EP2207322B1

Adaptive security for information devices

Abstract

This record has no abstract on file.

EP2207322B1, drawing sheet 1
Sheet 1 of 16

Term

2.3 yearsleft in the term

Expires 26 January 2029.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

20 claims: 7 independent, 13 dependent

  1. 1
    An information device having a dynamically configurable security arrangement, the device comprising:computer circuitry, including a processor (20) operatively coupled to a data store;a user interface, including display (14) and user input devices (16);communications circuitry (24) ;and a power supply (28) that provides power to the computer circuitry, user interface, and communications circuitry (24) ;wherein the computer circuitry includes a security arrangement comprising: a configurable security module (300) that provides security-related functionality in the information device according to a configuration of operational settings;a risk profiling module (470) that re-assesses a current set of security risks to which the information device is exposed;a computing capacity determining module (480) that re-assesses computing capacity_availability relating to usage and performance expectations for operation of the information device;and a security configuration module (450) that automatically and dynamically configures the operational settings of the security module (300) based on the current set of security risks from the risk profiling module (470) and on the current state of dynamically-variable computing capacity availability from the computing capacity determining module (480), wherein the security configuration module (450) includes: a configuration determining module (460) that determines, from among a set of security-related functionality with which the security module (300) is to be configured in response to the current set of security risks from the risk profiling module (470), a subset of more essential security functionality and a subset of less essential security functionality relevant to the current set of security risks;and a configuration setting module (465) that sets the configuration of operational settings such that, in response to the computing capacity availability being indicative of a reduction of computing capacity availability from a previous computing capacity availability, the configuration setting module (465) disables the subset of less essential security functionality to an extent that computational loading on the computer circuitry attributable to operation of the configurable security module (300) is reduced to facilitate operation of the information device corresponding to the usage and performance expectations while executing the subset of more essential security functionality in the configurable security module.
  2. 12
    A method for automatically configuring an information device having a security module which executes a set of security function to facilitate usability while providing security protection via a security arrangement for the information device, the method comprising:using computer circuitry, automatically profiling a set of current security risks to which the information device is exposed;using the computer circuitry, automatically determining a set of security functionality with which a security module is to be configured in the information device to protect the information device in response to a result of the profiling of the set of current security risks;using the computer circuitry, automatically re-assessing from among the set of security functionality, a subset of more essential security functionality and a subset of less essential security functionality relevant to the set of current security risks;using the computer circuitry, automatically re-assessing current computing capacity_availability relating to usage and performance expectations for operation of the information device;and using the computer circuitry, automatically and dynamically configuring the security arrangement to run on the information device based on a result of the profiling of the current set of security risks and on a result of the re-assessing of the current computing capacity availability, including: in response to the result of the re-assessing of the current computing capacity availability being indicative of a reduction of computing capacity availability from a previous computing capacity availability, disabling the subset of less essential security functionality to an extent that computational loading on the information device attributable to operation of the configurable security module (300) is reduced to facilitate operation of the information device corresponding to the usage and performance expectations while the information device executes the subset of more essential security functionality.
  3. 16
    The method according to any of claims 12-15, wherein at least one of:said automatically profiling a set of current security risks, said automatically determining the set of security functionality with which the security module is to be configured in the information device, said automatically re-assessing subsets of more essential and less essential security functionality, said automatically re-assessing computing capacity availability, and said automatically and dynamically configuring the security arrangement, is performed by the information device.
  4. 17
    The method according to any of claims 12-16, wherein automatically re-assessing the computing capacity includes assessing a present demand on computing resources based on at least one monitored parameter selected from the group consisting of:application programs in use on the information device, network traffic to or from the information device, processor (20) idling of the information device, an amount of memory allocated on the information device, or any combination thereof.
  5. 18
    The method according to any of claims 12-17, wherein determining the computing capacity includes assessing available computing resources based on a condition of a battery of the information device.
  6. 19
    The method according to any of claims 12-18, further comprising:obtaining, by a computing device, at least one parameter from the user, said parameter being selected from the group consisting of: security risk tolerance information, user experience requirements, or any combination thereof;and wherein configuring the security module (300) is performed based on the at least one parameter.
  7. 20
    The method according to any of claims 12-19, wherein automatically profiling the current set of security risks is performed based on application programs installed or operating on the information device.