mobile electronic device with access protection
Abstract
Die Erfindung beschreibt ein mobiles elektronisches Gerät (1) mit Zugriffskontrolle (2). Dabei erfolgt zumindest eine Teil der Überprüfung der Zugangsberechtigung durch ein Zusatzgerät (7). Zugriffe auf geschützte Bereiche (4) des mobilen Gerätes (1) sind nur nach erfolgreicher Berechtigungsprüfung und nur für einen vorbestimmten Zeitraum möglich. Nach Ablauf dieser Zeit muss das mobile Gerät (1) eine erneute Prüfung durch das Zusatzgerät (7) vornehmen lassen. Durch die Erfindung wird der Zugriffs- und Diebstahlschutz für das mobile elektronische Gerät (1) dadurch erhöht, das sein Besitz allein den Zugriff auf geschützte Teile (4) des Geräts (1) nur für einen vorbestimmten Zeitraum ermöglicht.

Term
Term ended
Projected expiry passed 26 October 2025, 0.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
23 claims: 3 independent, 20 dependent
- c-de-0001Portable electronic device (1) with Access Protection (2) for at least partial blocking of the device (1), the thereby is formed such that after checking the authorization of a user of the access to predetermined portions (4) of the device (1) for a predetermined time is unlocked and, after the predetermined time of the access to the predetermined portions (4) of the apparatus (1) is automatically locked, characterized in that carried out the verification of a user's privilege under cooperation of the mobile device (1) including an attachment (7).
- c-de-0003Mobile electronic device according to any one of claims 1 or 2, characterized in that the clearing is done by transmitting a Freischaltkodes (10) from the auxiliary device (7).
- c-de-0004Portable electronic device (1) according to any one of claims 2 or 3, characterized in that the auxiliary device (7) is a stationary computer with an attached docking station (9) for the mobile device (1).
- c-de-0007Portable electronic device (1) according to one of claims 5 or 6, characterized in that the Freischaltkode (10) can only be used once.
- c-de-0008Portable electronic device (1) according to one of claims 5 to 7, characterized in that the Freischaltkode (10) only in a predetermined period validity.
- c-de-0012Portable electronic device (1) according to one of claims 3 to 11, characterized in that a Freischaltkode (10) can be used from a group of predetermined Freischaltkodes for submission.
- c-de-0014Portable electronic device (1) according to one of claims 3 to 13, characterized in that the Freischaltkode (10) with a unique identifier (14) of the mobile electronic device (1) is encrypted.
- c-de-0015Portable electronic device (1) according to one of claims 1 to 14, characterized in that access protection (2), the mobile device (1) locks against any use.
- c-de-0016Portable electronic device (1) according to one of claims 1 to 14, characterized in that access protection (2) the execution of predetermined programs prevented.
- c-de-0017Portable electronic device (1) according to one of claims 1 to 14, characterized in that access protection (2) access to predetermined data prevented.
- c-de-0018Portable electronic device (1) according to any one of claims 1 to 17, characterized in that the access protection (2) is integrated in the BIOS of the device (1).
- c-de-0019Portable electronic device (1) according to any one of claims 1 to 17, characterized in that the access protection (2) in the operating system software of the device (1) is integrated.
- c-de-0020A method for protecting a device (1) from unauthorized access by Lock predetermined portions (4) of the device (1) that will be canceled after verification of the authorization of a user for a predetermined time and is blocked again after the predetermined time, characterized in that If the verification of the authorization of a user under interaction of the device (1) with an external auxiliary device (7).
- c-de-0022A method for assigning a mobile electronic device (1) to an attachment (7), comprising the steps of:(A) entry of a password to the mobile electronic device (1), (B) storage of the entered password in a nonvolatile memory of the mobile device (1), (C) transfer the stored password from the mobile electronic device (1) to the attachment (7), (D) entering a password on the attachment (7), (E) comparison of the transferred password with the locally entered password, (F) transmitting a Freischaltkodes (10) from the auxiliary device (7) to the mobile electronic device (1) if the passwords match.
