Providing security in virtualized mobile devices
Abstract
One embodiment is a method of providing security for a virtual mobile device consisting of virtualization software that supports one or more virtual computers, in which the method is (a) at the stage of receiving a security policy on the virtual mobile device. As such, this security policy includes one or more location or location-time scenarios for virtual mobile devices, which are applications that are reduced, how they are reduced, and applications that operate. , And the steps to identify how they behave, and (b) collect one or more of the virtual mobile device location information or information related to the time spent at the location, and location and time information. Includes a step of identifying a scenario associated with one or more of the following, and (c) a step of reducing or operating the application according to the identified scenario.

Term
Projected expiry 28 June 2030.
- Priority
- Filed
- Published
- Today
- Projected expiry
9 claims: 1 independent, 8 dependent
- 11つ以上の仮想計算機をサポートする仮想化ソフトウェアを含む仮想モバイル機器のセキュリティを提供する方法であって、 前記仮想モバイル機器においてセキュリティ・ポリシーを受信する段階であって、このセキュリティ・ポリシーは前記仮想モバイル機器のための1つ以上の位置又は位置-時間シナリオを含み、このシナリオは、削減されるアプリケーション、それらがどのように削減されるか、動作されるアプリケーション、そしてそれらがどのように動作されるかを識別する段階と、 仮想モバイル機器位置情報又は前記位置で費やされる時間に関連している情報の1つ以上を集める段階と、 前記位置および時間情報の前記1つ以上に関連しているシナリオを識別する段階と、 前記識別されたシナリオに従ってアプリケーションを削減するか又は動作させる段階と、 を含む方法。
- 2前記仮想モバイル機器が多くの電話を備え、各々は仮想計算機として具体化され、そしてセキュリティ・ポリシーが前記電話の各々に関連する請求項1記載の方法。
- 3前記電話の1つが、前記電話の別の要求より強いセキュリティ要求を有する請求項2記載の方法。
- 4前記電話セキュリティ・ポリシーの1つが、パスコードを入力する要求に関連している請求項2記載の方法。
- 5前記仮想モバイル機器がその地理的な位置を決定する請求項1記載の方法。
- 6決定が、内蔵GPSデバイス、外部GPSデバイス、所定のブルートゥース・デバイス、又はwifi基地局の1つ以上から情報を得ることに基づいている請求項5記載の方法。
- 7識別する段階が、前記位置情報を前記セキュリティ・ポリシーと比較する段階を含む請求項1記載の方法。
- 8前記セキュリティ・ポリシーが、所定時間の間前記モバイル機器に多くの所定位置のうちのいずれかにあることを要求すること、パスコード入力にロッキングを防止することを要求することが使用禁止になる前の所定時間の間前記モバイル機器に所定位置にあることを要求すること、パスコード入力が要求されない期間を延長する前の所定時間の間前記モバイル機器に多くの所定位置のうちのいずれかにあることを要求すること、一日の時間に応じてアクティビティの無い所定時間の後にパスコード入力を要求するかどうかの決定を要求すること、前記モバイル機器が他のモバイル機器の存在を検出せず、そして1つ以上の所定位置にある場合は、パスコード・ロッキングを使用禁止にすることの1つ以上を含む請求項1記載の方法。
- 9セキュリティ・ポリシーが、遠隔企業サーバから前記仮想モバイル機器内の管理クライアントへの通信に応答して変更される請求項1記載の方法。
Independent claims9
64 paragraphs, as filed
The present invention relates to providing security for a virtual mobile device. [Cross-reference of related applications] [0001] The present application is related to the following applications, which are transferred to the assignee of the present application, filed on the same day as the present application, and "virtual mobile device", "control of use of virtual mobile device". , "Prevention of malware attacks on virtual mobile devices", and "Migration function of virtual mobile devices".
[0002] A mobile device is typically a device such as a mobile phone (eg, an internet-connected multimedia smartphone designed and marketed by Apple under the name iPhone, or Research in Motion. (Research In Motion Refers to BlackBerry® smartphones sold by Limited), media players, handheld game consoles, calculators, etc. As is well known, mobile devices of this type usually have limited physical memory compared to desktop or laptop computers, and because they normally operate on battery power, their power saving features Therefore, they use processors with ARM architecture (formerly advanced RISC machines, and earlier Acorn RISC machines). Also, as is well known, ARM architecture refers to the 32-bit RISC processor architecture developed by ARM Holdings of Maidenhead, UK, which is widely used in many embedded designs.
<p><patcit num="1"><text>Patent Application No. 12 / 466,159</text></patcit></p>
<p> This type of issue related to memory and CPU regulation creates problems when using this type of mobile device.</p>
<p> [0003] One or more embodiments of the present invention are methods of providing security for virtual mobile devices. In particular, one embodiment of the present invention is a method of providing security for a virtual mobile device, including virtualization software that supports one or more virtual computers, the method of which is (a) a security policy in the virtual mobile device. This security policy includes one or more location or location-time scenarios for virtual mobile devices, which are the applications to be reduced and how they are reduced. , Identifying the applications that work, and how they work, and (b) collecting one or more of the mobile device location information or information related to the time spent at the location. It involves identifying scenarios related to one or more of location and time information, and (c) reducing or operating applications according to the identified scenarios.</p>
<figref num="1">[0004] A block diagram of a virtual mobile device manufactured according to one or more embodiments of the present invention is shown.</figref>
[0005] FIG. 1 shows a block diagram of a virtual mobile device 100 made according to one or more embodiments of the present invention. As shown in FIG. 1, the virtual mobile device 100 includes a mobile device hardware 200, a virtualization software layer 300 that interacts with the mobile device hardware 200, and a virtual computer that interacts with the virtualization software layer 300 ("" VM ") 400<sub>1</sub>~400<sub>n</sub>including. As further shown in FIG. 1, the mobile device hardware 200 includes a CPU 210 (eg, and, but not limited to, an ARM processor 210), a memory 220, and various data network interface devices 230 (eg, and). Various, but not limited to, wifi devices 230), various phone interfaces 240 (eg, and, but not limited to, cell wireless phones 240), various mobile device display and voice input / output devices 250.<sub>1</sub>~250<sub>n</sub>(For example, and without limitation, liquid crystal display device 250<sub>1</sub>, Touch screen display device 250<sub>2</sub>, Voice input / output device 250<sub>3</sub>Includes (eg, and but not limited to speakers) and positioning device 260 (eg, and but not limited to GPS determination device 260).
