Storing and accessing data in a mobile device and a user module
Abstract
Procedure for storing configuration data (62) and accessing them, as well as for executing at least one application program (46) on a mobile device (10), especially a mobile phone or a personal digital assistant that It has a device memory (38) for the application program (46) and is connected via an interface (14) with a user module (12) that has a module memory (52). characterized in that the configuration data (62) also refers, as a minimum, to the availability of the application program (46) or certain functions thereof, and that the configuration data (62) is stored in the module memory ( 52) and are read from it to determine if the application program (46) is executed, and to what extent it is executed.

Term
Term ended
Projected expiry passed 2 December 2022, 3.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
9 claims: 2 independent, 7 dependent
- 1ES 2 289 615 T3 REIVINDICACIONES 1. Procedimiento destinado a almacenar datos de configuración (62) y acceder a los mismos, así como para ejecutar, como mínimo, un programa de aplicación (46) en un aparato móvil (10), en especial un teléfono móvil o un asistente personal digital que dispone de una memoria de aparato (38) para el programa de aplicación (46) y que está conectado mediante una interfaz (14) con un módulo de usuario (12) que dispone de un memoria de módulo (52), caracterizado porque los datos de configuración (62) también se refieren, como mínimo, a la disponibilidad del programa de aplicación (46) o de determinadas funciones del mismo, y porque los datos de configuración (62) están almacenados en la memoria de módulo (52) y se leen desde la misma para determinar si se ejecuta el programa de aplicación (46), y en qué medida se ejecuta.
- 2Procedimiento, según la reivindicación 1, caracterizado porque la lectura de los datos de configuración (62) desde la memoria de módulo (52) está protegida mediante una contraseña y/o una comprobación biométrica.
- 3Procedimiento, según las reivindicaciones 1 ó 2, caracterizado porque se descargan en la memoria de aparato (38), como mínimo, partes del programa de aplicación (46) de forma correspondiente con los datos de configuración (62).
- 4Procedimiento, según una de las reivindicaciones 1 a 3, caracterizado porque el aparato móvil (10) es un aparato que también dispone de funciones de telecomunicaciones.
- 5Procedimiento, según una de las reivindicaciones 3 y 4, caracterizado porque la transmisión, como mínimo, de partes del programa de aplicación (46) a la memoria de aparato (38) se realiza utilizando, como mínimo, una de las funciones de telecomunicaciones del aparato móvil (10).
- 6Procedimiento, según una de las reivindicaciones 1 a 5, caracterizado porque el módulo de usuario (12) también es un módulo de identificación de abonado previsto para el registro en una red de telecomunicaciones (18).
- 7Aparato móvil (10), en especial un teléfono móvil o un asistente personal digital, dotado de una memoria de aparato (38) para un programa de aplicación (46) y conectado mediante una interfaz (14) a un módulo de usuario (12) que comporta una memoria de módulo (52), caracterizado porque la interfaz (14) está configurada para leer los datos de configuración (62) de la memoria de módulo (52), de manera que dichos datos de configuración también se refieren, como mínimo, a la disponibilidad del programa de aplicación (46) o de determinadas funciones del mismo, y porque el aparato móvil (10) está preparado para determinar, según los datos de configuración (62) leídos desde la memoria de módulo (52), si se ejecuta el programa de aplicación (46), y en qué medida se ejecuta.
- 8Aparato móvil (10), según la reivindicación 7, preparado para realizar, en combinación con un módulo de usuario (12), un procedimiento, según una de las reivindicaciones 1 a 7.
- 9Módulo de usuario (12), en especial un módulo de identificación de abonado para una red de telecomunicaciones (18), preparado para realizar, en combinación con un aparato móvil (10), según la reivindicación 7, un procedimiento, según una de las reivindicaciones 1 a 6.
Independent claims9
46 paragraphs in 5 sections, as filed
ES 2 289 615 T3
DESCRIPTION
Storage and access to configuration data on a mobile device and user module.