Independent claims14
29 paragraphs in 1 section, as filed
p0001The invention relates to a mobile electronic device with an access protection for at least partial blocking of the device, which is formed by is that after reviewing an authorization of a user access to predetermined portions of the device unlocked for a predetermined time and after the predetermined time of automatically allowed full access to predetermined portions of the device.
p0002The increasing diffusion and use of mobile electronic devices is also gaining a protection of these devices against theft and unauthorized access in importance. Therefore, such devices typically are provided with a password protection, which makes the product for an unauthorized user unusable. The award, the note and enter the password, the user is relatively uncomfortable and granted in some situations only insufficient protection. Quick or easy to guess passwords do not provide adequate protection against unauthorized access is unauthorized. Prolonged and difficult to identify passwords are for the user difficult however to remember.
p0003Alternatively, are biometric protection procedures. Here biometric features of the user, for example, will be fingerprint used to verify the user's identity. However, the need for such a process sensors are expensive to manufacture. In addition, the detection reliability of such methods is still relatively low. One hand this may lead to unauthorized users are improperly allowed to operate the equipment or other, legitimate users are prevented from using the device.
p0004Therefore, the object of the invention is to improve the access protection over simple password entry without this results in a significant loss of comfort for the user. Furthermore, should not require expansion of hardware of the mobile device of such designed access protection.
p0005The object is achieved by a device of the type described above that is characterized in that the verification of a user's privilege under cooperation of the mobile device is carried out with an attachment.
p0006Only when such a review of user access authorization was successful interaction with the auxiliary device, the mobile device provides access to protected areas. Such access is permitted only for a predetermined period. By the time, the predetermined time period has expired, the mobile device to re-check of access authorization must in turn interact with the accessory.
p0007By the invention, the access protection is on the mobile device increased in that an access to protected areas of the mobile device only for that is possible has access to the attachment. The possession of the mobile device is no longer enough to access on the protected part after the predetermined time period.
p0008The usual password entry can occur in addition to the protection of the invention. While entering the password to the mobile electronic device is mainly used for data security, theft protection is provided by the protection mechanism of the invention. It makes no sense to steal a device whose password protection can be circumvented, for example by reinstalling the software, but that after the predetermined time, regardless of the software installed without the attachment is unusable.
p0009Advantageously located in the attachment to a stationary device. Such a device typically is in an enclosed area, such as in an office, erected. This limits access to such an accessory to a manageable group of people.
p0010The release of the access authorization can be made by sending a Freischaltkodes of the attachment to the mobile device. The forwarded Freischaltkode replaced preferably the conventional password. Since such code is typically transmitted electronically, the code used can be chosen considerably longer than would be usual for a manually entered password. A guessing such Freischaltkodes thereby compounding the difficulties.
p0011The safety of the assigned Freischaltkodes can be further increased when the Freischaltkode is a unique device identifier (UUID), as is common in mobile devices is encrypted. Thus, a possibly determined by means of another mobile device Freischaltkode not be used on any other mobile device.
p0012Further advantageous details and embodiments of the invention are specified in the subclaims.
p0013The invention will be described using two embodiments with reference to the drawings. In the drawings:<ul><li>Figure 1 is a schematic diagram of a mobile electronic device according to the invention with attached accessory device,</li><li>2 shows a flow chart explaining the operation of the access protection,</li><li>Figure 3 is a detailed schematic diagram of the mobile electronic device according to the invention in a first embodiment,</li><li>Figure 4 is a detailed schematic diagram of the mobile electronic device according to the invention in a second embodiment.</li></ul>
p0014The schematic diagram of Figure 1 and the flowchart in Figure 2 serve to illustrate the interaction of the components of the electronic device according to the invention with the accessory. The electronic device 1 includes an access control means 2 with built-in timer 3, a protected area 4, an unprotected area 5, means for input and output 6 and a unique device identifier 14. An equipment 7 can cooperate with the access control means. 2
p0015The first time you start or cold start of the mobile electronic device 1, such as at the first time after installing a new operating system, locks the access control means 2 to access the protected area 4 accesses to the unprotected area 5 are also possible in this state. Of course, a configuration is possible in which extends the protected area to the entire device. When attempting to access the protected area 4 the mobile electronic device 1 requests a review of the user authorization. This can be done for example by displaying a corresponding prompt on the screen 6, or sending a call signal to the external equipment. 7 Responds the attachment 7 at the request of the user or in automatic response to the request signal by sending a confirmation of the access, the access control means 2 of the mobile device 1 checks a sent confirmation of their validity. This can be done for example by checking the identity of the external equipment. 7 In case of a negative verification calls to the mobile device 1 for reconsideration of the user authorization. In case of positive verification, a timer 3 to a predetermined time is adjusted to the needs to be a reconsideration of the user ID at the latest. In the case of the presence of another protection function 8, such as a built-in password protection of the mobile device, the control will be transferred to this additional protection. 8 Authorized to the user and with respect to the further protection function 8, for example by entering the correct password, lifts the access control means 2, the barrier of the protected area 4.
