EP2207322A1

Adaptive security for information devices

Abstract

An information device includes a dynamically configurable security module in which operational settings are automatically and dynamically configured based on risk profile or computing capacity information, or both.

EP2207322A1, drawing sheet 1
Sheet 1 of 17

Term

2.3 yearsto projected expiry

Projected expiry 26 January 2029, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

20 claims: 9 independent, 11 dependent

  1. 1
    An information device having a dynamically configurable security arrangement, the device comprising:computer circuitry, including a processor operatively coupled to a data store;a user interface, including display and user input devices;communications circuitry;and a power supply configured to provide power to the computer circuitry, user interface, and communications circuitry;wherein the computer circuitry includes a security arrangement comprising: a configurable security module arranged to provide security-related functionality in the information device according to a configuration of operational settings;a risk profiling module configured to re-assess a current set of security risks to which the information device is exposed;a computing capacity determining module configured to re-assess computing capacity availability relating to usage and performance expectations for operation of the information device;and a security configuration module arranged automatically and dynamically to configure the operational settings of the security module based on the current set of security risks from the risk profiling module and on the current state of dynamically-variable computing capacity availability from the computing capacity determining module, wherein the security configuration module includes: a configuration determining module arranged to determine, from among a set of security-related functionality with which the security module is to be configured in response to the current set of security risks from the risk profiling module, a subset of more essential security functionality and a subset of less essential security functionality relevant to the current set of security risks;and a configuration setting module arranged to set the configuration of operational settings such that, in response to the computing capacity availability being indicative of a reduction of computing capacity availability from a previous computing capacity availability, the configuration setting module disables the subset of less essential security functionality to an extent that computational loading on the computer circuitry attributable to operation of the configurable security module is reduced to facilitate operation of the information device corresponding to the usage and performance expectations while executing the subset of more essential security functionality in the configurable security module.
  2. 3
    An information device according to claims 2, wherein the configurable security module is arranged to store a plurality of threat definitions and to scan at least one of the data store and network traffic for any presence of security threats based on the plurality of threat definitions, and wherein the computing capacity determining module is arranged to disable a subset of less essential security functionality by reducing the quantity of threat definitions on which the scanning is based.
  3. 8
    An information device according to nay preceding claim, wherein the computing capacity determining module is arranged to assess available computing resources based on at least one parameter selected from the group consisting of:application programs in use, network traffic, processor idling, an amount of memory allocated, an amount of memory available in the data store, a condition of the on-board energy source, or any combination thereof.
  4. 12
    A method for automatically configuring an information device to facilitate usability while providing security protection for the information device, the method comprising:using a computing device, automatically profiling a set of current security risks to which the information device is exposed;using a computing device, automatically determining a set of security functionality with which a security module is to be configured in the information device to protect the information device in response to a result of the profiling of the set of current security risks;using a computing device, automatically re-assessing from among the set of security functionality, a subset of more essential security functionality and a subset of less essential security functionality relevant to the set of current security risks;using a computing device, automatically re-assessing current computing capacity_availability relating to usage and performance expectations for operation of the information device;and using a computing device, automatically and dynamically configuring the security arrangement to run on the information device based on a result of the profiling of the current set of security risks and on a result of the re-assessing of the current computing capacity availability, including: in response to the result of the re-assessing of the current computing capacity availability being indicative of a reduction of computing capacity availability from a previous computing capacity availability, disabling the subset of less essential security functionality to an extent that computational loading on the information device attributable to operation of the configurable security module is reduced to facilitate operation of the information device corresponding to the usage and performance expectations while the information device executes the subset of more essential security functionality.
  5. 16
    A method according to any of claims 12-15, wherein at least one of:said automatically profiling a set of current security risks, said automatically determining a set of security functionality with which a security module is to be configured in the information device, said automatically re-assessing subsets of more essential and less essential security functionality, said automatically re-assessing computing capacity availability, and said automatically and dynamically configuring the security arrangement, is performed by the information device.
  6. 17
    A method according to any of claims 12-16, wherein automatically re-assessing the computing capacity includes assessing a present demand on computing resources based on at least one monitored parameter selected from the group consisting of:application programs in use on the information device, network traffic to or from the information device, processor idling of the information device, an amount of memory allocated on the information device, or any combination thereof.
  7. 18
    A method according to any of claims 12-17, wherein determining the computing capacity includes assessing available computing resources based on a condition of a battery of the information device.
  8. 19
    A method according to any of claims 12-18, further comprising:obtaining, by a computing device, at least one parameter from the user, said parameter being selected from the group consisting of: security risk tolerance information, user experience requirements, or any combination thereof;and wherein configuring the security module is performed based on the at least one parameter.
  9. 20
    A method according to any of claims 12-19, wherein automatically profiling the current set of security risks is performed based on application programs installed or operating on the information device.