EP1501330B1

Security for a mobile communications device

Abstract

This record has no abstract on file.

EP1501330B1, drawing sheet 1
Sheet 1 of 2

Term

Term ended

Expired 22 July 2024, 2.2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

25 claims: 21 independent, 4 dependent

  1. 1
    A mobile communications device (10) for communicating with a wireless network (50), comprising:an electronic storage element (24) having data stored thereon;a processor (38) connected to the electronic storage element (24) for accessing the data;a communications subsystem (11) connected to the processor (38) for exchanging signals with the wireless network (50) and with the processor (38);a user input interface connected to send user input signals to the processor (38) in response to user action;and, a security module (56) associated with the processor (38) for: (i) detecting a trigger condition comprising inactivity of the user input interface for a predetermined duration, (ii) monitoring, after the trigger condition has been detected if a secret shared by the user and the mobile communications device is received through the user input interface within a predetermined duration after detection of the trigger condition, and (iii) if receipt of the shared secret is not detected within the predetermined duration, automatically taking a security action to: (1) erase all or selected data on the electronic storage element (24), or (II) encrypt all or selected data stored on the electronic storage element (24) and store the encrypted data on the electronic storage element (24),
  2. 4
    The mobile communications device (10) of any one of claims 1, to 3, wherein the data stored on the mobile communications device includes service data, wherein the security action is erasing all service data.
  3. 5
    The mobile communications device (10) of any one of claims 1 to 3, wherein the data stored on the mobile communications device includes user data, wherein the security action is erasing all user data.
  4. 6
    The mobile communications device (10) of any one of claims 1 to 3, wherein the data stored on the mobile communications device includes user data, wherein the security action is encrypting all user data.
  5. 7
    The mobile communications device (10) of any one of claims 1 to 3, wherein the data stored on the mobile communications device includes service data, wherein the security action is encrypting all service data and storing the encrypted service data on the electronic storage element (24).
  6. 8
    The mobile communications device (10) of any one of claims 1 to 3, wherein the data on the electronic storage element (24) includes service data required by the mobile communications device (10) to successfully communicate over the wireless network (50) and the security action includes erasing the service data from the electronic storage element (24).
  7. 9
    The mobile communications device (10) of any one of claims 1 to 8, wherein the security action includes disabling an ability of the mobile communications device (10) to communicate with the wireless network (50).
  8. 10
    The mobile communications device (10) of any one of claims 1 to 8, wherein the user input interface includes a keyboard or keypad and the trigger condition includes inactivity of the keyboard or keypad for a predetermined duration.
  9. 11
    The mobile communications device (10) of any one of claims 1 to 10, wherein after detecting the trigger condition and while monitoring for entry of the shared secret, the security module takes the security action to erase or encrypt the at least some of the data if entry of the shared secret is not detected within a predetermined number of attempts.
  10. 12
    The mobile communications device (10) of any one of claims 1 to 11, further comprising a user output device for issuing a prompt for entry of user input, the security module causing the prompt to be issued upon detection of the trigger condition.
  11. 13
    A method of providing security for a mobile communication device (10) that is configured to communicate over a wireless communications network (50), the mobile communication device (10) including an electronic storage element (24) having data stored therein, the method comprising:(a) monitoring for a trigger condition comprising the inactivity of the user input interface for a predetermined duration;(b) subsequent to occurrence of the trigger condition, monitoring to detect if a secret shared by the mobile communications device (10) and the user is entered through a user input interface of the mobile communications device (10) within a predetermined duration after the occurrence of the trigger condition;and, (c) if user entry of the shared secret is not detected within the predetermined time duration after occurrence of the trigger condition, automatically taking security action to: (I) erase all or selected data stored on the electronic storage element (24), or (II) encrypt all or selected data stored on the electronic storage element (24) and store the encrypted data on the electronic storage element (24).
  12. 16
    The method of any one of claims 13 to 15, wherein the data stored on the mobile communications device includes service data, wherein the security action is erasing all service data.
  13. 17
    The method of any one of claims 13 to 15, wherein the data stored on the mobile communications device includes user data, wherein the security action is erasing all user data.
  14. 18
    The method of any one of claims 13 to 15, wherein the data stored on the mobile communications device includes user data, wherein the security action is encrypting all user data.
  15. 19
    The method of any one of claims 13 to 15, wherein the data stored on the mobile communications device includes service data, wherein the security action is encrypting all service data.
  16. 20
    The method of any one of claims 13 to 15, wherein the data stored on the mobile communication device (10) includes service data required by the mobile communication device (10) to communicate over the wireless communications network (50), wherein only the service data (60) required to establish and maintain communication between the device (10) and the wireless network (50) is erased.
  17. 21
    The method of any one of claims 13 to 20, further comprising prompting the user to take action upon occurrence of the trigger condition.
  18. 22
    The method of any one of claims 13 to 21, further comprising monitoring a number of user attempts to enter the shared secret in step (c) and taking the security action if the shared secret is not successfully entered within a predetermined number of attempts.
  19. 23
    The method of any one of claims 13 to 22, wherein at least some communications functions of the device are suspended during the predetermined time duration.
  20. 24
    The method of any one of claims 13 to 23, wherein the user input interface includes a keyboard or keypad, and the trigger condition includes inactivity of the keyboard or keypad for a predetermined duration.
  21. 25
    A computer program product including a computer readable medium carrying computer program code means for providing security for a mobile communication device (10) that is configured to communicate over a wireless communications network (50), the computer program code means including means for performing the method of any one of claims 13 to 24.
Independent claims21