[0006] One or more embodiments of the invention described herein provide a method of using a virtual mobile device. As used herein, the term "mobile device" is used, for example, but not limited to, mobile and / or cell phones, smartphones, multimedia smartphones, media players connected to the Internet. Most widely used, including devices such as handheld gaming devices, calculators, etc.
[0007] According to one or more embodiments of the invention, as shown in FIG. 1, the virtual mobile device 100 operates on the mobile device hardware 200 to provide the virtual mobile device, eg, and is limited. Includes virtualization software layer 300, such as a hypervisor (sometimes called a virtual computer monitor), which is not a thing. According to one or more embodiments of this type, applications that drive the methods of the invention described herein in this type of virtual mobile device are: (a) operating system (guest operating system). In the guest OS "), that is, sometimes referred to as the guest of the virtualization software layer 300), the guest OS 410<sub>1</sub>~410<sub>n</sub>As a person skilled in the art of computer virtualization, this kind of guest OS410<sub>1</sub>~410<sub>n</sub>Easily understand how is supported by the virtualization software layer 300), (b) within the application container supported by the virtualization software layer 300, and (c) within the virtualization software layer 300. Works with software modules, or (d) some of the combinations mentioned above. The pending patent application, entitled "In-Place Shadow Table for Virtualization," which is Patent Document 1 filed on May 14, 2009, is owned by the transferee of the present application and is described herein. As cited in the above, a method of providing the virtualization software layer 300 to the virtual mobile device 100 will be described.
[0008] Some VM400s, as those skilled in the art can understand from Figure 1.<sub>1</sub>~400<sub>n</sub>Can run on the virtual mobile device computer 100 and they are protected from each other as if they were running on different devices, i.e. each VM is physically separate of this kind of VM It is less vulnerable to a failed (ie, virus-infected) VM located in any of the same locations than it would be if it were placed in a handset. This is called isolation, and isolation is important in mobile devices such as mobile phones to protect the baseband stack, that is, the portion of the mobile phone that interacts with the cellular telephone network. This is because a failed baseband stack can disrupt the entire cellular network. In fact, many smartphones now have two processor chips to provide this kind of isolation, and baseband software is burned into ROM. However, the advent of multi-core chips and higher capacity single cores favors combining baseband and application features into a single chip.
[0009] Guest OS 410, as further shown in Figure 1.<sub>1</sub>~410<sub>n</sub>Runs the guest application. As is well known, all of the CPU, memory, and devices must be virtualized to have VMs that are detached from the actual hardware (eg, where each VM has its own handset, ie physical. I think I'm running on a typical phone). There are several options when designing virtualization software. According to one such option, the guest operating system can operate out-of-the-box, it is known as full virtualization, or according to the second option, the source code can be modified, it is paravirtualized. Is known as. As is well known, mobile devices usually have one or more processors, each of which is often an ARM core.
[0010] As is known, typical mobile devices include, but are not limited to, screens, keyboards and buttons, radios, GPS, Bluetooth devices, cameras, imaging devices, microphones, speakers, etc. Includes a large collection of devices like.
[0011] Guest OS 410, as shown in Figure 1.<sub>1</sub>~410<sub>n</sub>Is a set of device drivers (single guest device driver 410)<sub>1</sub>~410<sub>n</sub>(Shown as an example by). Rather than interacting with real devices, these guest device drivers interact with emulated or virtualized devices. As further shown in Figure 1, the virtualization software 300 is VM400.<sub>1</sub>~400<sub>n</sub>Device emulator 320 to virtualize your device<sub>a</sub>~320<sub>m</sub>The virtualization software 300 includes a device driver (device driver 310) that interacts with the physical device of the mobile device 100.<sub>a</sub>And 310<sub>b b</sub>(Shown as an example by). The fully virtualized guest operating system device driver attempts to read or write a specific physical address associated with the physical device, however, each access trap to the virtualization software 300 with device emulator software The virtualization software 300 indicates that these pages are unreadable and unwritable so as to decrypt the proper behavior. Alternatively, it may be paravirtualized so that the guest device driver makes a direct call to the virtualization software 300. In any case, the emulated device then finally communicates with the actual device driver that interacts with the physical device. In this way, the flow is guest device driver ~ device emulator ~ actual device driver ~ physical device. The actual device driver that interacts with the physical device may be part of the virtualization software 300, or in some cases, the actual device driver can assume a particular operating system. It may be in a special driver VM so that the "buggy" driver code does not compromise the rest of the virtualization software 300.
[0012] According to one or more embodiments of the invention, as shown in FIG. 1, the VM is actually interacting with a device emulator, but with a physical device. I think it is acting on. Further, according to one or more embodiments of this type, the device emulator sends data through a transformer stack 350 with a set of transformers, including a filter, a data transformer, a multiplexer, and / or a demultiplexer. According to one or more further embodiments, one or more of the device emulators interact directly with the device driver.
[0013] According to one or more embodiments of the invention, the transformer stack 350 transforms data as it flows between the device emulator and the actual device driver. According to one or more embodiments of this type, the data is flowing, but according to a further embodiment, the control stream and the data packet may be in shared memory. According to one or more embodiments of this type, the transformer is bidirectional in that control and data can flow in either direction. A simple transformer is one for a "forward" path from the device emulator to the actual device driver, for example, two feature pointers that point to the next transformer (or device emulator or device driver) in the data path. It has one feature pointer and another feature pointer for the backward path from the actual device driver to the device emulator. Depending on the physical device driver used, the multiplexer is a transformer with an additional functional pointer for the backward path, and the device selector or demultiplexer is an additional functional pointer for the forward path. A transformer with a function pointer. As shown in FIG. 1, the transformer stack 350 includes transformers A to N. In addition, according to one or more embodiments of the invention, the transformer stack 350 can direct the data flow of the route from the first device emulator to another device emulator. As described below, this allows the second VM to receive the communication sent by the first VM, where the second VM acts as a means by which it allows it to affect functionality.
[0014] A VM may assume that it is contained in a mobile device (eg, a handset) that has a particular physical device (that physical device is emulated by virtualization software 300), of this kind. The corresponding physical device may not be in the handset. For example, the VM may assume that the handset has a wifi device, but the handset may only have 3G and USB Ethernet® devices. In this case, the virtualization software 300 is a transformer that routes the device emulator to one of the set drivers for the actual physical device, eg, and, but not limited to, the device. -Provide a selector or demultiplexer. This type of transformer is an example of a device data stream transformer. According to one or more embodiments of the invention, there may be other transformers along the path through the transformer stack 350 as well. For example, and without limitation, network communication from a particular VM may also be encrypted or compressed by a transformer.
