EP1535159B1

System and method for preventing access to data on a compromised remote device

Abstract

This record has no abstract on file.

EP1535159B1, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Expired 9 August 2023, 3.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

17 claims: 17 independent, 0 dependent

  1. 1
    A method of controlling access to data, the data comprising a first type of data and a second, different, type of data, the first and second types of data each comprising data items held on a client device, the first type of data comprising data items (520) to be synchronised between the client device and a server system (110), the client device (120) being remote from the server system and being a client thereof, and the second type of data comprising data items (510, 530) whose values are not updated at the server system in response to changes thereto on the client device, wherein a data tracker is maintained on the client device, the data tracker identifying each data item as one of the first type or of the second type, the method comprising:receiving (810), at the server system, an indication that the client device is compromised;selecting (825;835;845;855), at the server system, at least one subset of data from the client device, the selected subset being specified as data of the first type or data of the second type;transmitting (830;840;850;860) from the server system, to the client device, in response to receipt of the indication that the client device is compromised, a command to erase the selected at least one subset of data;using, at the client device, the data tracker and the specified type of data to identify (915) the at least one subset of data on the client device;anderasing (915), at the client device, the identified at least one subset of data based on the transmitted command. Procédé de contrôle d'accès à des données, les données comprenant un premier type de données et un deuxième type de données différent, les premier et deuxième types de données comprenant chacun des éléments de données conservés sur un dispositif client, le premier type de données comprenant des éléments de données (520) à synchroniser entre le dispositif client et un système de serveur (110), le dispositif client (120) étant à distance du système de serveur et étant un client de celui-ci, et le deuxième type de données comprenant des éléments de données (510, 530) dont des valeurs ne sont pas mises à jour au niveau du système de serveur en réponse à des changements de celles-ci sur le dispositif client, dans lequel un pisteur de données est maintenu sur le dispositif client, le pisteur de données identifiant chaque élément de données comme un du premier type ou du deuxième type, le procédé comprenant : la réception (810), au niveau du système de serveur, d'une indication que le dispositif client est compromis ;la sélection (825 ;835 ;845 ;855), au niveau du système de serveur, d'au moins un sous-ensemble de données provenant du dispositif client, le sous-ensemble sélectionné étant spécifié comme des données du premier type ou des données du deuxième type ;la transmission (830 ;840 ;850 ;860), du système de serveur au dispositif client, en réponse à la réception de l'indication que le dispositif client est compromis, d'une commande pour effacer l'au moins un sous-ensemble de données sélectionné ;l'utilisation, au niveau du dispositif client, du pisteur de données et du type de données spécifié pour identifier (915) l'au moins un sous-ensemble de données sur le dispositif client ;etl'effacement (915), au niveau du dispositif client, de l'au moins un sous-ensemble de données identifié sur la base de la commande transmise. Verfahren zum Steuern eines Zugriffs auf Daten, wobei die Daten einen ersten Typ von Daten und einen zweiten, unterschiedlichen Typ von Daten umfassen, wobei der erste und der zweite Typ von Daten jeweils Dateneinheiten umfassen, die in einer Client-Vorrichtung gehalten werden, wobei der erste Typ von Daten Dateneinheiten (520) aufweist, die zwischen der Client-Vorrichtung und einem Server-System (110) zu synchronisieren sind, wobei die Client-Vorrichtung (120) sich von dem Server-System entfernt befindet und dessen Client ist, und wobei der zweite Typ von Daten Dateneinheiten (520, 530) aufweist, deren Werte im Server-System als Antwort auf Änderungen daran in der Client-Vorrichtung nicht aktualisiert werden, wobei ein Daten-Tracker in der Client-Vorrichtung unterhalten wird, wobei der Daten-Tracker jede Dateneinheit als eine des ersten Typs oder des zweiten Typs identifiziert, wobei das Verfahren umfasst: Empfangen (810) eines Hinweises durch das Server-System, dass die Client-Vorrichtung kompromittiert ist,Auswählen (825, 835, 845, 855) wenigstens einer Teilmenge von Daten der Client-Vorrichtung auf Seiten des Server-Systems, wobei die ausgewählte Teilmenge als Daten des ersten Typs oder Daten des zweiten Typs spezifiziert ist,Übermitteln (830, 840, 850, 860) eines Befehls von dem Server-System an die Client-Vorrichtung zum Löschen der ausgewählten wenigstens einen Teilmenge von Daten als Antwort auf den Empfang des Hinweises, dass die Client-Vorrichtung kompromittiert ist,Verwenden des Daten-Trackers und des spezifizierten Datentyps zum Identifizieren (915) der wenigstens einen Teilmenge von Daten auf der Client-Vorrichtung in der Client-Vorrichtung, undLöschen (915) der identifizierten wenigstens einen Teilmenge von Daten auf der Grundlage des übermittelten Befehls auf Seiten der Client-Vorrichtung.
