Selective Root Access via Native Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling devices restrict user privileges, preventing full control over device elements, which hinders the installation and operation of applications requiring root access, while manufacturers aim to prevent rooting to maintain security.

Innovation Solution

An information handling device is configured to grant selective root access to protected system elements, allowing applications to perform root privilege tasks on a secure or unrooted device through a pre-built native service with an associated API, determining the application's system privileges and executing privileged code accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user privileges are restricted to protect device security, then device integrity and security are improved, but application functionality requiring root access deteriorates

Engineering Contradiction:
Improvedevice securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments root access privileges into granular, application-specific permissions. Instead of providing full root access or none at all, the system divides privileges into discrete units that can be selectively granted to individual applications based on their specific needs, resolving the contradiction between security and functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a privilege management system as an intermediary layer between applications and device resources. This mediator evaluates application requests, verifies developer credentials, and grants appropriate levels of access without requiring full root privileges, thereby maintaining security while enabling necessary functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If full root access is granted to applications, then application control and functionality are improved, but device security and integrity deteriorate

Engineering Contradiction:
Improveapplication controlVSAvoiddevice security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by granting different privilege levels to different applications based on their specific requirements and trustworthiness. Each application receives the minimum necessary privileges for its function rather than universal root access, allowing high control for legitimate applications while maintaining security through restricted access for others.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of access privileges from a binary state (root or non-root) to a multi-level hierarchy. By adjusting privilege parameters granularly, the system can provide applications with precisely the level of control they need while preventing excessive access that would compromise security.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If selective privilege system is implemented, then application installation flexibility is improved, but system complexity increases

Engineering Contradiction:
Improveapplication installation flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-establishing a framework of privilege levels and access rules before applications are installed. The system pre-configures the privilege management infrastructure, credential verification mechanisms, and permission granting protocols, which simplifies the actual application installation process rather than increasing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9881151B2Providing selective system privileges on an information handling device
Publication Date: 2018.01.30 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US9881151B2 patent drawing
  • US9881151B2 patent drawing
  • US9881151B2 patent drawing

AI summary

Devices, methods and products are described that provide for selective system or root level access for applications on an information handling device. One aspect provides a method comprising determining whether an application has system privileges on an information handling device; and executing privileged code from the application on said information handling device responsive to determining that the application has system privileges through one or more native services operating on said information handling device. Other aspects and embodiments are also described herein.