Side-load Server Identifies Software Source via Authorship Signature

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of mobile devices in business settings and the 'bring your own device' phenomenon have led to challenges in managing and securing mobile applications, particularly due to the risk of malware and undesirable software being installed from untrusted sources, such as peer-to-peer file sharing networks, which existing mobile device management solutions struggle to monitor and control effectively.

Innovation Solution

A system and method for determining the source of software on computing devices, involving a side-load server that matches source identifiers with white and black lists, and communicates with an administrator server to set application states, allowing for blocking or disabling of untrusted software and notifying management systems, thereby enhancing security and control over software installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If mobile devices allow installation of applications from various sources including peer-to-peer networks, then users gain access to more software options and flexibility, but the risk of malware and untrusted software increases

Engineering Contradiction:
Improvesoftware installation flexibilityVSAvoidmalware risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system consisting of a side-load server and administrator server that acts as a mediator between the mobile device and external software sources. This intermediary analyzes source identifiers, maintains white and black lists of trusted sources, and communicates with mobile devices to approve or block software installations. The intermediary resolves the contradiction by enabling flexible software installation from various sources while filtering out malicious content through automated analysis and administrator oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing mobile device management solutions monitor and control software installation, then security is improved, but the complexity of the management system increases

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the mobile device into a managed portion (subject to MDM controls) and an unmanaged portion (where users have autonomy). The side-load server specifically manages side-loaded applications separately from traditionally distributed applications. This segmentation allows the system to enforce security policies on critical components while maintaining user flexibility elsewhere, reducing overall system complexity by avoiding blanket control of all software.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service mechanisms where the side-load server automatically analyzes source identifiers, compares them against maintained white and black lists, and makes approval or blocking decisions without requiring constant administrator intervention. The server autonomously monitors software installations, identifies potential threats, and enforces security policies, reducing management complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If the system blocks or disables untrusted software, then the risk of data loss and malware infiltration is reduced, but the ability to execute only verified applications limits software availability

Engineering Contradiction:
Improvedata loss riskVSAvoidsoftware availability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by maintaining pre-established white lists and black lists of trusted and untrusted software sources before software installation attempts occur. The side-load server continuously monitors and updates these lists based on threat intelligence and administrator input. When software installation is attempted, the system quickly checks the source identifier against these pre-prepared lists, enabling fast approval or blocking decisions without compromising software availability from trusted sources.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9940454B2Determining source of side-loaded software using signature of authorship
Publication Date: 2018.04.10 LOOKOUT INC
  • US9940454B2 patent drawing
  • US9940454B2 patent drawing
  • US9940454B2 patent drawing

AI summary

A source of side-loaded software is determined. An action may be performed in response to the determination of the source. In one case, the handling of an application on a mobile device may be based on whether the source of the application is trusted or untrusted. If a software application being newly-installed on a mobile device of a user is determined to be untrusted, installation or execution is blocked. In one approach, the determination of the source includes: determining whether a first source identifier of a first application matches a white list of source identifiers or a black list of source identifiers; and sending the first source identifier, a first application identifier, and a signature of authorship for the first application to a different computing device.