Virtual Profile Access Control for Context-Aware Privilege Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access privilege management systems for mobile devices lack the ability to create and enforce fine-grained, context-aware rules for secondary account holders, leading to inadequate control over service feature usage, particularly in shared device environments such as families or work groups.

Innovation Solution

The Access Privilege Control (APC) system allows primary account holders to configure high-fidelity access privilege rules associated with virtual profiles, which can be transmitted to client devices, enabling conditional access based on parameters like time, location, and context of operation, and includes features to intercept and manage service feature usage, generate recommendations, and update rules dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If high-level access privilege rules are implemented, then ease of operation is improved, but manufacturing precision deteriorates

Engineering Contradiction:
Improveease of configuring access privilegesVSAvoidfidelity of access privilege control
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent segments access privilege control into multiple hierarchical levels: device-level rules, service feature-level rules, and application-level rules. This allows the system to provide both high-level coarse control (device-level) and fine-grained control (service feature and application levels) simultaneously, resolving the contradiction between ease of operation and control fidelity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic rule configuration where access privileges can be adjusted in real-time based on context parameters such as time of day, location, and device state. Rules can be modified without reconfiguring the entire system, enabling both ease of operation and precise control through flexible, context-aware policies.

Inventive Principle:
Principle #15Dynamics

2Manufacturing precision

If fine-grained access privilege rules are implemented, then manufacturing precision is improved, but device complexity increases

Engineering Contradiction:
Improvefidelity of access privilege controlVSAvoidcomplexity of access privilege system
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent employs a nested hierarchical structure where service feature rules are contained within device rules, and application rules are contained within service feature rules. This nesting allows fine-grained control at each level while managing complexity through hierarchical abstraction, where higher levels provide context and lower levels provide specificity.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces virtual profiles as intermediary entities that mediate between users and access privilege rules. Virtual profiles encapsulate complex rule sets and context parameters, allowing users to manage access privileges through simplified profile-based control rather than directly configuring complex rules, thus reducing perceived complexity while maintaining fine-grained control capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If context-aware access privilege rules are implemented, then manufacturing precision is improved, but loss of information increases

Engineering Contradiction:
Improvegranularity of access privilege rulesVSAvoiddata transmission overhead
Core Design Contradiction:
Manufacturing precisionVSLoss of information

Solution Approach 1:

The patent performs preliminary configuration of context parameters and rule conditions during rule creation, storing these parameters in the virtual profile. This allows the system to evaluate access requests using pre-configured context information without needing to continuously transmit or process large amounts of contextual data, reducing information overhead while maintaining fine-grained control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements local quality by associating specific context parameters with specific access privilege rules rather than maintaining a global context model. Each rule contains only the context parameters relevant to its specific purpose, reducing overall information requirements while enabling precise, context-aware control decisions at the point of evaluation.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11627137B2Virtual profile instantiations via an access privilege control system
Publication Date: 2023.04.11 T MOBILE US INC
  • US11627137B2 patent drawing
  • US11627137B2 patent drawing
  • US11627137B2 patent drawing

AI summary

This disclosure describes techniques for facilitating a primary account holder (PAH) of a client account to control access privileges of service features that are accessible by secondary account holders (SAH), via the client account. More specifically, an Access Privilege Control (APC) system is described that enables the PAH to generate access privilege rules that control the use of service features by a SAH, that are accessible via the client device(s) associated with the client account. The APC system may associate a set of updated access privilege rules with virtual profile data for clients associated with the client account. The virtual profile data may be transmitted to client devices, or subset thereof, associated with the client account. Further, the APC system may monitor an operation of client devices associated with the client account and provide one or more recommendations to update access privilege rules based on monitored service feature usage.