EP2575319B1

Portable security device and methods for dynamically configuring network security settings

Abstract

This record has no abstract on file.

EP2575319B1, drawing sheet 1
Sheet 1 of 7

Term

5.8 yearsleft in the term

Expires 19 July 2032.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

7 claims: 2 independent, 5 dependent

  1. 1
    A method for dynamically configuring network access setting for a user device (110) connected to a wireless network (130) by a network security device (160), the method comprising:collecting by the security device (160) hardware and software information from the user device (110) for assessing security characteristics of the user device (110) ;obtaining network configuration setting of the wireless network (130) for assessing security characteristics of the wireless network (130) ;selecting security settings that control operation of at least one application on the user device (110) based on the security characteristics of the user device (110) and the security characteristics of the wireless network (130);detecting changes in the security characteristics of the user device (110) or the security characteristics of the wireless network (130) in order to modify the security settings that control operation of the at least one application on the user device (110);regulating by the security device (160) the network access of the user device (110) based on the changed security settings;and based on an assessment of the security characteristics of the user device (110) and the security characteristics of the wireless network (130): selecting high security settings when both the user device (110) and the wireless network (130) are found unsecure by: deactivating one or more Internet-accessing applications on the user device (110), activating one or more Internet-accessing applications on the security device (160), activating a data input user interface of the security device (160) for entering user authentication data associated with the one or more activated Internet-accessing applications, and transmitting an application-related data and the user authentication data to and from the user device (110) through the first (150a) and second (150b) secure network connections;selecting medium security settings when one of the user device (110) and the wireless network (130) is found unsecure by: activating one or more Internet-accessing applications on the user device (110), activating a data input user interface of the security device (160) for entering user authentication data associated with the one or more activated Internet-accessing applications, and transmitting an application-related data and the user authentication data to and from the user device (110) through the first (150a) and second (150b) secure network connections;and selecting low security settings when both the user device (110) and the wireless network (130) are found secure by: activating one or more Internet-accessing applications on the user device (110), activating a data input user interface of the user device (110) for entering user authentication data associated with the one or more activated Internet-accessing applications, and transmitting an application-related data and the user authentication data to and from the user device (110) through the first (150a) and second (150b) secure network connections.
  2. 5
    A security device (160) for dynamically configuring network access setting for a user device (110) connected to a wireless network (130) by the network security device (160), the device (160) comprising:at least one network module (250a, 250b) configured to: collect hardware and software information from the user device (110) for assessing security characteristics of the user device (110) ;obtain network configuration setting of the wireless network (130) for assessing security characteristics of the wireless network (130) ;select security settings that control operation of at least one application on the user device (110) based on the security characteristics of the user device (110) and the security characteristics of the wireless network (130);detect changes in the security characteristics of the user device (110) or the security characteristics of the wireless network (130) in order to modify the security settings that control operation of the at least one application on the user device (110) ;regulate the network access of the user device (110) based on the changed security settings;and based on an assessment of the security characteristics of the user device (110) and the security characteristics of the wireless network (130): select high security settings when both the user device (110) and the wireless network (130) are found unsecure by: deactivating one or more Internet-accessing applications on the user device (110), activating one or more Internet-accessing applications on the security device (160), activating a data input user interface of the security device (160) for entering user authentication data associated with the one or more activated Internet-accessing applications, and transmitting an application-related data and the user authentication data to and from the user device (110) through the first (150a) and second (150b) secure network connections;select medium security settings when one of the user device (110) and the wireless network (130) is found unsecure by: activating one or more Internet-accessing applications on the user device (110), activating a data input user interface of the security device (160) for entering user authentication data associated with the one or more activated Internet-accessing applications, and transmitting an application-related data and the user authentication data to and from the user device (110) through the first (150a) and second (150b) secure network connections;and select low security settings when both the user device (110) and the wireless network (130) are found secure by: activating one or more Internet-accessing applications on the user device (110), activating a data input user interface of the user device (110) for entering user authentication data associated with the one or more activated Internet-accessing applications, and transmitting an application-related data and the user authentication data to and from the user device (110) through the first (150a) and second (150b) secure network connections.