Mobile devices such as handsets may have several VMs running simultaneously to access their guest devices. As mentioned earlier, for each guest device in each VM, there is a device emulator for virtualization software 300 (for example, each VM assumes it has a screen and keyboard). In this way, the virtualization software 300 must multiplex access to each physical device. The exact way multiplexing works depends on the particular device. Some physical devices can be shared (for example, many handsets vibrate to communicate with the owner in a semi-silent way, and in some cases any VM is not capable of vibrating the battery. (Do not). However, some physical devices may be exclusively assigned to VMs such as keyboards. For example, the keyboard is usually dedicated to "foreground" VMs, that is, given the dimensions of the screen, it is likely to be exclusively allocated, and a small image of the screen per VM when the user switches between VMs. VMs running "in the background" may have those screens that are "thumbnailed" so that you can see.
[0016] In such cases, the transformer, eg, and, but not limited to, the multiplexer must send the input data to the appropriate VM. Since it is difficult to automatically determine which VM gains exclusive access to a Bluetooth device, for example, the user can exclusively follow one of many methods to monopolize the physical device. Note that you may have to take action using the user interface to make the assignment.
[0017] As further shown in FIG. 1, according to one or more embodiments of the present invention, the management server 500 is for inserting, removing, or configuring various transformers A through N of the transformer stack 350. Interacts with the management client 340 of the virtualization software 300. Thus, for example, the management server 500 can control the logic within the transformer 350 to remote the device, multicast its data, or use a particular physical device. One way to manage the transformer stack 350 in a dynamic way is for each transformer to maintain a functional pointer table that points to the next transformer on the path, and as mentioned earlier, simple transformers It has two pointers (one for each direction). The virtualization software 300 then suspends communication to and from each VM. Then, when all VMs are hibernated, the function pointer table for each associated transformer is updatable, thereby altering the flow through the transformer stack 350. The set of transformers may be long enough to help keep the overhead low. For example, it may not be necessary to flush the data or duplicate it between each transformer. In addition, control packets may be small, and therefore they can often be held in a small number of registers. In further additions, the data can most likely remain in memory, and the virtualization software 300 will be in the address space of each transformer, VM, and device driver that may need to examine the data. Map this memory.
Inserting, removing, or modifying transformers can compromise the security, isolation, integrity, reliability, and so on of all devices. Thus, according to one or more embodiments of the present invention, a set of transformers on the transformer stack 350 can only operate in user mode and address the data buffers and storage within the transformer stack 350. Also, according to one or more embodiments of this type, it should be directly accessible by the management client 340 so that the keyboard and screen cannot be forged or inserted by some untrusted software. Is.
[0019] As is well known, a virtual machine (VA) is software in which an application and all required operating system services are packaged together to act as a VM. In other words, it is a complete software stack managed and maintained as a unit with a reduced operating system size. According to one or more embodiments of the invention, one or more guest device drivers in a VA (or VM) can interact with a device emulator that interacts with a transformer stack 350. And one or more guest device drivers in the VA (or VM) can interact directly with the device driver for the physical device without going through the transformer stack 350. According to one or more additional embodiments of this type, one or more device emulators of this type that interact with the transformer stack 350 are such that the VA (or VM) acts as a means of communication. Can interact with another device emulator (as directed by Transformers Stack 350) to enable. Thus, according to one or more embodiments of the invention, the control flow from the guest OS device driver may proceed to an intermediate VM or VA. There is no need to distinguish between the actual device and the emulated software. Therefore, the VM may not be able to determine if its GPS display is derived from the true GPS or from the log of the previous display.
[0020] As used herein, the term "pervasive computing service" includes a service that allows one device to find a nearby device and make its own resources available to another. The device collaborates, the authentication model, and many other details all utilize the device's remote processing capabilities. For pervasive computing service applications, special applications are required for each device and each operating system. For example, consider a group camera use case. There: (a) A single phone application takes an image and announces its effectiveness not only through a local ad hoc wifi network, but also through a bluetooth connection. (b) All other phones on the network have an application that searches for this service and moves images. And (c) the authentication mechanism is used to ensure that the images are only sent to them in the group. In this example, some phones may have GPS and the images may be labeled accordingly. On the other hand, other phones may be able to add notes directly to the image. Applications whose location simply fetches images from remote controls may not be able to take advantage of these enhanced applications. Therefore, the user must ensure that he / she uses the correct application, namely the real camera application or the remote image acquisition application. According to one or more embodiments of the invention, the combination of transformer and VA addresses these concerns.
[0021] Two steps are used to install the Pervasive Computing Services application software on a mobile device. The first step is to install a pervasive computing service virtual machine running in virtualization software 300, referred to herein as a PerComm virtual machine or PerComm VA. The second step is to guide certain virtual and physical devices to be sent through PerComm VA. This may require explicit action by the owner of the mobile device, as it may expose the physical resources of the handset to outsiders.
[0022] The data and controls coming out of the VM are then sent to PerComm VA. PerComm VA runs in user mode in its own address space, and virtualization software 300 can control the virtual for machine language address mapping and arrange it to avoid data copying (networking streams). When converting to packets, however, it may not be impossible to avoid copying). PerComm VA communicates this data and control to remote devices via Bluetooth connectivity, wifi, or some other wireless communication device. The user may be given control over when and which device will be processed by PerComm VA. Data and control information from the remote device is transmitted to the PerComm VA, which can then transfer this data and control information to the transformer stack 350 (or virtualization software 300) that directs it to the VM. The VM thinks it is interacting with the local device, but the interaction is PerComm It is mediated by VA.
[0023] There is time for the virtualization software 300 to be updated or patched. Similarly, there may be times when the handset VM is under the control of a remote entity, eg, a company that owns a virtual work phone that is attached to an employee's personal handset (this is explained in more detail below). ). According to one or more embodiments of the invention, the management of physical devices accessed by a "work phone" can be controlled by a remote enterprise server. According to one or more embodiments of this type, the management module, eg, the management client 340 in the virtualization software 300, has the appropriate authentication, authorization, security protection, and policy rules to allow this to happen. To support. In addition, according to one or more further embodiments of the invention, the owner or user of the handset performs similar management operations for another VM, a VM that is not controlled by input from a remote enterprise server. it can. In this case, the management module may be similar to a management module that responds to a remote enterprise server, but it receives that command in this form, eg, and, but not limited to, a remote link or keyboard command.