p0016In this state, the mobile electronic device 1 is fully operational, ie, a user can use it to the full extent. A device-internal protection functions 8 can be used as usual in this state, ie, a user can prevent unauthorized access, the mobile device 1, for example, by assigning a password. To re-access to the mobile electronic device 1, for example, when performing a soft reset, it must protect internal 8 then be overcome, for example by entering a password. A reconsideration of the user authorization by the attachment 7 is not necessary, as long as the predetermined time, which is stored in the timer 3 for reconsideration has not been reached.
p0017If the set in the timer 3 time for reconsideration of the admission reached, blocks the access control means 2 the protected area 4 from further access. The user of the electronic device 1 is alerted to this by either a request for reconsideration of user authority or by a precautionary warning on the screen. 6 Of course, an untimely reset the timer 3 on the predetermined time by a controlled deceleration of the predetermined time before checking the user authorization is possible. Furthermore, the protected area 4 of the mobile device 1 can be locked on the user's request has the predetermined time ago.
p00183 shows a first detailed embodiment of a mobile electronic device according to the invention 1, its internal components match those of FIG. 1 The electronic device 1 is connected to a docking station. 9 The docking station is 9 with an auxiliary device 7, in the embodiment of a stationary computer, connected. The insertion of the mobile electronic device 1 in the docking station 9 is detected by the device. 1 The access control means 2 of the portable electronic device 1 then requests a Freischaltkode 10 from the equipment. 7 The additional device 7 checks the identity of the requesting mobile electronic device 1. If this unit 1 considered entitled to request a Freischaltkode, then a valid Freischaltkode 10 to dock 9 is transmitted. The access control means 2 of the portable electronic device 1 receives the Freischaltkode 10 from the docking station 9. The received Freischaltkode 10 is checked for correctness. In the case of validity of the received code 10, an internal timer is set to 3 for a predetermined time. In the case of the presence of a device-internal protection function 8 this is polled as described above. Thereafter, all future accesses are allowed on the protected area 4 of the device 1 until the set time of the timer is reached 3 or the user locks the mobile device itself. Latest at the end of the predetermined period, all requests are denied again on the protected area 4 of the mobile electronic unit 1. Instead, a warning message on the screen 6 of the mobile electronic device is displayed. This message prompts you to re-check of access authorization by the auxiliary equipment. 7 If the device 1 again used the predetermined time prior to the docking station 9, a new Freischaltkode requested 10 of the auxiliary device 7 automatically. then If a valid Freischaltkode received 10, the timer 3 is again reset to the predetermined time period.
p0019An arrangement consisting of a stationary computer 7, a docking station 9 and a mobile electronic device 1 is already being used frequently. The docking station is 9 contained in a rule to synchronize to the mobile electronic device 1 data with the connected stationary computer 7. In an advantageous embodiment, checking the access authorization and synchronization of data is carried out jointly. A user who has relative to the stationary computer 7 already authorized, can use this authorization hereinafter also for the mobile electronic device the first In case the presence of a multi-user system on both sides of the mobile electronic device 1 than on the side of the stationary computer 7, the user ID and, optionally, the user password can be accommodated in the Freischaltkode. An additional key input or a password is no longer necessary. Simultaneously, the data of the mobile electronic device 1 are brought up to date. Compared to a separate authorization of the user with respect to the mobile electronic device 1 and a subsequent synchronization of the data contained on the method described results in a considerable gain in comfort for the user.
