Security Management Module for Mobile API Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-secure operating systems on mobile devices lack a robust framework for API access control and application management, allowing rogue applications to access sensitive information without security protocols, posing risks to confidential corporate data.

Innovation Solution

Implementing a security management module that provides API access control and application execution control, using a connect module for secure communication and an integration module to interface with the operating system, ensuring only authorized applications access sensitive APIs and execute on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a non-secure operating system is used on mobile devices, then ease of operation and application compatibility are improved, but security control and data protection deteriorate

Engineering Contradiction:
Improveapplication compatibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security management module as an intermediary layer between applications and the operating system. This module intercepts API calls from applications and enforces security policies before allowing access to sensitive resources, thus maintaining application compatibility while adding security control without requiring changes to the underlying non-secure operating system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security management module segments the system into distinct functional layers: application layer, security management layer, and operating system layer. This segmentation allows each layer to operate independently with defined interfaces, enabling security policies to be enforced at the security management layer without affecting application compatibility or operating system functionality.

Inventive Principle:
Principle #1Segmentation

2Reliability

If API access control frameworks are added to non-secure operating systems, then security control is improved, but device complexity increases

Engineering Contradiction:
ImproveAPI access controlVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security management module is designed as a universal component that handles multiple security functions including API access control, application execution control, and data protection through a single integrated framework. This multi-functional approach consolidates security capabilities into one module rather than distributing security functions across multiple components, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

By positioning the security management module as an intermediary that sits between applications and the operating system, the patent avoids the need to modify the existing operating system architecture. The module intercepts and manages API calls through standardized interfaces, adding security control without increasing the complexity of the underlying operating system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If application execution control is implemented, then security management is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveapplication controlVSAvoidapplication installation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security management module implements self-service mechanisms by automatically evaluating applications against security policies and making authorization decisions without requiring user intervention. The module autonomously controls application execution based on predefined security rules, maintaining ease of operation while enforcing security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the security management module continuously monitors application behavior and adjusts access control decisions based on security policy violations or suspicious activities. This automated feedback loop enables dynamic application control without requiring manual user input, preserving ease of operation while enhancing security management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8045958B2System and method for application program operation on a wireless device
Publication Date: 2011.10.25 MALIKIE INNOVATIONS LTD
  • US8045958B2 patent drawing
  • US8045958B2 patent drawing
  • US8045958B2 patent drawing

AI summary

Embodiments described herein address mobile devices with non-secure operating systems that do not provide a sufficient security framework. More particularly, the embodiments described herein provide a set of applications to the device for providing security features to the non-secure operating system.