enabling the device to maintain network communication through the gateway device while independently enforcing security policies without direct network access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If applications are installed on lightweight computing devices through gateway devices, then application functionality is improved, but security risk increases due to potential malicious components in installed applications

Engineering Contradiction:
Improveapplication functionalityVSAvoidmalicious application risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security action by deploying the security agent on the lightweight computing device before malicious applications can cause harm. The security agent proactively scans installed applications, checks them against known malicious patterns, and remediates threats before they can execute harmful operations. This preliminary security measure is performed locally on the device, preventing malicious components from compromising system integrity or stealing data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security agent operates autonomously on the lightweight computing device, performing self-service security functions. It independently scans installed applications, identifies malicious components, and remediates threats without requiring continuous external intervention. The agent uses local resources to maintain security, enabling the device to protect itself against malicious applications while maintaining full application functionality.

Inventive Principle:
Principle #25Self-service

3Reliability

If security scanning is performed on lightweight computing devices, then security threat detection is improved, but device complexity increases due to limited resources on lightweight devices

Engineering Contradiction:
Improvesecurity threat detectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex security scanning and remediation functions from the lightweight computing device's core operations and implements them as a dedicated security agent component. This extracted security subsystem handles all complex threat detection, application scanning, and remediation operations independently. By separating security functions from general device operations, the patent achieves comprehensive security threat detection while minimizing the impact on the device's limited resources and maintaining simplicity in the overall system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10158662B1Scanning for and remediating security risks on lightweight computing devices
Publication Date: 2018.12.18 GEN DIGITAL INC
  • US10158662B1 patent drawing
  • US10158662B1 patent drawing
  • US10158662B1 patent drawing

AI summary

The present disclosure relates to scanning for security threats on a lightweight computing device. An example method generally includes receiving, from a mobile device, a software package including a lightweight computing device security application. A lightweight device transmits, to the mobile device, information identifying at least a first application installed on the lightweight computing device. In response, the lightweight device receives, from the mobile device, information identifying the first application as being a known security threat and remediates a security threat posed by the identified application.