Weight-Based Access Control for Military Mobile Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the Android environment, existing systems fail to effectively manage access to system data and system functions by applications, particularly in military contexts, where nuanced role-based access control and immediate notification of blocked states are challenging to implement.
Innovation Solution
A weight-based function is introduced in mobile terminals for military purposes, utilizing an interface unit to receive control policies and information deciding intent weights, with a controller determining use authority and executing log generation, immediate notification, or terminal lock based on preset boundary values, allowing for multiple stages of blocking levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If simple permission or denial control is used for application access to system data and functions, then the control mechanism is simple to implement, but it fails to provide immediate notification of blocked states and cannot implement role-based access control with multiple blocking levels
Solution Approach 1:
The access control mechanism is segmented into multiple blocking levels (first blocking level, second blocking level, etc.) with different boundary values. Each level represents a different degree of access restriction, allowing the system to differentiate between minor and major policy violations while maintaining a structured control framework
Solution Approach 2:
The system changes the parameter of blocking intensity by introducing multiple blocking levels with different boundary values. When the calculated weight exceeds a boundary value, the system transitions from no blocking to first-level blocking, and potentially to second-level blocking, dynamically adjusting the access control parameter based on the severity of the policy violation
2Adaptability or versatility
If multiple blocking levels are introduced for different users and applications, then granular access control is achieved, but the system complexity increases
Solution Approach 1:
The system performs preliminary actions by pre-calculating weights for different applications based on their characteristics and pre-defining multiple blocking levels with boundary values. When an application requests access, the system simply compares the pre-calculated weight against the pre-defined boundary values, avoiding complex real-time decision-making and reducing operational complexity
Solution Approach 2:
The system manages complexity by parameterizing the access control mechanism through weights and boundary values. Different users and applications are differentiated through parameter assignment rather than structural complexity, allowing granular control while maintaining a unified control framework that can be configured through parameter adjustment
3Reliability
If immediate notification and terminal lock are implemented for blocked access, then security response is improved, but the control system becomes more complex
Solution Approach 1:
The security response is segmented into distinct levels corresponding to different blocking levels. First-level blocking triggers immediate notification to the user, while second-level blocking triggers terminal lock. This segmentation allows the system to provide appropriate security responses matched to the severity of the policy violation without requiring a single complex response mechanism
Solution Approach 2:
The system performs preliminary action by pre-defining the security responses for each blocking level. The controller is pre-programmed with the logic that exceeds first boundary value triggers notification and exceeds second boundary value triggers lock. This eliminates the need for complex real-time analysis of security threats and simplifies the control system while maintaining effective security responses
Data Source
AI summary
A mobile terminal for performing a weight-based function with military purposes according to the present invention includes an interface unit configured to receive a control policy controlling intent, and information deciding a weight for the intent, and a controller configured to determine whether or not a use authority for the intent is provided, decide a weight based on the control policy and the information when the use authority is not provided, and execute one of a log generation, an immediate notification and a terminal lock by comparing the decided weight with a preset boundary value, whereby multiple stages of blocking levels can be provided upon blocking intent, thereby allowing for setting access and blocking with respect to various users or applications.