The present invention relates to the general technical field of data storage and access to mobile devices, as well as to user modules for such devices. A preferred field of application of the invention is that of mobile devices, which offer the user both telecommunications functions (for example, the transmission of voice and / or data through a telecommunications network) and application programs (for example, a agenda or a text editor). Such mobile devices may be equipped as high performance mobile phones or as PDA personal digital assistants (PDA = "personal digital assistant").
The German document DE 197 24 901 A1 shows a mobile phone according to the GSM standard (GSM = 'global system for mobile communication'). The mobile telephone has a control unit, a device memory and an interface for a SIM subscriber identification module (SIM = "subscriber identification module"). Using a connection line to a computer, user data, for example address lists, sales data or price lists, can be loaded into the device memory. Furthermore, provision is made for the possibility of loading into the device memory, by means of the connection line, programs not specified in more detail, and subsequently making the mobile phone execute said programs. Data transmission can be done with integrity assurance or with encryption.
The European document EP 0 730 387 A2 discloses a mobile telephone that can be called by several call numbers. Each of the call numbers, which are stored in a "Number assignment module", is assigned to a different phone book and / or speed dial list.
US patent US-PS 5,814,798 discloses the use of a portable data carrier for storing user preferences for, for example, a mobile phone. These preferences are used, for example, to adjust color, lightness, and contrast, or to define a special character set, and so on.
Generally, when a GSM mobile phone is connected, an authorization check takes place, in which the user is asked to enter a personal secret PIN (PIN = "personal identification number"). The entire user area, including the options for accessing the user data stored on the mobile phone, is only released when the secret number is entered correctly. In this way, the most confidential data is protected to a certain extent. However, the problem remains that this security element can be bypassed by a determined criminal. For example, by means of suitable devices, it is possible to read components from the memory of the mobile phone directly at the hardware level.
The storage of user data in the mobile device is especially convenient when the mobile device is also configured to run application programs for the processing of said user data. These functions are already available today in high-performance GSM mobile phones and PDAs. For mobile devices of generations 2,5 and 3, for example, devices for networks GPRS (“general packet radio service”), EDGE, UMTS (“universal mobile telecommunications system”) and WCDMA (“wideband code-division multiple access ”), Through the wireless interface application programs can be downloaded and / or updated from a service provider to the mobile device, thanks to the high data transmission speed.
In the aforementioned mobile devices there are still problems or it is necessary to improve them in several aspects. First of all, in this case too, it is necessary to prevent unauthorized access to application programs. Thus, it must be ensured that an application program, or certain secure functions thereof, can only be used by the authorized user. Second, it would be desirable to have the ability to offer the user a selection of functions best suited to his needs. Third, it should be ensured, as far as possible, that the apparatus are independent of the functions made available.
EP-A 1 107 627 discloses a mobile device for which the storage and reading of configuration data as well as the execution of application programs are described, and in which the application programs are stored in a memory of the device. However, the user has no information about which application programs or individual functions are available on the mobile phone.
The invention aims to solve, in part or totally, these problems. In particular, the invention should increase the security and protection against unauthorized access to the application programs of a mobile phone. Furthermore, in its preferred configurations, the invention must provide the user with high comfort, and must be able to be performed economically.
According to the invention, these objectives are achieved, partially or totally, by a method with the features of claim 1, a mobile device with the features of claim 7 and a user module with the features of claim 9. The dependent claims relate to preferred embodiments of the invention.
ES 2 289 615 T3
The invention starts from the basic idea that the aforementioned security requirements can be satisfied by suitable storage of the configuration data.
The invention is based on the fundamental concept of indicating, by means of the configuration data, the availability of the entire application program or of each of its functions. The configuration data is stored in the user module, while the application program is in the mobile device. The application program is only executed, totally or partially, as indicated by the configuration data.
The concept on which the invention is based provides protection against unauthorized execution of the application program, or of certain functions thereof, since, in addition to the mobile device, the user module is always necessary with the corresponding configuration data that authorize the execution of the program. Furthermore, the invention provides the technical bases necessary to offer a program configuration exactly adapted to the needs of the user. This is especially important when, for the use of the program, a fee must be paid depending on the functionalities offered, as happens, for example, with the services of ASP application service providers (ASP = “application service provider”). Since, according to the invention, the configuration data is stored in the user module, the user module can establish the desired configuration on any compatible mobile device, simply by reconnecting the user module.