p0020According to Figure 4, in a further development of the invention of an auxiliary device 7, written again in the form of a stationary computer, valid Freischaltkodes 10 for the mobile electronic device 1 on removable media 11th In the exemplary embodiment is used as the removable storage medium 11 is a memory card that is inserted into a read / write device 12 of the attachment 7th The storage medium 11 may be several Freischaltkodes 10 included. Upon insertion of the storage medium 11 in a read / write unit 13 of the mobile electronic device 1 checks this, if any of the codes has 10 valid for submission. This can be done to recordable by comparing an encoded in Freischaltkode identity of generating additional device 7 with a stored in the mobile device identity, or by checking the encoded information on the validity period of Freischaltkodes 10. If a valid Freischaltkode 10 found on the storage medium 11, the timer 3 access control 2 is reset to the predetermined value. The mobile electronic device 1 then prompts the user by displaying an appropriate message, 11 to remove the storage medium again from the read / write device. 13 Thereafter, the control is transferred to a possibly available protective function 8 and lifted the barrier of the protected area 4 to overcome them. As before, at the latest, all access blocked on reaching the predetermined time to the protected area 4, if in the meantime no renewed check of access authorization has occurred. The user of the device 1 is then alerted by a warning message on the screen 6, that a review of the admission means of the attachment 7 or of the storage medium 11 before accessing the protected area 4 is necessary.
p0021To increase the protective effect, it is advantageous if each Freischaltkode 10 is only valid for a one-time authorization. Furthermore i st advantageous if each Freischaltkode 10 has only for a predetermined period validity. In this case can be 11 prepared for planned absence of the attachment 7 is a storage medium that contains a valid Freischaltkode 10, for example for each day of absence. Each of these Freischaltkodes 10 is only once and only within a predetermined period valid. Thus, the mobile electronic device 1 is only of limited use even with simultaneous loss of the device 1 and the memory card 11, which makes it particularly unattractive to a potential thief.
p0022Before a planned absence, a storage medium 11 with the required number of Freischaltkodes is prepared 10 and associated validity periods. Advantageously, encrypts the attachment 7 Freischaltkodes 10 it produced with the unique identifier 14 of the device 1. During the absence of a phase Freischaltkode is respectively 10 read from the removable media 11 in the mobile device 1 and used to verify the authorization. The Freischaltkode 10 used may be referred to as consumed by the access control means 2 and are therefore marked invalid for further verification. After this operation, the removable storage media 11 is removed from the read / write device 13 and stored in a safe place. After the predetermined activation period the process is repeated.
p0023Alternative embodiments of the electronic device 1 according to the invention can be used in a local network authentication as the network identifier, or the identifier predetermined server computer. The resulting advantage is that with such an arrangement can be done checking the access authorization to a mobile device 1 in the whole area of the local network, for example, by a local company network. In case of a local wireless network, the mobile device 1, for example, within the company building remains unlimited use, since each time they access the network, an automatic check of access authorization can be made. If the device is removed from the company, and thus of the radio range of the company network, the access to the device 1 itself or mission-critical data in the protected area 4 can be prevented. This makes, for example, the theft of electronic devices by company employees unattractive. In addition, a unique identifier can be a 14 as reported stolen mobile device 1, then on a blacklist that is managed by a central computer of the network, registered. This can be ruled out a future authorization even if the mobile device 1 again provides access to the local network.
p0024A placement of the access control means 2 in an unchanging part of the device BIOS prevents the overcoming of the access control means 2 to reinstall the operating system software. In this case, the mobile electronic device 1 is useless without the simultaneous access to the auxiliary device 7. This constellation is therefore particularly suitable for the embodiment of a theft protection.
