Mobile Device TrustScore Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise IT departments face challenges in managing and securing diverse mobile devices brought into the workplace due to the lack of control over OS updates, leading to increased security risks and vulnerabilities across various mobile platforms.

Innovation Solution

An enterprise access control system that integrates with device data sources and identity management systems to track vulnerabilities, generate TrustScores, and control access based on device configurations, using a TrustCatalog and TrustService to automate risk assessment and update management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personal smartphones and tablets are integrated with enterprise systems to support work activities, then employee productivity and flexibility are improved, but security risks and vulnerability exposure increase

Engineering Contradiction:
Improveemployee productivityVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary system comprising a mobile device management server, vulnerability database, and risk assessment module that mediates between personal devices and enterprise systems. This intermediary continuously monitors device vulnerabilities, assesses security risks, and controls access accordingly, allowing productive device integration while mitigating security threats through automated risk management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops where the mobile device management server periodically queries the vulnerability database for known vulnerabilities, assesses current device risk levels, and dynamically adjusts access permissions. This feedback mechanism ensures that security controls adapt to changing threat landscapes while maintaining productive device-Enterprise integration

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If diverse mobile platforms are supported in the enterprise environment, then device choice flexibility is improved, but device complexity and update management difficulty increase

Engineering Contradiction:
Improvedevice choice flexibilityVSAvoidplatform diversity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The mobile device management server implements a universal vulnerability assessment framework that works across multiple mobile platforms (iOS, Android, Windows Phone, etc.). The system queries platform-specific vulnerability databases and applies standardized risk assessment algorithms, enabling unified security management despite platform diversity and reducing the complexity of supporting multiple device types

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the vulnerability management process into distinct components: platform-specific vulnerability data collection, standardized risk assessment algorithms, and unified access control decisions. This segmentation allows the system to handle diverse platforms independently while maintaining consistent security policies, reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If mobile devices with unknown vulnerability statuses are allowed access, then ease of device integration is improved, but reliability of enterprise system security deteriorates

Engineering Contradiction:
Improvedevice integration easeVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary vulnerability assessment and risk evaluation before granting access to the enterprise system. The mobile device management server queries the vulnerability database and assesses device security posture in advance, blocking or conditioning access based on pre-evaluated risk levels, thus ensuring security reliability while maintaining ease of integration for legitimate devices

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8832793B2Controlling enterprise access by mobile devices
Publication Date: 2014.09.09 RAPID7 INC
  • US8832793B2 patent drawing
  • US8832793B2 patent drawing
  • US8832793B2 patent drawing

AI summary

A system comprising at least one component running on at least one server and receiving vulnerability data and, for each device of a plurality of devices, device data that includes data of at least one device component. The system includes a trust score corresponding to each device of the plurality of devices and representing a level of security applied to the device. The trust score is generated using a severity of the vulnerability data. The system includes an access control component coupled to the at least one component and controlling access of the plurality of devices to an enterprise using the trust score.