The term "application program" used in the present description refers, in particular, to the programs that carry out processing functions of the aforementioned user data. When the mobile device has telecommunication functions, the application programs are preferably independent of these telecommunication functions, or they can be used for other purposes. Common application programs include work calendars, address lists, word processing programs, calculation tables, databases, dictation recording programs, and so on. Among the programs in the present description are called application programs, there are also programs that only provide the user screen for the aforementioned programs or for similar applications (while the server of an ASP executes the processing operations themselves). In some configurations, browsers and viewers are also provided as application programs for the formatted presentation of documents. The application programs can also be multimedia content playback programs, for example for the MP3 sound format.
To better protect against unauthorized execution of the application programs, the reading of the configuration data is ensured, preferably by means of a password and / or a biometric check, for example, a voice or fingerprint analysis. The user module only releases the configuration data to allow access to the execution of the corresponding application program or the corresponding function of a program, once the user has been properly identified by means of the password and / or his / her biometric data.
The functionality disclosed by the invention can also be used in mobile devices that carry one or more permanently stored application programs. However, the configuration data also preferably serves to direct the download to the mobile phone of application programs or at least parts of them. Especially with mobile devices that have functions for high-capacity wireless data transmission, the necessary application programs or program modules can be downloaded via the wireless interface from an external service provider. This possibility is especially advantageous in relation to the services of an ASP. User comfort is greatly increased when you can start on any compatible mobile device, simply by using the user module, the automatic download of the application programs corresponding to your configuration. The use of programming languages independent of the computing platform, such as the Java language<sup>®</sup>, supports a manufacturer-independent download of application programs.
It is especially advantageous to combine the two mentioned aspects of the invention, since, in this way, protection against unauthorized access to user data and protection against illegal execution of application programs are achieved.
In preferred configurations, the mobile device is a telecommunications device, especially a mobile phone or a personal digital assistant (PDA) provided with telephony functions. The user module is preferably a SIM subscriber identification module (SIM = "subscriber identification module"), such as that required to register in a telecommunications network. In particular, a tamper-proof user module, such as a so-called “trusted device” or “tamper resistant device”, can be used so that the encryption and encryption functions cannot be bypassed. decryption, key data, or confidential configuration data. The use of a subscriber identification module is also convenient when the mobile device does not have telephony functions, or when the module is not registered with a telephone operator, since such modules are manufactured in large quantities, so their cost is relatively low.
Preferably, the mobile device and the user module are enhanced with features that correspond to the features described above and / or those mentioned in the dependent claims.
The following detailed description of an example of embodiment of the invention, and of various alternative embodiments, reveal other characteristics, advantages and objectives of the invention. Figure 1 of the schematic drawing3
ES 2 289 615 T3 shows a block diagram of the main functional units of a system, according to this embodiment of the invention.
Figure 1 shows a mobile device (10) and a user module (12), connected to each other via an interface (14). In this exemplary embodiment, the mobile device (10) is configured as a high-performance mobile telephone, which offers telecommunications functions according to the GSM Standard for telephone services, and the GPRS system for data transmission services. Correspondingly, the user module (12) is configured as a SIM card that is inserted into the mobile phone or that is fixedly arranged within it. The mobile device (10) can access a corresponding telecommunications network (18) through a wireless interface (16). In other alternative embodiments, the mobile device 10 is configured according to an improved telephony standard, for example UMTS, and / or as a personal digital assistant (PDA), which can also have multimedia capabilities.
In a basically known way, the mobile device (10) includes a high frequency stage (20) that emits and receives radio waves by means of an antenna (22). A digital signal processor (DSP) (24) processes the transmitted or received signals. In addition, the signal processor (24) processes the low-frequency signals that are led to a loudspeaker (28) by means of a low-frequency stage (26), or those that, coming from a microphone (30), are sent to the digital signal processor (24) by means of the low frequency stage (26). A processor unit (32) coordinates all the processes that take place in the mobile device (10). The processor unit (32) is connected, through the interface (14), with the digital signal processor (24), with an indicator (34) configured in this case as an LCD screen, with a keyboard (36) and with a device memory (38). Device memory 38 may be configured for fixed or removable installation, eg, in the form of a memory card.