p0025The placement of the access control means 2 in the operating system software of the device 1 allows the subsequent amendment of the authorization mechanism used after user authorization. This example allows for later integration of access protection according to the invention into an existing mobile electronic device 1. The access protection can be bypassed by any new installation of the operating system software here. However, such an approach, for example, the "flashing" the memory of the mobile electronic device 1, all stored data and programs of the mobile device 1 will be lost. This constellation therefore still provides protection against unauthorized access to important data stored in the protected area 4 of the mobile electronic device. 1
p0026An assignment of a mobile electronic device 1 to an auxiliary device 7 can be made in different ways. For example, an allocation by the input of the same passwords also be made the mobile device 1, both of the auxiliary device 7 as. In this case, an input on the mobile device 1 for later password authorization is stored in a nonvolatile memory of the mobile device 1 and transmitted at the first authorization request to the accessory device. 7 If the user authorizes the attachment 7 with the same password, a Freischaltkode is 10 transmitted to the mobile device. 1 Such assignment process can be implemented on any mobile electronic device 1, which provides for the entry of a password for authorization. The problem is that the user of the Zuatzgerät 7 password is stored unencrypted in the mobile electronic device. 1
p0027In order to improve the aforementioned method for assigning a mobile electronic device 1 to an auxiliary device 7, the entered on the mobile device 1 the password using the unique identifier 14 of the mobile device 1 may be encrypted. During the authorization the mobile device.1 transmits the encrypted password and its unencrypted device identifier 14 to the attachment 7. The user must be a case have as previously filed by the same password on accessory. 7 The additional device 7 can now encrypt the locally entered password with the received identifier 14 of the mobile device 1 and then compare the locally encrypted password with the received encrypted password. If they agree, is a Freischaltkode 10 encrypted with the device ID 14 of the mobile device 1 and transmitted to the mobile device. 1 When using this method, no passwords are stored unencrypted. This particular security for a password-protected attachment 7 increases.
p0028Advantageously, the assignment process takes place before the sale of systems whose individual units are to cooperate after the sale. However, a subsequent assignment can be provided by the device manufacturer, for example, for a reassignment to a sale of the mobile electronic unit 1.
LIST OF REFERENCE NUMBERS
p0029<dl id="dl0001" compact="compact"><dt>1</dt><dd>The mobile electronic device</dd><dt>2</dt><dd>Access control means</dd><dt>3</dt><dd>timer</dd><dt>4</dt><dd>protected area</dd><dt>5</dt><dd>Unprotected zone</dd><dt>6</dt><dd>Input and output components</dd><dt>7</dt><dd>attachment</dd><dt>8th</dt><dd>Docking station</dd><dt>9</dt><dd>Freischaltkode</dd><dt>10</dt><dd>Exchangeable storage medium</dd><dt>11</dt><dd>Reader / writer (of the attachment)</dd><dt>12</dt><dd>Read / write device (the mobile electronic device)</dd><dt>13</dt><dd>Device internal protection</dd><dt>14</dt><dd>Unique device identifier</dd></dl>
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2012175174A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| WO2011015596A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8713705B2 | Cited by | United States of America | Applicant |
| WO0241125A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| EP1284555A2 | Cites | European Patent Office (EPO) | Search report |
| US2002004910A1 | Cites | United States of America | Search report |
| WO9804967A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
3 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 102004059637 | Germany | – | |
| 102004059637 | Germany | A |
Members3
| Document | Office | Kind | |
|---|---|---|---|
| DE102004059637A1 | Germany | A1 | |
| EP1669903A2This record | European Patent Office (EPO) | A2 | |
| EP1669903A3 | European Patent Office (EPO) | A3 |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | |
| First examination report despatched17Q | 17Q | |
| Designation fees paidAKX | AKX | |
| Request for examination filed17P | 17P | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | |
| Designated contracting statesAK | AK | |
| Request for extension of the european patentAX | AX | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI |
Numbers
- Publication
- 1669903
- Application
- 50234129
Titles3
- German
- Mobiles elektronisches Gerät mit Zugriffsschutz
- English
- mobile electronic device with access protection
- French
- dispositif electronique mobile avec accès protégé
Classification
- IPC, 5
- G06F21 31
- G06F21 34
- G06F21 71
- G06F21 88
- G06F21 00
Designated states36
- Contracting states, 31
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Netherlands (Kingdom of the)
and 7 moreShow fewer
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 5
- Albania
- Bosnia and Herzegovina
- Croatia
- North Macedonia
- Yugoslavia, later Serbia and Montenegro (until 2006)