Usage Management: One or more embodiments of the invention control the use of one or more applications provided by a mobile device, such as, but not limited to, a mobile device. Provides a way to manage the use of mobile phones). So, according to one or more embodiments of this type, the enterprise is a mobile device managed by the employee's enterprise, for example, and by, but not limited to, by managing the telephone to manage costs. The use of may be restricted or controlled. In particular, and according to one or more embodiments of this type of the invention, a virtual mobile device 100 (eg, and, but not limited to, a virtual mobile phone) is a guest operating system (guest OS). And one or more VM400s with guest applications<sub>1</sub>~400<sub>n</sub>Includes virtualization software layer 300 (eg, hypervisor) that supports. According to one or more embodiments of this type, the management client 340 of the virtualization software 300 is, for example, and, but not limited to, a telephone network, or a wi-fi or wifi network {as is well known, Wi -Fi is a trademark of the Wi-Fi Alliance, which was founded in 1999 as WECA (Wireless Ethernet® Compatibility Alliance), and its products are IEEE802. 11 Standard (WLAN (Wireless) Consists of companies accredited by the Wi-Fi Alliance based on LAN) (also known as Wi-Fi)-certification guarantees interoperability between various wireless devices} and so on. Contact the corporate server (ie, management server 500) using one of many methods well known to those of skill in the art. According to one or more alternative embodiments, the VM of the virtual mobile device 100 is managed by the virtualization software 300 using any one of many methods of communicating by the virtualization software layer well known to those skilled in the art. Get in touch with 500.
[0025] According to one or more embodiments of this type, the management server 500 is a virtual mobile device 100 used to limit the use of any one of many guest applications running on the virtual mobile device 100. Send control information. For example, and without limitation, according to one or more embodiments of the invention, the management server 500 virtualizes control information, including limitations, to the management client 340 of the virtualization software 300, or as an alternative. Software 300 may send to the VM (according to one of many methods well known to those of skill in the art). The control information may be multidimensional in that it may be used to control a number of applications. For example, and without limitation, control information can be used to control one or more of the following uses, with proper identification of the particular application being controlled: (a) use of the network: Limit to a given or dynamically variable (eg, real-time input of control information from a corporate server) to a few minutes, (b) many sms messages (as we all know, Short Message). Service (Short Message Service) (SMS) is a communication protocol that allows the exchange of short text messages between mobile phone devices) with predetermined or dynamically variable (eg, control information from a corporate server). Limit the number (by real-time input of), (c) limit data transfer to a given or dynamically variable number (eg, by real-time input of control information from a corporate server), or (d) game Limit usage to one or more given games, or to given or dynamically variable (eg, by real-time input of control information from a corporate server) hourly usage (by virtualization software) .. As can be easily understood, an entity can dynamically change control information in response to changes in budget, for example, and without limitation, and control information can change by user group. (There, by user identification, where user groups are set, for example, but not limited to, when configuring virtual mobile devices, stored and / or accessed by virtual software 300 and / or VM. Can be identified).
[0026] According to one or more embodiments of the invention, an application (referred to herein as a guest application) is a guest running in virtualization software 300 of a virtual mobile device 100, eg, a hypervisor. Executed in the OS. In this type of virtual mobile device, cell network communication initiated from a guest application or guest OS, eg, and, but not limited to, phone calls, sms messages, 3G / Edge / GPRS messages {well-known Like, 3G was first marketed as a way to make video calls over mobile networks, but by browsing the internet, using voice over ip, and by email and instant messaging. GPRS, which is also a method of communicating with smartphones, is a system used to send data at speeds of up to 60 kilobits / second, and is a low power method of sending and receiving emails and browsing the Internet. And EDGE (Exchanged Data rates for GSM® Evolution (Exchanged Data Transfer Rate for GSM® Evolution) is a recent development based on the GPRS system, and due to the fact that it can operate at up to 473.6 kbps. Classified as "3G" standard. If your smartphone is EDGE capable, it can be used for large amounts of mobile data transmission, such as receiving large email attachments or browsing complex web pages at high speeds} etc. , Generates trapped guest OS device driver behavior and processes it by the device driver in virtualization software layer 300. In other words, in virtual mobile devices, the guest OS device driver does not communicate directly with the communication device, but rather with the device driver of the virtualization software layer 300.
[0027] In addition, and according to one or more embodiments of the invention, the guest OS can send data packets over wifi, cell, USB, or Bluetooth networks (as is well known, Bluetooth is fixed). And a wireless protocol for exchanging data over short distances from mobile devices). According to one or more embodiments of this type, in any of these cases, guest OS device driver behavior is trapped by virtualization software layer 300, and then the device driver for virtualization software layer 300. Is done by. According to one or more embodiments of this type, the device driver for virtualization software layer 300 can use different networks for communications other than those specified by the guest operating system. For example, and without limitation, the guest operating system can send packets over a 3G network, but in reality, virtualization software layer 300 device drivers can send it over a wifi network. In addition, at one point, the virtualization software layer 300 device driver uses the same communication mechanism indicated by the guest operating system.
[0028] In any case, according to one or more embodiments of the present invention, the virtualization software layer 300 can limit communication. In particular, according to one or more embodiments of this type, the virtualization software layer 300 network driver can count packets sent and received through the cellular network and send its usage information to the virtualization software layer 300. .. Then, when one or more limits set on the control information are reached, the virtualization software layer 300 can itself reduce communication over its network, where certain limits identify virtual mobile devices. May be used to limit the type of function of. In particular, reaching the limit is determined by calculating the difference between the usage information and the limit and determining that the difference exceeds or is equal to a predetermined amount, where, for example, but not limited to. , A predetermined amount can be included in the control information, or it may be a configuration parameter. For example, and without limitation, one limit can be related to sms messages, another can be related to phone calls, and yet another limit can be related to a particular game. .. According to one or more other embodiments, usage information can be sent to a VM that analyzes information for one or more limits. Also, according to one or more further embodiments, when one or more limits set on the control information are reached or exceeded, the transformers or transformer combinations in the transformer stack 350 are packets sent and received over the cellular network. Can be counted and, by itself, communication can be reduced through its network. In any of these cases, by exceeding a certain limit, a predetermined operation is executed, and the predetermined operation can be indicated in the control information. For example, exceeding a certain limit is absolute in that a mobile device may become inoperable, or exceeding a certain limit may make a particular function inoperable. In that there is "soft That is, less than absolute, or it is, for example, and without limitation, so that a mobile device can be used to send and receive phone calls to a particular area code only. , "Softer" in that certain features may be compromised. In addition, in connection with invoking the controller, the VM displays this type of information on the display associated with the mobile device and / or by sending a text message and / or by voice mail message. And / or by sending an e-mail message, you can provide the user with information explaining the measures being taken.