  2. 2
    Procédé selon la revendication 1, comprenant en outre le fait que le système de serveur transmet, au dispositif client, une commande pour transmettre l'au moins un sous-ensemble de données à un autre emplacement. The method of claim 1, further comprising the server system transmitting, to the client device, a command to transmit the at least one subset of data to another location. Verfahren nach Anspruch 1, wobei das Server-System an die Client-Vorrichtung zusätzlich einen Befehl zum Übermitteln der wenigstens einer Teilmenge von Daten an einen anderen Ort übermittelt.
  3. 3
    Procédé selon la revendication 1, dans lequel le deuxième type de données inclut des données personnelles. The method of claim 1, wherein the second type of data includes personal data. Verfahren nach Anspruch 1, wobei der zweite Typ von Daten persönliche Daten umfasst.
  4. 4
    Procédé selon la revendication 1, dans lequel le deuxième type de données inclut des applications. The method of claim 1, wherein the second type of data includes applications. Verfahren nach Anspruch 1, wobei der zweite Typ von Daten Anwendungen umfasst.
  5. 5
    Procédé selon la revendication 1, comprenant en outre le fait que le système de serveur transmet une commande, au dispositif client, pour couper une connexion entre le dispositif client et un réseau. The method of claim 1, further comprising the server system transmitting a command, to the client device, to sever a connection between the client device and a network. Verfahren nach Anspruch 1, wobei das Serversystem an die Client-Vorrichtung zusätzlich einen Befehl zur Trennung einer Verbindung zwischen der Client-Vorrichtung und einem Netzwerk übermittelt.
  6. 6
    Procédé selon la revendication 1, dans lequel l'indication est transmise par le dispositif client. The method of claim 1, wherein the indication is transmitted by the client device. Verfahren nach Anspruch 1, wobei der Hinweis von der Client-Vorrichtung übermittelt wird.
  7. 7
    Procédé selon la revendication 1, dans lequel l'au moins un sous-ensemble de données inclut toutes les données sur le dispositif client. The method of claim 1, wherein the at least one subset of data includes all data on the client device. Verfahren nach Anspruch 1, wobei die wenigstens eine Teilmenge von Daten alle Daten in der Client-Vorrichtung umfasst.
  8. 8
    Procédé selon une quelconque revendication précédente, dans lequel l'indication que le dispositif client est compromis comprend une indication que le dispositif client n'est plus autorisé à accéder au système de serveur. The method of any preceding claim, wherein the indication that the client device is compromised comprises an indication that the client device is no longer authorized to access the server system. Verfahren nach einem der vorstehenden Ansprüche, wobei der Hinweis, dass die Client-Vorrichtung kompromittiert ist, einen Hinweis umfasst, dass die Client-Vorrichtung nicht länger befugt ist, auf das Server-System zuzugreifen.
  9. 9
    A client device (120) for use in controlling access to data, the data comprising a first type of data and a second, different, type of data, the first and second types of data comprising data items held on the client device, the first type of data comprising data items (520) to be synchronised between a server system and the client device, said client device being remote from the server system and being a client thereof, wherein the second type of data comprises data items (510, 530) whose values are not updated at the server system in response to changes thereto on the client device, the client device comprising:a data tracker (710) arranged to track the location and type of data held in the client device as one of the first data type or second data type,wherein the client device is arranged to : receive, at the client device, a command to erase at least one subset of data at the client device, the command being received in response to an indication that the client device is compromised and the at least one subset of data being specified as data of the first type or the second type;anduse information generated by the data tracker and the specified type of data, to erase the at least one subset of data based on the received command. Client-Vorrichtung (120) zur Verwendung beim Steuern eines Zugriffs auf Daten, wobei die Daten einen ersten Typ von Daten und einen zweiten, unterschiedlichen Typ von Daten umfassen, wobei der erste und der zweite Typ von Daten jeweils Dateneinheiten umfassen, die in der Client-Vorrichtung vorhanden sind, wobei der erste Typ von Daten Dateneinheiten (520) aufweist, die zwischen einem Server-System und der Client-Vorrichtung zu synchronisieren sind, wobei die Client-Vorrichtung sich von dem Server-System entfernt befindet und dessen Client ist, wobei der zweite Typ von Daten Dateneinheiten (510, 530) umfasst, deren Werte im Server-System als Antwort auf Änderungen daran in der Client-Vorrichtung nicht aktualisiert werden, wobei die Client-Vorrichtung umfasst: einen Daten-Tracker (710), der dazu eingerichtet ist, die Position und