EP1564957B1

Method and apparatus for providing dynamic security management

Abstract

This record has no abstract on file.

EP1564957B1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 11 February 2024, 2.6 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

34 claims: 6 independent, 28 dependent

  1. 1
    A method of providing a dynamic security management in an apparatus (1) comprising:a platform for running an application (2);a security manager (7) for handling access of the application (2) to functions (3) existing in the apparatus;an application interface (11A) between the platform and the application (2);a set of access permissions stored in the apparatus and used by the security manager (7) for controlling access of the application (2) to functions (3) through the application interface (11A), characterised by the steps of: downloading into the apparatus (1) an object containing access permissions and other permission information to be associated with policy contained in the downloaded object as well as access permissions already existing in the apparatus (1), wherein the permissions are applicable to at least one function (3), said object comprising new routines and/or new functions;verifying the object;installing the access permissions together with the existing permissions;said object enhancing the application interface (11A) with said new routines and/or new functions.
  2. 4
    A method according to any one of the previous claims, characterised by downloading a further object containing a library (12), or the downloaded object further containing a library (12), said library (12) comprising new routines and/or new functions to be called by an application or library stored in the apparatus;and installing the library (12) to enable access of functions (3) through the application interface (11A).
  3. 7
    A method according to any one of the previous claims, characterised by downloading a further object containing an application (2), or the downloaded object further containing an application (2), said application (2) containing at least one new function;and installing the new function so that the new function can access existing functions through the application interface (11A).
  4. 9
    A method according to any one of the previous claims, characterised in that the access permissions are contained in a policy file.
  5. 14
    A method according to any one of the previous claims, characterised by the steps of:storing the access permissions in a security policy (8);providing the security policy (8) with a hierarchical structure, wherein the security policy (8) has a structure linking access levels of existing functions with a domain associated with the downloaded object, the domain defining the basic access level which may be combined with other information.
  6. 17
    An apparatus (1) with dynamic security management comprising:a platform for running an application (2);a security manager (7) for handling access of the application (2) to functions (3) existing in the apparatus (1);an application interface (11A) between the platform and the application (2);a set of access permissions stored in the apparatus and used by the security manager (7) for controlling access of the application (2) to functions (3) through the application interface (11A), characterised in that : the apparatus (1) is arranged to download an object containing access permissions and other permission information to be associated with policy contained in the downloaded object as well as access permissions already existing in the apparatus (1), wherein the permissions are applicable to at least one function (3), said object comprising new routines and/or new functions;to verify the object;and to install the access permissions together with the existing permissions;said object enhancing the application interface (11A) with said new routines and/or new functions.