[0029] Thus, according to one or more embodiments of the invention, many cell phone recordings used by mobile devices are by virtualization software 300, by transformers, or by GSM® {well-known. Like GSM® (Global System for Mobile Communications (originally from Groupe Special Mobile)) is a popular standard for mobile phones and GSM®. ) Is different from its predecessor in that both signaling and speech channels are digital, and is therefore considered a second generation (2G) mobile phone system) or CDMA (as is well known, Code- Division Multiple Access is a digital cellular technology that uses spread spectrum technology} to track many records that drivers connect to, and mobile devices, such as, but not limited to, for example, for example. By resetting the permissions using the user ID and PIN to grant the permissions, by not setting up any further connections until reinitialized-alone or in response to a message from the VM-to the limit It can be controlled by a VM (eg, and, but not limited to, a particular purpose VM) that has a virtualization software layer that disconnects when it reaches or by a transformer.
[0030] In addition, the virtualization software 300 uses the management client 340 or the VM provided for this to indicate which communications / applications should be restricted and how. For example, it is possible to periodically communicate with the management server 500 for updating.
Location-based security: According to one or more embodiments of the invention, it is based on the physical location of the mobile device, and on the basis of one or more location and time-based security policies. You may or may not need a password or PIN to access one or more of its features.
[0032] A typical mobile device security policy is that the user "unlocks" a mobile device, because the mobile device automatically locks when it is inactive for a specified period of time, usually for a few minutes. Requires entering a password on his / her mobile device. For example, after a period of inactivity (eg, no keys are pressed), the screen and keyboard are locked, and the only input allowed is the user's password. Once the password is entered, the screen and keyboard are activated (usually when daemons and background processes continue to run to enable this type of functionality). Alternatively, when a phone call comes in, the user can answer the call with a screen or key, but the rest of the device remains locked. Many users have to enter their passwords dozens of times or more each day, so they find this security feature annoying.
[0033] According to one or more embodiments of the invention, for example, and without limitation, password-entered mobile device access security is the physical location or physical location and / or physical of the mobile device. Based on the time spent in the target position (position-time). According to one or more further embodiments of the invention, the particular security policy may be a centralized security policy, which, for example, and by communication from, but not limited to, corporate servers. Can be changed.
[0034] According to one or more embodiments of the invention, the mobile device access policy is, for example, only if the user is physically away from the office or home (ie, location-based scenario). A password may be required, but not limited to. According to one or more embodiments of this type, the mobile device is a virtual mobile device, where a large number of VMs are a large number of virtual mobile devices, such as, but not limited to, a telephone (ie, but not limited to). Allows one virtual phone to be a corporate mobile phone, and another virtual phone to provide a personal mobile phone), where each virtual phone has its own security policy. Can have. Thus, and according to one or more embodiments of this type, access to corporate mobile phones may have stronger security requirements than personal mobile phones.
[0035] According to one or more embodiments of the invention, the virtual mobile device determines its current geographic location. This type of location determination may be based on obtaining information from: (a) built-in GPS devices, (b) external GPS devices (eg, by USB cable or by Bluetooth connection) wirelessly. (Car GPS device that communicates with mobile devices), (c) Detection of mobile phone base stations using any one of many methods well known to those skilled in the art, (d) Well known location A bluetooth device (for example, a desktop PC can be equipped with a bluetooth device, its identifier is known to the mobile device, and when the mobile device is within range of the desktop PC's bluetooth signal, the mobile device does it. The location is also known, as you know that is close to the desktop), (e) a wifi base station using one of many methods well known to those in the art, (e) Short-range radio communication activated by entering the facility through a passage protected by this type of short-range radio communication using any one of many methods well known to those of skill in the art, or (f) etc. Use of the mechanism. This type of location determination can be obtained using virtualization software 300, or it communicates with a VM, eg, and, but not limited to, virtualization software layer 300. It can be noted that it is started by a specific VM used for (referred to here as a security VM). If the location and, optionally, the time at that location are known, the security VM can compare the information to the security policy and take appropriate action as indicated by the comparison.
[0036] According to one or more embodiments of the invention, there are many levels or degrees of "proof" that provide evidence that the mobile device is in a safe position. For example, a mobile device may need to be in any one of many locations for a given amount of time (ie, a location-time based scenario). For example, mobile devices may have to be in the office designated location for at least an hour before the need to enter a password to prevent locking is disabled. As another example, when the mobile device is in any one of many predetermined locations, the time before locking the mobile device can be extended. As yet another example, the decision as to whether or not to lock a mobile device after a predetermined period of inactivity may be time dependent. For example, if an employee arrives at work at 9:00 am and returns home at 7:00 pm on weekdays, and the employee is at home on weekends and holidays, the mobile device Password locking is disabled only during these periods in place. In yet another embodiment, if the mobile device's phone is "alone", i.e. it does not detect the presence of another mobile device nearby, password locking may be unusable. According to one or more embodiments of this type, mobile devices (eg, security VMs) are other mobile devices by their Bluetooth radio using any one of many methods well known to those of skill in the art. Determine if it is alone by scanning the. If a mobile device responds, even in the office, the mobile device may require a password. Fortunately, this is useful when you leave your mobile device on your office desk. If someone else enters the office and wants to use the mobile device, that person will have to enter the password.
[0037] According to one or more embodiments of the invention, in order to reduce location spoofing (eg, location information may be imitated if the OS, eg, one of the guest operating systems, is compromised). A server, such as the management server 500 shown in FIG. 1, can track the location of a mobile device as it moves (eg, by having the mobile device (eg, a security VM) report this information). The server software then analyzes the position change using any one of many methods well known to those of skill in the art. Analysis confirms that the mobile device is in a previously identified position, as described above, i.e. to ensure that it is where it thinks it is from the data that the mobile device obtains, such as using GPS data. confirm. Servers that maintain a detailed history of mobile devices over many weeks or months have their history of mobile device migrations and their history of location migrations that follow one of many methods well known to those skilled in the art. You can be sure that they are consistent.
[0038] According to one or more embodiments of the invention, the mobile device is in a predetermined registered position (eg, and is not limited) to indicate that the mobile device is in a trusted position. When entering a workplace, home, or other registered device, a mobile device (eg, a security VM) can store information (eg, and, but not limited to, a bit). As a result of being in a trusted position, mobile devices are not automatically locked. Then, when the mobile device leaves the predetermined registered position, it returns to its normal mode. According to one or more embodiments of this type, an entry to a given registered location causes a mobile device (eg, a security VM) to communicate with a server (eg, management server 500) to create a given location. It can be confirmed by having the server verify that it is in the specified position and that it is given approval to be considered trusted. For example, when entering their office, a mobile device (eg, a security VM) can detect a local wifi base station and use it to locate it. According to one or more embodiments of this type, the server (eg, management server 500) can also contact the wifi base station to determine if it has just registered the mobile device as well.