den Typ von Daten als zum ersten Datentyp gehörig oder zum zweiten Datentyp gehörig nachzuverfolgen, die in der Client-Vorrichtung vorhanden sind,wobei die Client-Vorrichtung eingerichtet ist zum: Empfangen eines Befehls zum Löschen wenigstens einer Teilmenge von Daten in der Client-Vorrichtung auf Seiten der Client-Vorrichtung, wobei der Befehl als Antwort auf einen Hinweis empfangen wird, dass die Client-Vorrichtung kompromittiert ist, wobei die wenigstens eine Teilmenge von Daten als Daten des ersten Typs oder des zweiten Typs spezifiziert ist, undVerwenden von Information, die durch den Daten-Tracker erzeugt wurde, und des spezifizierten Typs von Daten zum Löschen der wenigstens einen Teilmenge von Daten auf der Grundlage des empfangenen Befehls. Dispositif client (120) pour une utilisation dans un contrôle d'accès à des données, les données comprenant un premier type de données et un deuxième type de données différent, les premier et deuxième types de données comprenant des éléments de données conservés sur le dispositif client, le premier type de données comprenant des éléments de données (520) à synchroniser entre un système de serveur et le dispositif client, ledit dispositif client étant à distance du système de serveur et étant un client de celui-ci, dans lequel le deuxième type de données comprend des éléments de données (510, 530) dont les valeurs ne sont pas mises à jour au niveau du système de serveur en réponse à des changements de celles-ci sur le dispositif client, le dispositif client comprenant : un pisteur de données (710) agencé pour pister la position et le type de données conservées dans le dispositif client comme un parmi le premier type de données ou le deuxième type de données,dans lequel le dispositif client est agencé pour : recevoir, au niveau du dispositif client, une commande pour effacer au moins un sous-ensemble de données au niveau du dispositif client, la commande étant reçue en réponse à la réception d'une indication que le dispositif client est compromis et l'au moins un sous-ensemble de données étant spécifié comme des données du premier type ou du deuxième type ;etutiliser des informations générées par le pisteur de données et le type de données spécifié, pour effacer l'au moins un sous-ensemble de données sur la base de la commande reçue.
  10. 10
    Client-Vorrichtung nach Anspruch 9, wobei die Client-Vorrichtung ferner eingerichtet ist zum:Empfangen eines Befehls durch die Client-Vorrichtung zum Übermitteln der wenigstens einen Teilmenge von Daten zu einem anderen Ort und Übermitteln der wenigstens einen Teilmenge von Daten an einen anderen Ort. Dispositif client selon la revendication 9, dans lequel le dispositif client est agencé en outre pour : recevoir, au niveau du dispositif client, une commande pour transmettre l'au moins un sous-ensemble de données à un autre emplacement ;ettransmettre l'au moins un sous-ensemble de données à un autre emplacement. The client device of claim 9, wherein the client device is further arranged to: receive, at the client device, a command to transmit the at least one subset of data to another location;andtransmit the at least one subset of data to another location.
  11. 11
    Client-Vorrichtung nach Anspruch 9, wobei der zweite Typ von Daten persönliche Daten umfasst. Dispositif client selon la revendication 9, dans lequel le deuxième type de données inclut des données personnelles. The client device of claim 9, wherein the second type of data includes personal data.
  12. 12
    Client-Vorrichtung nach Anspruch 9, wobei der zweite Typ von Daten Anwendungen umfasst. Dispositif client selon la revendication 9, dans lequel le deuxième type de données inclut des applications. The client device of claim 9, wherein the second type of data includes applications.
  13. 13
    Client-Vorrichtung nach Anspruch 9, ferner mit einer Trennungseinrichtung der Client-Vorrichtung, die eingerichtet ist zum:Empfangen eines Befehls auf Seiten der Client-Vorrichtung zur Trennung einer Verbindung zwischen der Client-Vorrichtung und dem Netzwerk, undTrennung der Verbindung zwischen der Client-Verbindung und dem Netzwerk. Dispositif client selon la revendication 9, comprenant en outre un moteur de coupure de dispositif client agencé pour : recevoir une commande, au niveau du dispositif client, pour couper une connexion entre le dispositif client et un réseau ;etcouper la connexion entre le dispositif client et le réseau. The client device of claim 9, further comprising a client device severing engine arranged to: receive a command, at the client device, to sever a connection between the client device and a network;andsever the connection between the client device and the network.
  14. 14
    Client-Vorrichtung nach Anspruch 9, wobei die wenigstens eine Teilmenge von Daten alle Daten in der Client-Vorrichtung umfasst. Dispositif client selon la revendication 9, dans lequel l'au moins un sous-ensemble de données inclut toutes les données sur le dispositif client. The client device of claim 9, wherein the at least one subset of data includes all data on the client device.
