EP1817668B1

Terminal, method and computer program product for validating a software application

Abstract

This record has no abstract on file.

EP1817668B1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 14 October 2025, 0.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

15 claims: 4 independent, 11 dependent

  1. 1
    A method comprising a processor:receiving a software application by an apparatus (90);operating an operating system platform of the apparatus;verifying an authenticity of the software application (94, 96) and, only if the authenticity of the software application is verified: installing the software application on the apparatus (98) for operation above the operating system platform;creating a permission record for the software application (100);and storing the permission record in a policy database of the operating system platform (102), the permission record including at least one permission identifying at least one service the software application is authorized to receive from the operating system platform, the permission record being editable by a user of the apparatus to indicate at least one service the user has authorized the software application to receive from the operating system platform;receiving a request from the software application for a service of the operating system platform (118), the request being received after the software application is executed for operation and while operating;determining if the software application is authorized to receive the requested service based upon the permission record (120,122);providing the requested service to the software application if the software application is authorized to receive the requested service (124);and maintaining the permission record in a volatile memory (50) until the software application is closed.
  2. 2
    A method according to Claim 1, wherein receiving a request from the software application comprises receiving a plurality of requests from the software application for at least one service of the OS platform, wherein determining if the software application is authorized comprises determining, for each requested service, if the software application is authorized to receive the requested service based upon the associated permission record.
  3. 3
    A method according to Claim 1, wherein verifying an authenticity comprises verifying an authenticity of the software application based upon a source of the software application, the software application having previously been received from the source.
  4. 4
    A method according to Claim 1 further comprising:initiating loading of the software application;verifying an integrity of the software application;and loading the software application for Operation on the apparatus if the integrity of the software application is verified, wherein initiating loading of the software application, verifying the integrity, and loading the software application occur before receiving a request from the software application for a service of the operating system platform.
  5. 5
    A method according to Claim 4, wherein the permission record associated with the software application further includes a signature associated with the software application, and wherein verifying an integrity of the software application comprises:generating a verification signature based upon the software application;comparing the verification signature with the signature in the permission record associated with the software application;and verifying the integrity of the software application based upon the comparison.
  6. 8
    A computer-readable storage medium comprising machine readable instructions that when executed by computing apparatus controls it to perform the method of any of claims 1 to 7.
  7. 9
    Apparatus (10) comprising:means for receiving a software application (54a, 54b);means for operating an operating system platform of the apparatus;means for verifying an authenticity of the software application (54a, 54b) and, only if the authenticity of the software application (54a, 54b) is verified: installing the software application (54a, 54b) on the apparatus (10) for operation above the operating system platform;creating a permission record for the software application (54a, 54b);and storing the permission record in a policy database (108) of the operating system platform, the permission record including at least one permission identifying at least one service the software application (54a, 54b) is authorized to receive from the operating system platform, the permission record being editable by a user of the apparatus (10) to indicate at least one service the user has authorized the software application (54a, 54b) to receive from the operating system platform;means (78) for receiving a request from the software application for a service of the operating system platform, the request being received after the software application (54a, 54b) is executed for operation and while operating;means (88) for determining if the software application (54a, 54b) is authorized to receive the requested service based upon the permission record;means (76a, 76b, 76c) for providing the requested service to the software application (54a, 54b) if the software application is authorized to receive the requested service;and means for maintaining the permission record in a volatile memory (50) until the software application is closed.
  8. 10
    The apparatus of Claim 9, wherein receiving a request from the software application comprises receiving a plurality of requests from the software application for at least one service of the OS platform, wherein determining if the software application is authorized comprises determining, for each requested service, if the software application is authorized to receive the requested service based upon the associated permission record.
  9. 11
    The apparatus of Claim 9, wherein verifying an authenticity comprises verifying an authenticity of the software application based upon a source of the software application, the software application having previously been received from the source.
  10. 12
    The apparatus of Claim 9 further comprises:means for initiating loading of the software application;means for verifying an integrity of the software application;and means for loading the software application for operation on the apparatus if the integrity of the software application is verified, wherein the apparatus is configured such that initiating loading of the software application, verifying the integrity, and loading the software application occur before receiving a request from the software application for a service of the operating system platform.
  11. 13
    The apparatus of Claim 12, wherein the permission record associated with the software application further includes a signature associated with the software application, and wherein verifying an integrity of the software application comprises:generating a verification signature based upon the software application;comparing the verification signature with the signature in the permission record associated with the software application;and verifying the integrity of the software application based upon the comparison.
  12. 14
    The apparatus of any of Claims 9 to 13, wherein the apparatus is a mobile terminal
  13. 15
    The apparatus of any of claims 9-14, wherein the policy database is included in a kernel (80) of the operating system platform (102).