EP1769366B1

System and method of operation control on an electronic device

Abstract

This record has no abstract on file.

EP1769366B1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Expired 29 April 2025, 1.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

15 claims: 2 independent, 13 dependent

  1. 1
    A method of application control for use on an electronic device (30), wherein the method comprises loading onto the device (30) information regarding a device owner as owner information, wherein the information comprises a digital signature public key of the device owner; wherein changes to existing owner information are subject to verification of a digital signature of the device owner using the digital signature public key of the device owner included in the existing owner information; storing on the device (30) owner control information in an authorization record; wherein the owner control information comprises one or more lists of required, allowable or excluded applications and, for each individual allowable and/or required application, an indication of allowable operations for the respective application; wherein the owner control information further comprises a version number; wherein the storing of the owner control information on the device (30) is subject to verification of the digital signature of the device owner; wherein the storing of the owner control information on the device (30) is further subject to the version number of the owner control information being higher than a version number of existing owner control information; and wherein alteration and deletion of the owner control information on the device (30) are restricted to the device owner using the digital signature of the device owner; disabling the device (30) if owner control information has not yet been stored on the device (30), if an application that is on the list of required applications is not present on the device (30), or if an application that is on the list of excluded applications is present on the device (30); controlling operation of the device (30) using the authorization record; receiving an operation request from an application; determining whether the requested operation is allowed to be performed by the application based upon the stored authorization record and an application identifier associated with the application; and allowing the application to perform the requested operation based upon whether the requested operation is determined to be allowed to be performed by the application, wherein the requested operation is selected from the group consisting of:opening a connection;accessing a telephone API;accessing local memory;and communicating with another application.
  2. 13
    A system of application control for use on an electronic device (30), the system comprising:an owner information store (36) configured to store information on the device owner as owner information, wherein the information comprises a digital signature public key of the device owner;wherein changes to existing owner information are subject to verification of a digital signature of the device owner using the digital signature public key of the device owner included in the existing owner information;an authorization record store (38) configured to store owner control information in an authorization record, wherein the owner control information comprises one or more lists of required, allowable or excluded applications and, for each individual allowable and/or required application, an indication of allowable operations for the respective application;wherein the owner control information further comprises a version number;wherein the storing of the owner control information on the device (30) is subject to verification of a digital signature of the device owner;wherein the storing of the owner control information on the device (30) is further subject to the version number of the owner control information being higher than a version number of existing owner control information;and wherein alteration and deletion of the owner control information on the device (30) are restricted to the device owner using a digital signature of the device owner;and software instructions that are configured to consult the authorization record in the authorization record store (38) in order to control operation of the device (30), and in order to determine whether an operation requested by an application operating on the electronic device (30) is allowed to be performed by the application, based upon the authorization record and an application identifier associated with the application, wherein the software instructions are further configured to disable the device (30) if owner control information has not yet been stored on the device (30), if an application that is on the list of required applications is not present on the device (30), or if an application that is on the list of excluded applications is present on the device (30);and wherein the requested operation is selected from the group consisting of: opening a connection;accessing a telephone API;accessing local memory;and communicating with another application.