[0039] Although embodiments of the present invention have been described with respect to the security provided by entering a password, further embodiments can be manufactured under various security schemes. For example, various functions provided by mobile devices can be controlled based on position. For example, and without limitation, access to various files or volumes can be location-based, or the application can only be run if the mobile device is in a particular secure location.
[0040] According to one or more of the above embodiments, to further avoid spoofing, the encryption between the mobile device and the server so that the server can assure the user that its tracking of the mobile device is reliable. You can use the encrypted communication. If the mobile device (virtualization software or VM assigned to the work) detects a security breach (eg, by comparing it to a recorded history of the mobile device's location to ensure consistent behavior), The virtualization software can lock the screen and / or the keyboard of the mobile device alone or in response to a command from the VM or server. Alternatively, one or more transformers in the transformer stack 350 can be used to block access to the screen and / or keyboard.
[0041] According to one or more embodiments of the invention, when an analysis indicates that a lock is required, for example, and by, but not limited to, a timeout maturity or movement to an unsafe position. When the lock is performed in addition to locking the screen and / or keyboard, the VM that provides the given function (eg, and, but not limited to, making a phone call) can be interrupted. In this example, the virtualization software can allow the mobile device to accept communications, but they are queued by the virtualization software until the VM is awakened. Alternatively, functionality can be interrupted by sending control information to one or more transformers in the transformer stack 350, which / they interrupt a given function, or enable it later.
[0042] According to one or more embodiments of the invention, instead of a mobile device tracking its own location, the carrier itself, in some circumstances, locates the mobile device (eg, for a 911 call). If so, the carrier will tell the police where the phone is located). Then, the telecommunications carrier sends the location information to the mobile device or to the server that transfers the location information to the mobile device.
Limit sabotage software in mobile devices: Security can be breached if the mobile device is compromised by the sabotage software. For example, this type of sabotage software allows a person to eavesdrop on personal conversations, track movements, and access personal information such as URLs, emails, contact lists, PINs, and so on. Can be used for Normally, this type of mobile device is always on, but security breaches can be more serious in the case of mobile devices, as users cannot keep an eye on it. As a result, simply alerting the user to suspicious behavior may be useful, but not sufficient. In addition to this, preventing spying by your own mobile device is more difficult than detecting traditional sabotage software. This is because mobile devices are vulnerable to the types of attacks that use harmless effects on mobile devices. For example, there are many applications that track the location of users and update remote servers, many of which are social networking applications, and mobile device owners allow this type of operation. Another example is another application that can produce some action, such as "geotagging," based on the location of the mobile device. Yet another embodiment is yet another application that records what the user is saying and sends the recording to a remote server for speech recognition processing. It is also possible to combine these applications so that, based on time and place, they start recording microphone input and launch mobile devices to send that information to a third party server. It's hard to prevent because the applications themselves are all valid applications, even though the user never wants this to happen. Traditional virus detection products do not detect this type of security breach.
[0044] According to one or more embodiments of the invention, a virtual mobile device is a mobile device, eg, and, but not limited to, a handset that has one or more "virtual" phones. Runs as a guest application in a guest operating system (called a VM) that runs in the virtualization software layer (eg, hypervisor). As explained above, in virtual mobile devices, each guest OS does not directly access the physical device, but rather the guest OS access of the guest device is trapped in the virtualization software layer and access to the physical device is not. , Performed by the virtualization software layer to perform proper behavior on real devices.
[0045] According to one or more embodiments of the invention, the virtualization software layer 300 collects information related to the state of the true device driver and is not limited to, for example, this information. Sends to the virus protection software module of the virtualization software layer, or a specific VM provided for this purpose (referred to here as a security VM), on a periodic basis. According to one or more embodiments of this type, a virus protection software module has a set of rules that can trigger an operation based on the information it receives regarding one or more of the physical device drivers. For example, and without limitation, the rule states that voice microphones are available and that an alarm must be issued whenever a TCP connection is possible for a particular set of destination addresses. Let's go. According to one or more embodiments of this type, a security server (eg, management server 500) can send a "rule set", for example, and without limitation, to mobile devices on a periodic basis. .. Moreover, according to one or more additional embodiments of this type, issuing an alarm is, for example, and, but not limited to, by providing a voice message and / or a text message, and / or a screen. Includes alerting the user by providing a message above and / or by blinking the screen display. In addition, according to one or more additional embodiments, issuing an alarm may require locking the mobile device to one or more predetermined applications relating to or related to a particular set of rules. is there. This type of lock can occur by sending control information to one or more transformers in the transformer stack 350, or this type of lock disables communication to one or more of the mobile device's VMs. It may occur by doing.
The running VM is checkedpoint and its entire state can be encapsulated in a single file. This file can be used later or on a different computer or handset to continue running the VM. When the radio latency is too long or there are insufficient resources in the handset or other embedded device, it is useful to move the handset's VM to another handset so that the computation is closer to the peripheral device. It is a characteristic. According to one or more embodiments of the invention, the functionality of a mobile device, such as, but not limited to, the functionality of a telephone, is from one mobile device to another, or one mobile device. From to netbook computers, laptop computers, desktop computers, or any other computerized device with sufficient computing power and connectivity. According to one or more embodiments of this type, the function is first performed using a VM, and then the VM is used by VMWare (VMware) in Palo Alto, California, a method called Vmotion. Migrate using one or more methods well known to those of skill in the art, such as. Advantageously, in one or more embodiments of the invention, the user, for example, and, but is not limited to, the user makes a suitable phone call based on the user's location or simply for fashion. His (female) phone can be "moved" from one physical device to another to allow it to be used. According to one or more embodiments of this type, the transition can be carried out using a wireless operator or using wifi or physical wire connections. According to one or more embodiments, the migration method involves selecting a target mobile device, ordering VMs representing virtual phones, and, for example, but not limited to, streaming in sequence. Stage of transferring side-by-side VMs from source mobile device to target device Including floors. According to one or more further embodiments, the method of migration is to computer or other means, such as, and, but not limited to, the management server 500 or another ordered VM representing a virtual phone. It includes a step of transferring to a service provider using a mobile device and a step of transferring an ordered VM to a target device. According to one or more embodiments of this type, the method (a) source and target SIM chips according to one of many methods known to those of skill in the art to receive calls only on the target mobile device. The stage of reprogramming, or (b) virtualizing and transferring the SIM chip with the VM (SIM, its reader and control circuit is a hardware device, and thus its function is other hardware Note that the hardware device can be emulated in a manner similar to how it is virtualized), or (c) notify the service provider of the change and call the service provider to the target mobile device only. It further includes a step of transferring.