The appliance memory (38) contains several semiconductor chips of various memory technologies. In the conceptual representation of Figure 1, the device memory (38) includes a read-only zone (40) (for example, made as ROM programmed with mask) and a zone (42) for writing, made as RAM or EEPROM , or as flash memory. The read-only area (40) of the device memory (38) contains, in particular, the operating programs (44) that the processor unit (32) executes as the basic operating system of the mobile device (10), as well as the necessary to use telecommunication functions. In the writing area (42) the application programs (46) and user data (48) are loaded.
Figure 1 shows as examples of application programs (46) a work calendar (46.1) (with address listing function) and a text editor (46.2). The user data (48) shown in figure 1 is a list of appointments and addresses (48.1) for the work calendar (46.1), as well as a letter (48.2) for the text editor (46.2). The application programs (46) are executed by the processor unit (32) and use the user data (48). The user data (48) is stored in the device memory (38) in encrypted form, which is represented in Figure 1 by a broken line.
The user module (12) is configured as a subscriber identification module (SIM) for the telecommunications network (18), and also the interface (14), from the mechanical and electrical point of view, conforms to the standards provided for this telecommunications network (18). The user module (12) includes a processor unit (50) configured as a microcontroller, integrated in a single chip together with a memory module (52). The memory module (52) is divided, by different memory technologies, into a read-only zone (54) and a write zone (56).
The memory module (52) contains the data and control programs that provide the basic functions of the operating system to the user module (12), and that, in addition, allow the registration and operation of the mobile device (10) for the telecommunications using the telecommunications network (18). For the sake of drawing clarity, Figure 1 does not separately show said data and control programs. The cryptographic functions (58) are stored in the memory module's read-only area (54), while the key data (60) and configuration data (62) are stored in the write area (56).
The cryptographic functions (58) comprise an encryption function (64), a decryption function (66) and a key generation function (68). The key data (60) is a public key (70) and a private key (72). The configuration data (62) includes, for each application program (46) provided in the mobile device (10), a corresponding set of data, specifically, in this exemplary embodiment, a set (62.1) of configuration data for the work schedule (46.1) as well as a set (62.2) of configuration data for the text editor (46.2).
The operation of the system shown in figure 1 includes the usual telecommunications functions according to the corresponding standards, in this case GSM and GPRS. Furthermore, the user can use the application programs (46) and process user data (48) or other data with them.
To start the application programs (46), when the mobile device is connected, or at the latest when the user wishes to start an application program (46), the mobile device (10) accesses the configuration data ( 62) of the user module (12). This access is carried out through the processor unit (50) of the user module (12), which, in turn, requests that a password be entered before allowing access to the data. The password request appears on the display (34) of the mobile device (10), and the user enters the corresponding password using the keyboard (36). The processor unit (50) checks that the password is correct.
ES 2 289 615 T3
If the user has entered the correct password, the user module (12) transmits to the mobile device (10) the configuration data (62) requested (all the configuration data -62-, or only the data set -62.1 -, -62.2- provided for the corresponding application program -46.1-, -46.2-). The processor unit (32) then checks, according to the configuration data (62), (62.1), (62.2), whether access is authorized for the execution of the application programs (46), or of the specific program of application (46.1), (46.2) requested. If so, the program is allowed to run.
When the desired application program (46.1), (46.2) is already in the device memory (38), the program can be started without further ado. Otherwise, the required program or user data, which may be subject to payment of a fee, is downloaded into the device memory (38) from a server of an ASP operator, using the wireless interface (16) to the telecommunications network (18). This download operation must also be authorized by the user module (12), which in this case acts as a command for the entrance door. Although the application program (46.1), (46.2) is already in the device memory (38), it is also possible to make a query to the ASP provider through the interface (16) for the transmission of accounting data, or to download in the mobile device (10) possible program updates.
