Weight-Based Access Control for Military Mobile Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the Android environment, existing systems fail to effectively manage access to system data and system functions by applications, particularly in military contexts, where nuanced role-based access control and immediate notification of blocked states are challenging to implement.

Innovation Solution

A weight-based function is introduced in mobile terminals for military purposes, utilizing an interface unit to receive control policies and information deciding intent weights, with a controller determining use authority and executing log generation, immediate notification, or terminal lock based on preset boundary values, allowing for multiple stages of blocking levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If simple permission or denial control is used for application access to system data and functions, then the control mechanism is simple to implement, but it fails to provide immediate notification of blocked states and cannot implement role-based access control with multiple blocking levels

Engineering Contradiction:
Improvecontrol mechanism complexityVSAvoidaccess control flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The access control mechanism is segmented into multiple blocking levels (first blocking level, second blocking level, etc.) with different boundary values. Each level represents a different degree of access restriction, allowing the system to differentiate between minor and major policy violations while maintaining a structured control framework

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of blocking intensity by introducing multiple blocking levels with different boundary values. When the calculated weight exceeds a boundary value, the system transitions from no blocking to first-level blocking, and potentially to second-level blocking, dynamically adjusting the access control parameter based on the severity of the policy violation

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple blocking levels are introduced for different users and applications, then granular access control is achieved, but the system complexity increases

Engineering Contradiction:
Improveaccess control granularityVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-calculating weights for different applications based on their characteristics and pre-defining multiple blocking levels with boundary values. When an application requests access, the system simply compares the pre-calculated weight against the pre-defined boundary values, avoiding complex real-time decision-making and reducing operational complexity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system manages complexity by parameterizing the access control mechanism through weights and boundary values. Different users and applications are differentiated through parameter assignment rather than structural complexity, allowing granular control while maintaining a unified control framework that can be configured through parameter adjustment

Inventive Principle:
Principle #35Parameter changes

3Reliability

If immediate notification and terminal lock are implemented for blocked access, then security response is improved, but the control system becomes more complex

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidcontrol system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security response is segmented into distinct levels corresponding to different blocking levels. First-level blocking triggers immediate notification to the user, while second-level blocking triggers terminal lock. This segmentation allows the system to provide appropriate security responses matched to the severity of the policy violation without requiring a single complex response mechanism

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-defining the security responses for each blocking level. The controller is pre-programmed with the logic that exceeds first boundary value triggers notification and exceeds second boundary value triggers lock. This eliminates the need for complex real-time analysis of security threats and simplifies the control system while maintaining effective security responses

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9769282B2Mobile terminal for performing weight based function with military purpose and control method thereof
Publication Date: 2017.09.19 AGENCY FOR DEFENSE DEV
  • US9769282B2 patent drawing
  • US9769282B2 patent drawing
  • US9769282B2 patent drawing

AI summary

A mobile terminal for performing a weight-based function with military purposes according to the present invention includes an interface unit configured to receive a control policy controlling intent, and information deciding a weight for the intent, and a controller configured to determine whether or not a use authority for the intent is provided, decide a weight based on the control policy and the information when the use authority is not provided, and execute one of a log generation, an immediate notification and a terminal lock by comparing the decided weight with a preset boundary value, whereby multiple stages of blocking levels can be provided upon blocking intent, thereby allowing for setting access and blocking with respect to various users or applications.