  15. 15
    Client-Vorrichtung nach einem der Ansprüche 9 bis 14, wobei der Hinweis, dass die Client-Vorrichtung kompromittiert ist, einen Hinweis aufweist, dass die Client-Vorrichtung nicht länger befugt ist, auf das Server-System zuzugreifen. Dispositif client selon l'une quelconque de la revendication 9 à la revendication 14, dans lequel l'indication que le dispositif client est compromis comprend une indication que le dispositif client n'est plus autorisé à accéder au système de serveur. The client device of any of claim 9 to claim 14, wherein the indication that the client device is compromised comprises an indication that the client device is no longer authorized to access the server system.
  16. 16
    A computer program for adapting a client device (120) to perform a method of controlling access to data, the data comprising a first type of data and a second, different, type of data, the first and second types of data comprising data items held on the client device, the first type of data comprising data items (520) to be synchronised between a server system and the client device, said client device being remote from the server system and being a client thereof, wherein the second type of data comprises data items (510, 530) whose values are not updated at the server system in response to changes thereto on the client device, the client device comprising a data tracker (710) arranged to track the location and type of data held in the client device as one of the first data type or second data type, wherein the method comprises:receiving a command to erase at least one subset of data at the client device, the command being received in response to an indication that the client device is compromised and the at least one subset of data being specified as data of the first type or the second type;using information generated by the data tracker and the specified type of data to erase the at least one subset of data based on the received command. Computerprogramm zum Anpassen einer Client-Vorrichtung (120) zum Durchführen eines Verfahrens zum Steuern eines Zugriffs auf Daten, wobei die Daten einen ersten Typ von Daten und einen zweiten, unterschiedlichen Typ von Daten umfassen, wobei der erste und der zweite Typ von Daten jeweils Dateneinheiten umfassen, die in der Client-Vorrichtung vorhanden sind, wobei der erste Typ von Daten Dateneinheiten (520) aufweist, die zwischen einem Server-System und der Client-Vorrichtung zu synchronisieren sind, wobei die Client-Vorrichtung sich von dem Server-System entfernt befindet und dessen Client ist, wobei der zweite Typ von Daten Dateneinheiten (510, 530) umfasst, deren Werte im Server-System als Antwort auf Änderungen daran in der Client-Vorrichtung nicht aktualisiert werden, wobei die Client-Vorrichtung einen Daten-Tracker (170) umfasst, der eingerichtet ist, die Position und den Typ von Daten als zum ersten Datentyp gehörig oder zur zweiten Datenart gehörig nachzuverfolgen, die in der Client-Vorrichtung vorhanden sind, wobei das Verfahren umfasst: Empfangen eines Befehls zum Löschen wenigstens einer Teilmenge von Daten in der Client-Vorrichtung, wobei der Befehl als Antwort auf einen Hinweis empfangen wird, dass die Client-Vorrichtung kompromittiert ist, wobei die wenigstens eine Teilmenge von Daten als Daten des ersten Typs oder des zweiten Typs spezifiziert ist, undVerwenden von Information, die durch den Daten-Tracker erzeugt wurde, und des spezifizierten Typs von Daten zum Löschen der wenigstens einen Teilmenge von Daten auf der Grundlage des empfangenen Befehls. Programme d'ordinateur pour adapter un dispositif client (120) à effectuer un procédé de contrôle d'accès à des données, les données comprenant un premier type de données et un deuxième type de données différent, les premier et deuxième types de données comprenant des éléments de données conservés sur le dispositif client, le premier type de données comprenant des éléments de données (520) à synchroniser entre un système de serveur et le dispositif client, ledit dispositif client étant à distance du système de serveur et étant un client de celui-ci, dans lequel le deuxième type de données comprend des éléments de données (510, 530) dont des valeurs ne sont pas mises à jour au niveau du système de serveur en réponse à des changements de celles-ci sur le dispositif client, le dispositif client comprenant un pisteur de données (710) agencé pour pister la position et le type de données conservées dans le dispositif client comme un parmi le premier type de données ou le deuxième type de données, dans lequel le procédé comprend : la réception d'une commande pour effacer au moins un sous-ensemble de données au niveau du dispositif client, la commande étant reçue en réponse à une indication que le dispositif client est compromis et l'au moins un sous-ensemble de données étant spécifié comme des données du premier type ou du deuxième type ;l'utilisation d'informations générées par le pisteur de données et le type de données spécifié pour effacer l'au moins un sous-ensemble de données sur la base de la commande reçue.
  17. 17
    A computer program according to claim 16, where in the indication that the client device is compromised comprises an indication that the client device is no longer authorised to access the server system. Computerprogramm nach Anspruch 16, wobei der Hinweis, dass die Client-Vorrichtung kompromittiert ist, einen Hinweis umfasst, dass die Client-Vorrichtung nicht länger befugt ist, auf das Serversystem zuzugreifen. Programme d'ordinateur selon la revendication 16, dans lequel l'indication que le dispositif client est compromis comprend une indication que le dispositif client n'est plus autorisé à accéder au système de serveur.
Independent claims17