EP2207323B1

Adaptive security for portable information devices

Abstract

This record has no abstract on file.

EP2207323B1, drawing sheet 1
Sheet 1 of 16

Term

2.3 yearsleft in the term

Expires 28 January 2029.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

20 claims: 7 independent, 13 dependent

  1. 1
    A portable information device (10) having a dynamically configurable security arrangement, the device comprising:computer circuitry, including a processor (20) operatively coupled to a data store;a user interface, including display (14) and user input devices;wireless communications circuitry (24);and a power supply (28) configured to provide power to the computer circuitry, user interface, and wireless communications circuitry, the power supply including an on-board energy source (30);wherein the computer circuitry includes a security arrangement comprising: a configurable security module (400) that selectively performs security services in the portable information device (10);a location determining module (414) configured to determine and provide an indication of a current location of the portable information device (10);a location profile database (416) containing security risk profile information for a plurality of local networks at a plurality of geographic locations;and a security configuration module (410) arranged to use the indication of the present location to assess a current security risk to which the portable information device (10) is exposed based on risk profile information contained in the location profile database (416) corresponding to the present location, and arranged dynamically to configure the security module (400) to provide for certain ones of the security services to be selectively performed by either a security server (352) that is located remotely from the portable information device (10);or by the security module (400).
  2. 12
    A method for automatically configuring a security module (400) on a portable information device (10), the method comprising:automatically determining, by the portable information device (10), a current location of the portable information device (10);automatically maintaining, by the portable information device (10), a location profile database (416) containing security risk profile information for a plurality of local networks at a plurality of geographic locations;automatically re-assessing, by the portable information device (10), a current security risk to which the portable information device is exposed based on risk profile information contained in the location profile database (416) corresponding to the present location;and automatically re-configuring the security module (400) based on the current security risk such that the security module (400) selectively performs security services by either a security server (352) that is located remotely from the portable information device (10);or by the security module (400).
  3. 16
    A method according to any of claims 12-15, further comprising:re-assessing a current state of computing capacity availability of the portable information device (10);and re-configuring the security module (400) in response to the current state of computing capacity availability.
  4. 17
    A method according to any of claims 12-16, further comprising:storing a plurality of threat definitions, and scanning data stored in, or communicated with, the portable information device (10) for any presence of security threats based on the plurality of threat definitions.
  5. 18
    A method according to any of claims 12-17, wherein the automatically reconfiguring of the security module (400) includes configuring the security module (400) based on available network communications bandwidth of the portable information device (10).
  6. 19
    A method according to any of claims 12-18, wherein the automatically reconfiguring of the security module (400) includes configuring the security module (400) based on available computing capacity of the portable information device (10).
  7. 20
    A method according to any of claims 12-19, further comprising:obtaining at least one parameter from the user selected from the group consisting of: security risk tolerance information, user experience requirements, or any combination thereof;and configuring the security module (400) based on the at least one parameter.