[0047] According to one or more embodiments of the invention, there are several different types of migrations: (a) VM self-service installation in a handset, (b) cold exercise (this involves shutting down the VM, moving it, and then starting it on another device), (c) VM A warm exercise with the steps of interrupting or checkingpoint, moving the state to another handset, and then resuming its execution in another handset, (d) hot exercise (or live transition) (where , On the other hand, the VM is running in one handset and is moving it towards another handset as if it never stopped working), (e) any of the above Clone with (but ensure that the VM has only one example of a VM that works with the first handset or always works with any handset).
[0048] VM self-service installation: There are many ways to put a VM on a mobile device, such as a phone-download via (i) USB cable, (ii) secure digital card, or (iii) radio waves. According to one or more embodiments of the invention, the user can check out the VM's self-service when the virtualization software is run on a mobile device such as a handset. To do this, according to one or more embodiments of this type, the user is (a) provided, for example, and limited by a server referred to herein as a "self-service" server. Not, but go to a website identified as http://www.acme.com/virtualphone.html;, (b) log on, (c) passcode, for example, and, but not limited to, Enter the phone number associated with the mobile device (there may be several passcodes, eg, the phone number associated with the mobile device, where, for example, and, but not limited to, one passcode. May be associated with a particular VM, for example), and (d) select the desired VM for that passcode, eg phone number. A self-service server, eg, management server 500, sends a message, eg, an SMS message, to a mobile device, eg, by phone using a communication path associated with a passcode, at a specified phone number, and the message is predetermined. Includes a communication link with the VM, for example, the link is a URL to a server that has a unique code at the end of the URL, eg http://www.acme. It may be com / downloadvirtualphone / abcdl234. The code abcdl234 identifies a particular user and the desired VM. At the same time, the virtualization software or VM provided for this (called the installation VM) launches the device driver, making it easier to retrieve the VM. According to one or more embodiments of this type, the action of contacting a server causes the virtualization software or installation VM to go to that server to begin downloading the VM. According to one or more embodiments of this type, the virtualization software can snoop browser traffic or smoop SMS traffic, but in any case, this snooping is to the virtualization software, where it is. Is to inform you of the steps it must take as well as the IP address from which the data must be retrieved.
[0049] According to one or more additional embodiments of this type, authentication, certification, and encryption protect against intervener attacks. To avoid using a third-party certification authority such as VeriSign, the virtualization software has a public key, and the self-service server encrypts it using the virtualization software creator's private key. You can use a public key cryptographically dependent protocol that has its own public key. Another way to state this is as follows. One or more embodiments of this type involve the involvement of distributors or creators of three entities or software systems-self-service servers (S), virtualization software (V), and virtualization software (C). The virtualization software installed on the handset contains C's public key, which is called public C. C needs S's public key to ensure that the virtualization software and server communicate. C also needs to know that S is guaranteed and not a fake site. The self-service server S has its public key, public S, encrypted using the creator's private key. The only way to decipher this is by the author's public key, which is already in the virtualization software. So, if the virtualization software can use the public key from the author to decrypt the message containing the server's public key, the virtualization software knows that the server is authenticated. Alternatively, the installation VM can be used in place of virtualization software.
[0050] Cold motion (the term "cold" refers to the fact that VMs are shut down before moving): According to one or more embodiments of the invention, VMs are required to operate with a small number of files. Including everything. In this way, by moving these files towards the new handset device, the VM can run on that device. The VM has a set of peripherals that may or may not be identical to the peripherals of the source device. In addition, the destination device can have different peripheral devices, different architecture generations, or even different architectures. According to one or more embodiments of this type, peripheral devices are virtualized and the device transformers in the virtualization software map one device to another.
[0051] Warm movement: According to one or more embodiments of the invention, the VM is moved from one handset to another and its execution is resumed in the second handset.
[0052] Hot Exercise: According to one or more embodiments of the invention, this is similar to a live transition between host computers, where the VM is run during execution. According to one or more embodiments of the invention, live migration occurs by checkingpoint a VM and launching it on another mobile device, where the VM runs on the first mobile device or whatever. Make sure you have only one example of a VM that also works on mobile devices.
[0053] According to one or more embodiments of the invention, if communication is in progress, and if communication is via wifi, the virtualization software of the first device will be the new device until the end of the communication stream. Forward the packet to the virtualization software. New communication automatically bypasses the first device. In this case, the virtualization software acts like a NAT (Network Address Transformer) so that the VM has the same IP and MAC address, but the new IP and MAC address is presented to the remote device. If the communication is via a cellular network, telephone or IP, the solution is different. There are two feasible solutions. One solution is for each virtual phone to have its own unique phone number. The phone with this number is on a server in a stable location. According to this type of solution, the call comes from this stable position, rather than coming directly to or from the phone. In addition, incoming calls are transferred to a handset that includes a virtual phone. Furthermore, the actual caller ID of the initiated phone is recorded by the server so that the handset sees the first caller ID and not the caller ID in a stable location. If the handset needs to know if the call was on a particular VM, the server can later convey that information to the handset. For example, the "received phone" log of each virtual phone can be recovered after the call ends by a message from a stable server. The second solution is to have multiple SIMs on the phone or to virtualize the SIMs. Certain phones allow the baseband processor to be virtualized. In such cases, the virtualized mobile device performs two or more copies of the baseband code to provide virtual SIM data to each and multiplex the wireless antenna. In any case, during hot exercise, the first handset must have a voice connection to the destination handset. This is done in one of many ways Can: The remote device can be made to act like a bluetooth headset, just as the speaker's voice is wirelessly communicated to the remote device, and as if it came from a microphone. , It receives audio from a remote device. Wifi can be made to send audio in either direction, much like a Bluetooth connection.
Cloning: Although not mentioned in any of the previous modes of movement, a virtual phone runs with only one handset at a time, i.e., even after it has been moved from the first handset. It was assumed that it would no longer run on that handset until it was returned to it. However, according to one or more embodiments of the invention, there are two virtual phones (ie, one keeps running on the first phone and one starts working on the destination phone). Virtual phones are "cloned". The following behavior is appropriate when the virtual phone is running on two or more different handsets. With an incoming phone call, each of the virtual phones rings to have multiple parent and child phones in a traditional landline scenario. In fact, the only difference between a cloned phone and multiple parent-child phones is that it happens when there is no call for the phone involved. For extensions, taking two extensions usually means that they can talk to each other without calling the phone. This is not possible with cloned phones.
