CA2575288C

Method and system for coordinating client and host security modules

Abstract

A system and methods for coordinating the operation of a client security module and a host security module on a mobile electronic device. The modules communicate with each other through a platform abstraction layer using application programming interfaces to coordinate their activities. In particular, the client security module instructs the host security module when to lock and unlock the device, and the host security module alerts the client security module to attempts by the user to lock or unlock the device.

CA2575288C, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 10 November 2024, 1.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

40 claims: 30 independent, 10 dependent

  1. 1
    CA 02575288 2016-10-11 WHAT IS CLAIMED IS:1. A method for coordinating a client security module with a host security module, wherein both modules are resident on a mobile electronic device with a client side and a host side, the method comprising: detecting a lock event;implementing one of a client-side lock of a client side and a host-side lock of the host side by one of the client security module and the host security module, respectively, in response to the lock event;sending a lock command from said one of the client security module and the host security module to the other of the client security module and the host security module;and implementing the other of a client-side lock of the client side by the client security module and a host-side lock of the host side by the host security module in response to said lock command.
  2. 2
    The method claimed in claim 1, wherein said detecting a lock event includes alerting the client security module to said lock event.
  3. 3
    The method claimed in claim 2, wherein said alerting the client security module to the lock event comprises calling an application programming interface for alerting the client security module to the lock event.
  4. 4
    The method claimed in claim 1, wherein said sending comprises sending the lock command through a platform abstraction layer.
  5. 5
    The method claimed in claim 1, wherein said sending comprises calling an application programming interface for instructing said other of the client security module and the host security module to implement the other lock. -18CA 02575288 2016-10-11
  6. 6
    The method claimed in claim 1, wherein said implementing the other a lock comprises launching a security screen.
  7. 7
    The method claimed in claim 1, wherein said implementing a lock comprises locking a keypad.
  8. 8
    The method claimed in claim 1, wherein said implementing a first lock operation comprises preventing user access to data stored on the device.
  9. 9
    A mobile electronic device comprising:a processor, and memory, and stored in memory to cause the processor to control the device: a host operating system;a host security module, wherein the host operating system and the host security module are resident on a host side of the device;a client application, the client application including a client security module, wherein the client application is resident on a client side of the device;and an abstraction interface layer between the client side and the host side, said abstraction layer including a plurality of application programming interfaces for exchanging communications between the client security module and the host security module, and wherein said client security module includes a component for implementing a client-side lock of the client side in response to a lock event and for calling one of said application programming interfaces for instructing said host security module to implement a host-side lock of the host side.
  10. 10
    The mobile electronic device claimed in claim 9, wherein said host security module includes a component for performing a host-side lock in response to said call from said client security module. -19CA 02575288 2016-10-11
  11. 11
    A method for coordinating a client security module with a host security module, wherein said client security module and said host security module are resident on a mobile electronic device with a client side and a host side, the method comprising:said client security module receiving a user security input;said client security module validating said received user security input;said client security module implementing a client-side unlock of the client side;said client security module passing control to the host security module with an unlock command;said host security module implementing a host-side unlock of the host side in response to receiving said unlock command;and when the client security module is not available on startup, the host security module receiving said user security input, the host security module validating said received user security input by calling a validation function.
  12. 12
    The method claimed in claim 11, wherein said passing comprises passing the unlock command through a platform abstraction layer.
  13. 13
    The method claimed in claim 12, wherein said platform abstraction layer comprises a plurality of application programming interfaces, and wherein said sending the unlock command comprises calling one of said application programming interfaces.
  14. 14
    The method claimed in claim 11, wherein said implementing the host-side unlock of the host side by the host security module comprises permitting user access to data stored on the device.
  15. 15
    The method claimed in claim 11, wherein said implementing the host-side unlock comprises permitting user access to host-side applications. -20CA 02575288 2016-10-11
  16. 16
    The method claimed in claim 11, further including detecting an input event and, in response to said input event, displaying a dialog for receiving said user security input.
  17. 17
    The method claimed in claim 16, wherein said detecting an input event includes alerting the client security module to detection of the input event, and wherein said displaying said dialog is performed by said client security module.
  18. 18