In the exemplary embodiment described in the present description, the configuration data (62) refers not only to the basic user authorizations, but also to the settings of the application programs (46) preferred by the user, for example, default data paths, language definitions, menu settings, and other user preferences. The application program (46) has access to these settings when it is started, so that the user always works with the desired configuration of the program. This also happens when the user connects his user module (12) to a new or different mobile device (10).
With sufficient standardization of API application programming interfaces (API = “application programming interfaces”), such as can be expected in the medium term, for example, by using the Java programming language<sup>®</sup>, an ASP provider may offer each user customized application program services independent of the mobile device (10) used. Furthermore, a high level of security is achieved thanks to the fact that all application programs (46) can only be started when the user module (12) is present and after the password has been entered. To prevent abuse in the event of theft of the connected mobile device (after the user has entered the password), it can be foreseen that a password will be requested again when the user's activity is interrupted for a predetermined time, in the way already known in the screensavers for desktop computers.
In the embodiment described above, an application program (46) has been considered as the smallest unit for the authorization mechanism and, where appropriate, for the download process via the wireless interface (16). However, depending on the programming technology used, finer granularity can also be used. For example, the configuration data (62) can refer to the authorization of the user to execute certain functions of the program, or certain modules of the program since, if necessary, by means of the interface (16), these can be loaded separately. functions or program modules. This procedure avoids long charging times and can also be adjusted more precisely to user preferences. Also for updating the application programs (46) via the wireless interface (16), preferably only those program modules that have been modified with respect to the version actually found on the mobile device (10) are transferred.
User data (48) processed by application programs (46) is stored in encrypted form, or at least partially encrypted, in device memory (38). For example, a file system for storing user data (48) can be provided for the user, in which each folder or each disk drive can be adjusted, as desired, to an encrypted or unencrypted data storage. . The similar function for desktop computers, without using a user module, of the PGPdisk product is known.<sup>®</sup> Network Associates, Inc.
When the application program (46) wants to store user data (48) in an area of the file system intended for encryption, the processor unit (32) transmits said data to the user module (12) through the interface (14) . The processor unit (50) of the user module (12) executes the encryption function (64) using the public key (70) contained in the key data (60). The encrypted user data (48) is stored in the appliance memory (38) via the interface (14) and the processor unit (32).
Access to the stored encrypted user data (48) is done accordingly. Also in this case, the processor unit (50) of the user module (12) decrypts the data using the decryption function (66) and the private key (72). The processor unit (50) previously prompts the user to enter a password. The decryption process is allowed only after the password ("passphrase") has been entered through the keyboard (36), (or, when another biometric identification has been successfully completed).
In the present example, encryption and decryption are performed using an asymmetric RSA procedure. On the other hand, other asymmetric or symmetric encryption and decryption procedures, or mixed forms thereof, are envisaged in other alternative embodiments, for example, symmetric encryption using an asymmetrically encrypted key. In symmetric procedures it is not necessary to differentiate between the public key (70) and the private key (72).
ES 2 289 615 T3
The technique proposed in the present invention fully ensures that the encrypted user data (48) can only be read or used when the user module (12) of the authorized user is connected to the interface (14) and when the user is you have correctly identified, for example, by means of a password.
In the present exemplary embodiment, the processor unit (50) of the user module (12) executes the entire encryption and decryption process, so that the data (60) of the keys never leaves the user module (12 ). However, alternative embodiments have also been envisaged, in which the encryption function (64) and the public key (70), which does not need to be kept secret, are transferred to the mobile device (10) so that the processor unit (32) of the mobile device (10), generally more powerful, can carry out the encryption process. For the decryption process, in some alternative embodiments, the processor unit (32) can also be used, provided that this does not compromise the security of the private key (72).
In the present embodiment, the key generation function (68) is used to generate the key data (60), which is also executed by the processor unit (50) of the user module (12). This program calculates in a basically known way a key pair made up of a public key (70) and a private key (72). In this way, a particularly high security of the data is guaranteed, since the private key (72) does not leave the user module (12), not even during the generation of the keys.
