Tiered Device Access via Dynamic Unlock Mechanisms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computing devices either remain locked with no access or fully unlocked, exposing sensitive content when shared, with static containerization methods being cumbersome in device sharing scenarios.
Innovation Solution
Implementing a system with multiple unlock interfaces (e.g., voice command, gesture, PIN) that dynamically adjust access levels based on user input, using a processor with a request module and policy module to select appropriate security levels and authenticate users, allowing for tiered access to content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the device is fully unlocked to allow access, then ease of operation is improved, but security is worsened as sensitive content becomes accessible
Solution Approach 1:
The patent segments device access into multiple levels (first level and second level access) corresponding to different unlock mechanisms. The first unlock mechanism provides access to a first set of applications, while the second unlock mechanism provides access to a second set of applications. This segmentation allows the device to be unlocked for general use while protecting sensitive content behind an additional authentication layer.
Solution Approach 2:
The patent applies different security qualities to different parts of the device ecosystem. The first unlock mechanism has a first timeout value and provides standard access, while the second unlock mechanism has a second timeout value and provides enhanced access to specific applications. Each application or data set can have its own security requirements, allowing localized security policies rather than a blanket approach.
2Object-affected harmful factors
If containerization applications are used to secure data, then security is improved, but device complexity is worsened due to static and cumbersome implementation
Solution Approach 1:
The patent implements dynamic security policies that adjust based on runtime conditions. The system monitors usage patterns, device state, and contextual information to dynamically determine which unlock mechanism and timeout values to apply. This replaces static containerization with a flexible, adaptive security framework that automatically adjusts protection levels without requiring complex manual configuration.
Solution Approach 2:
The patent changes security parameters (timeout values, access levels, unlock mechanisms) based on runtime conditions and policy evaluations. The system can modify timeout durations, switch between different unlock mechanisms, and adjust access permissions dynamically. This parameter-based approach simplifies security management compared to fixed containerization schemes while maintaining strong security controls.
3Object-affected harmful factors
If multiple unlock mechanisms are implemented for tiered access, then security is improved, but ease of operation is worsened due to additional authentication steps
Solution Approach 1:
The patent applies partial authentication for partial access. Users can unlock the device with a first mechanism (such as a simple PIN or biometric) to access commonly used applications without providing full authentication. The second unlock mechanism (such as a password or more complex biometric verification) is only required when accessing specific protected applications. This partial action approach provides adequate security for most operations while maintaining ease of use.
Solution Approach 2:
The system automatically determines which unlock mechanism and timeout policy to apply based on the requested operation and current device state. Rather than requiring users to manually select authentication methods or configure security settings, the system self-manages the authentication process, selecting appropriate security levels and timeout values based on embedded policies and runtime conditions.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods may provide for receiving runtime input from one or more unlock interfaces of a device and selecting a level of access with regard to the device from a plurality of levels of access based on the runtime input. The selected level of access may have an associated security policy, wherein an authentication of the runtime input may be conducted based on the associated security policy. In one example, one or more cryptographic keys are used to place the device in an unlocked state with regard to the selected level of access if the authentication is successful. If the authentication is unsuccessful, on the other hand, the device may be maintained in a locked state with regard to the selected level of access.