Software Installation Control via Risk Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often unknowingly install unauthorized software applications on their devices, posing security risks as critical security mechanisms struggle to differentiate between legitimate and malicious applications, leading to potential data misuse by hackers.

Innovation Solution

A method and system that automatically detect software application installations, assess their danger level based on collected and pre-stored data, and allow or block installations based on a threshold, providing users with control and visibility through a network service that monitors and verifies installations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automatic application installation control is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary application installation control mechanism that acts as a mediator between the user device and incoming software applications. This control mechanism analyzes application information, assesses potential risks, and makes installation decisions without requiring complex user intervention or fundamentally altering the device architecture, thereby improving security while maintaining manageable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If user control over installations is enhanced, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service mechanism where the application installation control system automatically performs risk assessment, information collection, and installation decision-making processes. The system serves itself by autonomously evaluating applications against security criteria and managing the installation workflow, thereby enhancing security control without burdening users with complex operational tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the control system continuously monitors application behavior, user interactions, and installation outcomes. This feedback loop enables the system to learn from past decisions, adjust security policies dynamically, and provide users with informed recommendations, thereby strengthening security while maintaining user-friendly operation through intelligent automation.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If application information collection is expanded, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvedanger level assessment accuracyVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the application information collection process into distinct modules: basic information gathering, detailed analysis, risk assessment, and decision-making. Each segment handles specific aspects of application evaluation independently, allowing the system to collect comprehensive information for accurate danger level assessment while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8413135B2Methods, systems, and computer program products for controlling software application installations
Publication Date: 2013.04.02 AT&T INTELLECTUAL PROPERTY I L P
  • US8413135B2 patent drawing
  • US8413135B2 patent drawing
  • US8413135B2 patent drawing

AI summary

Methods, systems, and computer program products that automatically control the installation of software applications on a device are provided. The installation of a software application on a device is detected. The installation is temporarily halted and information about the detected software application installation is collected. A danger level of the detected software application is assessed based upon the collected information. Installation of the detected software application is allowed to continue if the assessed danger level is below a threshold level and installation of the detected software application is terminated if the assessed danger level is above the threshold level.