The present exemplary embodiment is not limited to a single encrypted area for user data (48) or to a single cryptographic procedure. For example, as long as there is the corresponding validation with a password, a zone can be deactivated at any time and thus allow access to it. It is also possible to perform a new encryption with the same user module (12), or with a different one. Multiple encrypted zones can also be established and managed, if applicable with different key pairs and / or different sizes.
In particular with the present configuration, which foresees the use of an ASP, the user data (48), in addition to being stored in the mobile device (10), can also be transmitted via the wireless interface (16) to a server of the ASP provider and be stored on that server. The synchronization of the user data (48) stored in the two places can be performed each time an application program (46) accesses to write, or when a user session ends, or at the express request of the user. In this way, the user has, on the one hand, quick access to the user data (48) stored locally and, on the other hand, is independent of the mobile device (10) used, thanks to the fact that, at all times and with Any other mobile device can download the user data (48) stored in the ASP provider.
In some configurations, it is also possible to provide a key component at the network provider or ASP provider. Once the mobile device (10) has registered in the telecommunications network (18), this key component is transmitted through the wireless interface (16), so that the network provider or the ASP provider shares with the user control over certain user data (48) stored in the mobile device (10).
Contents5
1 sheet
Sheet 1
25 members in 10 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 10159398 | Germany | A | |
| 10159398 | Germany | A | |
| 2001159398 | Germany | – | |
| 0500874310159398 | – | – | – |
| DE2001159398 | – | – | – |
Members25
| Document | Office | Kind | |
|---|---|---|---|
| DE10159398A1 | Germany | A1 | |
| WO03049471A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002365818A1 | Australia | A1 | |
| EP1454503A1 | European Patent Office (EPO) | A1 | |
| CN1600039A | China | A | |
| JP2005512425A | Japan | A | |
| US2005120225A1 | United States of America | A1 | |
| EP1560449A1 | European Patent Office (EPO) | A1 | |
| RU2004115025A | Russian Federation | A | |
| EP1454503B1 | European Patent Office (EPO) | B1 | |
| AT362284T | Austria | T | |
| ATE362284T1 | Austria | T1 | |
| DE50210136D1 | Germany | D1 | |
| EP1454503B8 | European Patent Office (EPO) | B8 | |
| EP1560449B1 | European Patent Office (EPO) | B1 | |
| AT373931T | Austria | T | |
| ATE373931T1 | Austria | T1 | |
| DE50210944D1 | Germany | D1 | |
| ES2286333T3 | Spain | T3 | |
| ES2289615T3This record | Spain | T3 | |
| RU2326509C2 | Russian Federation | C2 | |
| JP2008243213A | Japan | A | |
| CN100574528C | China | C | |
| US7962762B2 | United States of America | B2 | |
| JP4874288B2 | Japan | B2 |
Numbers
- Publication
- 2289615
- Publication, DOCDB
- 2289615
- Publication, EPODOC
- ES2289615T
- Application
- 5008743
- Application, DOCDB
- 05008743
- Application, EPODOC
- ES20050008743T
Titles2
- Spanish
- MEMORIZACION Y ACCESO A DATOS DE CONFIGURACION EN UN DISPOSITIVO MOVIL Y MODULO DE USUARIO.
- English
- MEMORIZATION AND ACCESS TO CONFIGURATION DATA IN A MOBILE DEVICE AND USER MODULE.
Classification
- CPC, 15
- H04L63/0853
- H04L63/102
- H04M2215/2026
- H04M2215/32
- H04W4/24
- H04W8/183
- H04W8/22
- H04W8/245
- H04W12/08
- H04W92/18
- G06F21/32
- G06F21/34
- G06F21/602
- G06F21/6245
- H04W12/033
- IPC, 12
- H04M1 725
- G06F21 31
- G06F21 32
- G06F21 35
- G06F21 62
- H04Q1 00
- H04W8 18
- H04W8 22
- H04W8 24
- H04W12 06
- H04W12 08
- H04W92 18