Author: Sophia Shahnami

A framework for evaluating whether mobile security telemetry is authoritative for the enterprise decisions it informs.

Published Work

Mobile Telemetry-Centered Threat Modeling for Managed Enterprise Architectures

IEEE Computer, May 2026

DOI: https://doi.org/10.1109/MC.2026.3668342

Core Thesis

Enterprise mobile architectures intentionally decouple device enforcement from centralized decision-making. Failures happen when enterprise systems treat stale, replayed, or uncorroborated telemetry as valid, even when device-side controls remain completely intact.

TCTM formalizes the evaluation of telemetry across four integrity properties:

• Origin: Generation by a trusted platform

• Time-bounded validity: Alignment between signal timestamp and decision window

• Lineage: Traceability across collection, transformation, and ingestion

• Binding: Strong association with specific device identity and transaction context