    A mobile electronic device, comprising:a processor, and memory, and stored in memory to cause the processor to control the device: a host operating system resident on a host-side of the device;a host security module resident on the host-side of the device;a client application resident on a client-side of the device, the client application including a client security module;and an interface between the client-side and the host-side for exchanging communications between the client security module and the host security module, said client security module being configured to unlock the client-side of the device in response to receiving a password and pass control to the host security module with an instruction to unlock the host-side of the device;and when said client security module is not available on startup, the host security module is configured to receive said password and the host security -21 CA 02575288 2016-10-11 module is configured to validate said password by calling a validation function.
  19. 19
    The mobile electronic device claimed in claim 18, wherein said host security module is configured to unlock the host-side in response to said instruction from said client security module.
  20. 20
    The mobile electronic device claimed in claim 18, wherein said interface comprises an application programming interface for requesting validation of the password.
  21. 21
    The mobile electronic device claimed in claim 20, wherein said host security module includes an unlock component for operation on start-up of the device, wherein said unlock component receives an input password and calls said application programming interface for requesting validation of said input password.
  22. 22
    A computer-readable medium containing computer-executable instructions for coordinating a client security module with a host security module, wherein said client security module and said host security module are resident on a mobile electronic device with a client side and a host side, the instructions, when performed by a processor, cause said processor to:receive a user security input at said client security module;validate said received user security input at said client security module;implement a client-side unlock of the client side by the client security module;pass control, with an unlock command, from the client security module to the host security module;implement a host-side unlock of the host side by the host security module in response to receiving said unlock command;and -22CA 02575288 2016-10-11 when the client security module is not available on startup: receive said user security input at the host security module, and validate said received user security input by the host security module by calling a validation function.
  23. 28
    The computer-readable medium of claim Tl wherein the instructions that cause the processor to detect an input event comprise instructions that cause the processor to alert the client security module to detection of the input event, and wherein the displaying the dialog is performed by the client security module. -23CA 02575288 2016-10-11
  24. 30
    A computer-readable medium containing computer-executable instructions for coordinating a client security module with a host security module, wherein said client security module and said host security module are resident on a mobile electronic device with a client side and a host side, the instructions, when performed by a processor, cause said processor to carry out the method of any one of claims 1 -8 and 11-17.
  25. 31
    A method for coordinating a client security module with a host security module, wherein both modules are resident on a mobile electronic device, the host security module and a host operating system being resident on a host-side of the device, the method comprising:detecting a lock event;implementing a client-side lock operation by the client security module, to lock a client application that includes the client security module;sending a lock command from the client security module to the host security module;initiating a host-side lock operation at the host security module in response to said lock command wherein said initiating said host-side lock operation comprises launching a security screen;said client security module unlocking the client-side of the device in response to a valid password;and passing control from the client security module to said host security module with an instruction to unlock the host-side of the device. -24CA 02575288 2016-10-11
  26. 34
    The method as claimed in any one of claims 31-33, wherein said initiating said hostside lock operation comprises locking a keypad.
  27. 35
    The method as claimed in any one of claims 31-34, wherein said implementing said client-side lock operation comprises preventing user access to data stored on the device.
  28. 36
    A mobile electronic device, comprising:a processor, and memory, and stored in memory to cause the processor to control the device: a host operating system;a host security module, wherein the host operating system and the host security module are resident on a host-side of the device;a client application, the client application comprising a client security module, wherein the client application is resident on a client-side of the device;and an abstraction interface layer between the client-side and the host-side, said abstraction layer comprising a plurality of application programming interfaces for exchanging communications between the client security module and the host security module, wherein said client security module comprises a component for: -25CA 02575288 2016-10-11 implementing a client-side lock operation to lock said client application in response to detecting a lock event;calling one application programming interface of said plurality of application programming interfaces for instructing said host security module to implement a host-side lock operation comprising launching a security screen;unlocking the client-side of the device in response to a valid password;and calling another application programming interface of said plurality of application programming interfaces for instructing said host security module to unlock the host-side of the device.
  29. 39
    The mobile electronic device as claimed in any of claims 36 to 38, wherein said implementing said client-side lock operation comprises preventing user access to data stored on the device.
  30. 40
    A computer readable medium storing program instructions executable by a processor of a computing device for causing the computing device to implement the method of any one of claims 31 to 35.
Independent claims30