Locked Mobile Devices: There is no satisfactory common platform to provide a secure environment for sensitive applications in the mobile device space. Java®, as promised, does not provide programming in mobile space to run anywhere once a common platform is written, in a particularly secure way. There are also many organizations such as banks, insurance companies and broker-dealers who want to provide secure applications so that users can access their accounts and information in a secure way. According to one or more embodiments of the invention, an organization can package a VM as a "mobile device" and distribute it to users for operation on virtual mobile devices. According to one or more embodiments of this type, the virtualization software layer isolates the appliance and prevents unauthorized access to it. The instrument is an image or data file containing the code and data. It can be encrypted in device storage so that no other VM or application can access the data or modify the code. When the instrument runs, the image pages are embedded in SRAM or memory and decrypted by virtualization software. Other technologies borrowed from ACE or offline VDI can be implemented to protect and manage mobile devices.
[0056] A person skilled in the art will appreciate the particular practices described herein to the extent that various modifications and modifications do not deviate from the broader spirit and scope of the invention as described in the appended claims. Understand that it can be made into a form. Therefore, the above description and drawings should be considered as illustrations rather than in a limited sense.
[0057] Various embodiments described herein can use a variety of computer-implemented operations, including data stored in a computer system. For example, these operations may usually, but not necessarily, require physical treatment of physical quantities, which can take the form of electrical or magnetic signals, where they, Or their representations can be stored, transferred, combined, compared, or treated. Moreover, this type of treatment is often referred to by terms such as generation, identification, determination, or comparison. Any operation described herein that forms part of one or more embodiments of the invention may be a useful mechanical operation. In addition, one or more embodiments of the present invention also relate to devices or devices that perform these operations. The device may be specially configured for a particular required purpose, or it may be a general purpose computer that is selectively operated or configured by a computer program stored in the computer. In particular, various general purpose machines can be used with computer programs written according to the teachings of the present specification, or it is more convenient to configure more specialized equipment to perform the required operations. There may be.
[0058] Various embodiments described herein include other computer system configurations, including portable devices, microprocessor systems, microprocessor-based or programmable appliances, minicomputers, mainframe computers, and the like. Can be practiced by.
[0059] One or more embodiments of the present invention may be implemented as one or more computer programs or as one or more computer program modules incorporated into one or more computer-readable media. The term "computer-readable medium" refers to any data storage device that can store data that can be entered into a computer system later, and computer-readable media allows computer programs to be read by a computer. It may be based on any existing or later developed technology to be implemented in a method. Examples of computer-readable media are hard disks, network-attached storage (NAS), read-only memory, random access memory (eg, flash memory devices), CD (compact disc) CD-ROM, CD-R, or CD-RW. , DVDs (Digital General Purpose Discs), magnetic tapes, and other optical and non-optical data storage devices. Computer-readable media can also be distributed to network-bound computer systems so that computer-readable code is distributed, stored, and executed.
[0060] Although one or more embodiments of the present invention have been described in a little more detail for clarity, it is clear that certain modifications and modifications can be made within the scope of the claims. Therefore, the embodiments described should be considered exemplary and not limiting, and the claims should not be limited to the details given herein. And can be modified within a reasonable amount. Unless explicitly stated in the claims, the elements and / or stages do not imply any particular order of operation.
[0061] In addition, those skilled in the art will assume that the virtualization methods described usually provide an interface consistent with the particular hardware system of the virtual computer. You will recognize that it can be used in conjunction with virtualization that does not directly support any particular hardware system. All virtualization systems according to various embodiments, implemented as hosted embodiments, unhosted embodiments, or embodiments that tend to blur the difference between the two, are envisioned. Furthermore, various virtualization operations can be performed entirely or partially in hardware. For example, hardware implementations can use look-up tables for modified aspects of storage access requests to guarantee non-disk data.
[0062] Many modifications, modifications, additions, and improvements are possible regardless of the degree of virtualization. Virtualization software can therefore include components of a host, console, or guest operating system that perform virtualization functions. Multiple examples can be provided for the components, behaviors, or structures described herein as a single example. Finally, the boundaries between the various components, behaviors, and data accumulations are somewhat arbitrary, and specific behaviors are illustrated in the context of specific exemplary configurations. Other functional allocations are envisioned and can be included within the scope of the invention. Generally, in a typical configuration, the structures and functions presented as separate components can be implemented as a composite structure or component. Similarly, structures and functions presented as a single component can be implemented as separate components. These and also other modifications, modifications, additions, and improvements may fall within the appended claims.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US9866890B2 | Cited by | United States of America | Applicant |
| JP2016506546A | Cited by | Japan | Search report |
| JP2002185579A | Cites | Japan | Examiner |
| JP2002185579A | Cites | Japan | Search report |
| JP2003078952A | Cites | Japan | Examiner |
| JP2003078952A | Cites | Japan | Search report |
| JP2005044009A | Cites | Japan | Examiner |
| JP2005044009A | Cites | Japan | Search report |
| WO2007043659A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO2007043659A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2008097203A | Cites | Japan | Search report |
| JP2008097203A | Cites | Japan | Examiner |
| JP2009070073A | Cites | Japan | Examiner |
| JP2009070073A | Cites | Japan | Search report |
| JP2009130856A | Cites | Japan | Search report |
| JP2009130856A | Cites | Japan | Examiner |
8 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 12492611 | United States of America | – | |
| 49261109 | United States of America | A | |
| 49261109 | United States of America | A | |
| 2010040143 | United States of America | W | |
| 2010040143 | United States of America | W | |
| 2009492611 | – | – | – |
| 2010040143 | – | – | – |
| US20090492611 | – | – | – |
| WO2010US40143 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO2010151860A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2010330961A1 | United States of America | A1 | |
| AU2010265908A1 | Australia | A1 | |
| EP2446391A1 | European Patent Office (EPO) | A1 | |
| US8233882B2 | United States of America | B2 | |
| JP2012531678AThis record | Japan | A | |
| AU2010265908B2 | Australia | B2 | |
| JP5611338B2 | Japan | B2 |
25 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Written request for registration of change of nameJAPANESE INTERMEDIATE CODE: R313533S533 | S533 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 |
Numbers
- Publication
- 2012531678
- Publication, DOCDB
- 2012531678
- Publication, EPODOC
- JP2012531678
- Application
- 2012517818
- Application, DOCDB
- 2012517818
- Application, EPODOC
- JP20120517818
Titles2
- Japanese
- 仮想モバイル機器のセキュリティの提供
- English
- Providing security for virtual mobile devices
Classification
- CPC, 2
- G06F21/31
- G06F2221/2111
- IPC, 3
- G06F21 22
- G06F9 46
- G06F21 20
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo