Safe application distribution and execution in a wireless environment
Abstract
This record has no abstract on file.
Term
Term ended
Expired 23 May 2022, 4.3 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
6 claims: 3 independent, 3 dependent
- 1ワイヤレスネットワークを介して通信を行うワイヤレス装置上での使用のための、サーバによるアプリケーションの処理及び配布のための方法であって、 前記サーバが、前記アプリケーションと前記アプリケーションに関連する第1の識別情報とを配布元から受信することであって、前記第1の識別情報は前記アプリケーションの配布元の身元を確認するのに使用されることと、 前記サーバが前記アプリケーションを解析することによって、前記アプリケーションが一組の所定の基準における各基準を満足することを認証することであって、各基準は、前記ワイヤレス装置におけるアプリケーション実行環境に合致して決められることと、 前記認証の後に、前記サーバが、前記アプリケーションに対して一組の許可を付与することであって、前記一組の許可は複数の許可を含み、該複数の許可のそれぞれは前記一組の所定の基準における各基準に関連しており、さらに、前記一組の許可は、前記ワイヤレス装置上での前記アプリケーションの実行を許可すべきか否かについて判別するのに用いられる一組の認証フラグを含み、各認証フラグは、前記アプリケーションが前記認証にパスしたか否かに応じてセットされることと、 前記サーバが、前記アプリケーションと、前記一組の許可と、前記サーバの身元を確認するのに使用される第2の識別情報とを前記ワイヤレス装置に送信することと、を具備 した前記 方法。
- 2前記ワイヤレス装置への送信にあたって、少なくとも前記アプリケーションに対して、当該アプリケーションが送信される間に変更されたか否かを検出するためのデジタル署名技術が適用される請求項1記載の方法。
- 3ワイヤレスネットワークを介して通信を行うワイヤレス装置上で使用されるアプリケーションの処理及び配布のためのシステムであって、 キャリアネットワークと、 前記ワイヤレスネットワークを支持するとともに、前記キャリアネットワークに接続され、インターネット及び/又は電話システムで構成されるインフラストラクチャと、 前記キャリアネットワークに結合され、配布元から前記アプリケーションを受信するサーバと、を具備し、 前記サーバは、 前記アプリケーションと前記アプリケーションに関連する第1の識別情報とを受信することであって、前記第1の識別情報は前記アプリケーションの配布元の身元を確認するために使用されることと、 前記サーバが前記アプリケーションを解析することによって、前記アプリケーションが一組の所定の基準における各基準を満足することを認証することであって、各基準は、前記ワイヤレス装置におけるアプリケーション実行環境に合致して決められることと、 前記認証の後に、前記サーバが、前記アプリケーションに対して一組の許可を付与することであって、前記一組の許可は複数の許可を含み、該複数の許可のそれぞれは前記一組の所定の基準における各基準に関連しており、さらに、前記一組の許可は、前記ワイヤレス装置上での前記アプリケーションの実行を許可すべきか否かについて判別するのに用いられる一組の認証フラグを含み、各認証フラグは、前記アプリケーションが前記認証にパスしたか否かに応じてセットされることと、 前記アプリケーションと、前記一組の許可と、前記サーバの身元を確認するのに使用される第2の識別情報とを前記キャリアネットワークと前記インフラストラクチャとを介して前記ワイヤレス装置に送信することと、を行うように構成され た前記 システム。
- 4前記アプリケーションと、前記一組の許可と、前記第2の識別情報とを前記ワイヤレス装置に送信するにあたって、前記アプリケーションが前記送信中に変更されたか否かを検出するためのデジタル署名技術が使用される請求項3記載のシステム。
- 5前記サーバは、 サーバ間ネットワークと、 配布元から前記アプリケーションを受信するように構成された第1のサーバと、 前記アプリケーションを認証するように構成された第2のサーバと、 前記アプリケーションに対して一組の許可を付与するとともに、前記アプリケーションを送信するように構成された第3のサーバであって、前記一組の許可は、前記ワイヤレス装置上での前記アプリケーションの実行を許可すべきか否かについて判別するのに使用される第3のサーバと、を具備し、 前記第1、第2及び第3のサーバはそれぞれ前記サーバ間ネットワークに結合されるとともに、前記第3のサーバは前記キャリアネットワークに結合されている請求項3記載のシステム。
- 6ワイヤレスネットワークを介して通信を行うワイヤレス装置上での使用のための、アプリケーションの処理及び配布のためのシステムであって、 キャリアネットワーク手段と、 前記ワイヤレスネットワークを支持するとともに、前記キャリアネットワークに接続され、インターネット及び/又は電話システムで構成されるインフラストラクチャ手段と、 前記キャリアネットワークに結合されたサーバ手段であって、 配布元から前記アプリケーションと前記アプリケーションに関連する第1の識別情報とを受信するための受信手段であって、前記第1の識別情報は前記アプリケーションの配布元の身元を確認するために使用される受信手段と、 前記アプリケーションを解析することによって、一組の所定の基準における各基準を満足することを認証する認証手段であって、各基準は、前記ワイヤレス装置におけるアプリケーション実行環境に合致して決められる認証手段と、 前記アプリケーションが前記認証手段によって認証された後に当該アプリケーションに対して一組の許可を付与する付与手段であって、前記一組の許可は複数の許可を含み、該複数の許可のそれぞれは前記一組の所定の基準における各基準に関連しており、さらに、前記一組の許可は、前記ワイヤレス装置上での前記アプリケーションの実行を許可すべきか否かについて判別するのに用いられる一組の認証フラグを含み、各認証フラグは、前記アプリケーションが前記認証にパスしたか否かに応じてセットされる付与手段と、 前記アプリケーションと、前記一組の許可と、前記サーバの身元を確認するのに使用される第2の識別情報とを前記ワイヤレス装置に送信するための送信手段と、を具備 した前記 システム。
Independent claims6
68 paragraphs, as filed
The present invention relates to the processing of applications used in wireless devices, and more particularly to the increased security, security and integrity of applications performed in wireless devices.
Wireless communications have recently experienced explosive growth. As consumers and the business industry increasingly rely on wireless devices such as mobile phones and personal digital assistants (PDAs), wireless service providers or carriers strive to provide additional functionality with respect to these wireless devices. There is. Such additional features not only increase the demand for wireless devices, but also increase their use among current users. However, in particular, the increase in functionality by increasing the number of applications accessible by wireless devices causes high cost and complexity, which discourages carriers from providing such functionality.
Moreover, there is little guarantee that an application once installed in a wireless device will run successfully. Currently, the reliability of the ability of an application to run on a wireless device depends on the developer, wireless device manufacturer and / or carrier. As more applications are developed and the number of applications installed in the wireless device increases, the environment of the wireless device becomes more dynamic. For example, a wireless device may choose to search for or execute a number of different applications from a collection of applications available at the appropriate time. That is, ensuring that any application is distributed to a wireless device and executed safely becomes difficult to control.
This is especially true for unauthorized execution of applications not only to adversely affect wireless devices, but also to carrier networks and other network elements, including other wireless devices. For example, one application (but not limited to) can control the power control of a wireless device, causing interference with other wireless devices and the total capacity of the cell servicing the wireless device. Will be reduced.
<p> At present, neither manufacturers nor carriers of wireless devices are configured to support dynamic application distribution and application testing and secure distribution in execution environments. That is, the application can be distributed and executed on the wireless device and harm the wireless device, carrier network, or other network elements.</p><p> In addition, there are safety issues that arise when more applications are developed and the environment in which the applications are sent to wireless devices becomes more dynamic. As the number of applications and the number of developers building these applications grows, so does the desire to know the source or developer of any application. The carrier or handset manufacturer wants to know with some degree of confidence that the source of the application can be determined if the application causes harm.</p><p> That is, what is needed in the industry is a system and method for providing a safer environment for the distribution and execution of applications on wireless devices.</p><p> Systems and methods conforming to the present invention provide traceability to developers for test applications with predetermined standards to prevent denial, inspect for unintended changes to the application, and from wireless devices. Overcome the shortcomings of existing systems by allowing application removal and / or creating a secure environment for application distribution and execution using rules and permissions that define the environment in which the application is run.</p><p> Ensuring that an application meets certain standards provides the advantage of proactively detecting errors that occur during execution. This helps prevent adverse effects on application execution.</p><p> Traceability provides the benefit of non-repudiation. If you have any problems with your application, it is useful to track the source of your application to resolve the problem. In addition, providing traceability has the effect of preventing developers from creating applications that cause harmful consequences, whether intentionally or not.</p><p> In addition, the ability to determine if an application has been modified before it is received by a wireless device increases security by ensuring that the application received is the same as it was transmitted. Provide benefits. The ability to determine if an application has changed when it is distributed more freely in a wireless environment is the trust that has not changed, regardless of whether the application received by the wireless device is intentional or not. Increase the degree.</p><p> Providing a set of rules and permissions that specify when an application runs, for example, by preventing unauthorized execution of the application on a platform, such as an unauthorized system or environment. , Increase the security of application distribution and execution systems.</p><p> The ability to remove applications from wireless devices increases the security of application distribution systems. Having a mechanism to remove an application in case of an unpredictable negative consequence when the application is installed on the handset via the manufacturer or application download is by removing unwanted code that is harmful and harmful. Increase the security of application distribution and execution systems.</p><p> Systems and methods conforming to the present invention use one or more techniques disclosed herein. However, by using all the techniques disclosed and referenced herein, systems and methods conforming to the present invention provide high quality and secure distribution and execution of applications.</p>
<p> According to one aspect of the invention, a method for processing and distributing an application by a server for use on a wireless device that communicates over a wireless network, wherein the server is the application and said. With the first identification information related to the application<u style="single">From the distributor</u>Receiving, the first identification information of the application<u style="single">distribution</u>Used to verify the original identity and the server<u style="single">By analyzing the application</u>, The application is to certify that it meets each criterion in a set of predetermined criteria, each criterion.<u style="single">It should be decided according to the application execution environment in the wireless device.</u>After the authentication, the server grants a set of permissions to the application, the set of permissions.<u style="single">Including a plurality of permits, each of the plurality of permits is associated with each criterion in the set of predetermined criteria, and further.</u>The set of permissions is used to determine whether the application should be allowed to run on the wireless device.<u style="single">Each authentication flag is set depending on whether or not the application has passed the authentication, including a set of authentication flags used.</u>The server comprises transmitting the application, the set of authorizations, and a second identification information used to verify the identity of the server to the wireless device. Between the wireless device and the wireless network<u style="single">Exchange messages to process the application in</u>It is independent of the act of performing wireless communication.</p><p> Further, according to one aspect of the present invention, it is a system for processing and distributing an application used on a wireless device that communicates via a wireless network, and supports a carrier network and the wireless network. , Connected to the carrier network<u style="single">Consists of internet and / or telephone system</u>Combined with the infrastructure and the carrier network<u style="single">Receive the application from the distributor</u>The server comprises, and the server receives the application and the first identification information related to the application, and the first identification information is the application.<u style="single">distribution</u>Used to verify the original identity and the server<u style="single">By analyzing the application</u>, The application is to certify that it meets each criterion in a set of predetermined criteria, each criterion.<u style="single">It should be decided according to the application execution environment in the wireless device.</u>After the authentication, the server grants a set of permissions to the application, the set of permissions.<u style="single">Including a plurality of permits, each of the plurality of permits is associated with each criterion in the set of predetermined criteria, and further.</u>The set of permissions is used to determine whether the application should be allowed to run on the wireless device.<u style="single">Each authentication flag is set depending on whether or not the application has passed the authentication, including a set of authentication flags used.</u>To transmit the application, the set of authorizations, and a second identity used to identify the server to the wireless device via the carrier network and the infrastructure. The application is configured to perform between the wireless device and the wireless network.<u style="single">Exchange messages to process the application in</u>It is independent of the act of performing wireless communication.</p><p> Further, according to one aspect of the present invention, it is a system for processing and distributing an application for use on a wireless device that communicates via a wireless network. The carrier network means and the wireless network are supported and connected to the carrier network.<u style="single">Consists of internet and / or telephone system</u>Infrastructure means and server means coupled to the carrier network.<u style="single">From the distributor</u>It is a receiving means for receiving the application and the first identification information related to the application, and the first identification information is the first identification information of the application.<u style="single">distribution</u>Receiving means used to verify the original identity and the application<u style="single">By analyzing</u>, An authentication means that certifies that each standard in a set of predetermined standards is satisfied, and each standard is<u style="single">Determined according to the application execution environment in the wireless device</u>An authentication means and a granting means that grants a set of permissions to the application after the application has been authenticated by the authentication means.<u style="single">Including a plurality of permits, each of the plurality of permits is associated with each criterion in the set of predetermined criteria, and further.</u>The set of permissions is used to determine whether the application should be allowed to run on the wireless device.<u style="single">Each authentication flag includes a set of authentication flags used and an granting means that is set depending on whether the application has passed the authentication.</u>The application comprises a transmission means for transmitting the application, the set of permissions, and a second identification information used to verify the identity of the server to the wireless device. , Between the wireless device and the wireless network<u style="single">Exchange messages to process the application in</u>It is independent of the act of performing wireless communication.</p>
<p> According to the present invention, high quality and secure distribution and execution of applications can be provided.</p>
An exemplary and preferred embodiment of the invention as shown in the accompanying drawings will be described in detail. Here, the same reference numerals indicate the same or corresponding parts in the drawings. The nature, purpose and advantages of the present invention will become apparent to those skilled in the art upon understanding the following detailed description with reference to the accompanying drawings.
The present invention provides a secure and secure application distribution and execution by providing a system and method for testing an application to ensure that it meets certain criteria related to the environment in which it is performed. provide. In addition, by using change detection techniques such as rules and authorization lists, application removal, digital signatures, etc., the present invention also determines if an application has been modified and permits it to perform in a given wireless device environment. By determining when and removing the application if desired, it provides a mechanism for the safe distribution and execution of tested or untested applications.
Those skilled in the art will recognize that the above describes the application file types that are distributed and executed for simplicity. Application includes files with executable content such as object code, scripts, JAVA® files, bookmark files (or PQA files), WML scripts, bytecodes, and pearl scripts. In addition, the "application" used herein includes normally non-executable files such as documents to be opened or other data files to be accessed.
FIG. 1 is a flowchart showing a high level process of application distribution and execution in a manner consistent with an exemplary embodiment of the invention.
Embodiments of the present invention allow a developer identification to be associated with the application, test the application against the environment in which the application is intended to run, and determine which device or system runs the application. Assign permissions that can be used to indicate and provide application removal when an application performs illegal or unwanted actions.
Systems and methods should use all these techniques to increase the secure distribution and execution of applications. However, we recognize that using one or more of these technologies will increase the secure distribution and execution of the application.
High-level processing begins by associating the developer identification with the application (step S100). This process is performed by combining the developer identity with the application when it is distributed. On the other hand, the associated developer identification is stored with the corresponding application on the server in the system. It is also desirable that the developer identification information be associated with the application information so that it is stored and cannot be easily modified.
The application is then tested for malicious behavior (step S105). An application is in an environment where malicious behavior not only affects the device on which the application is running, but also affects other devices that are directly connected to the device or connected to the device on the network. Used in. It is desirable to test the application so that it does not generate inappropriate system calls or have a negative impact on the device or other connected devices during operation. In one embodiment, the test is performed by a certification process that is tested to determine if the application meets certain criteria. In order to test the application, it is desirable to perform an authentication process independent of the developer. The independence of this certification process facilitates more accurate and reliable testing.
Prior to running the application, the application is checked to see if it should be "permitted" to run on the device (step S110). This inspection is performed by using the permits and regulations described below or other permitting mechanisms known to those of skill in the art. In addition, it should be inspected each time the application is run. This relentless inspection process increases the safety of running the application. For example, it can protect against applications with Trojan-type destructive programs that are inserted into the application on the executable through other applications.
Applications that perform rogue or unwanted actions are then removed from the device (step S115). This can be prevented from causing further damage to the application and frees up memory in the device for other uses. On the other hand, the application does not need to be removed from the application. Removing the application means that the application is inactive, leaving the application on the device.
FIG. 2 shows a system architecture in which exemplary embodiments of the invention are implemented. Developer 200 builds an application for use on wireless device 230. As mentioned above, the above description includes application file types, but those skilled in the art will recognize that other file types can also be used. Furthermore, the present invention can be applied to other wireless or non-wireless devices, and can be applied to wireless networks, non-wireless networks or combinations thereof.
Generally, the developer 200 has a set of development specifications for developing an application for running on the wireless device 230. In one embodiment, the wireless device includes a software platform such as BREW® software developed by QUALCOMM, Inc. (San Diego, Calif.) To assist the application in interface with the wireless device. Developers create applications that meet the software platform or BREW software, specification standards and conventions.
In one embodiment, the developer 200 is connected to the central server 205 to electronically send the application to the central server 205. In one embodiment, the central server is the Application Control Center Leaders (ACCHQ) server used to distribute the application to wireless devices. Developer 200 digitally signs the application (discussed further below) to determine if the application has changed. It turns out that no physical connection to the central server is required. For example, the developer 200 sends the application to the central server 205 stored on the CD-ROM by first-class mail or the like.
In addition, the developer sends various source identification information to the central server 205. This source identity includes any information associated with the application that identifies the developer, such as company name, company tax identification or other identity.
Central server 205 is used for application parsing and authentication using itself or authentication server 210. In one embodiment, the Application Control Center (ACC) is used as the authentication server. The authentication server 210 is used to analyze the application to determine if it meets certain authentication criteria. This criterion includes whether the application meets the development specifications for execution on a wireless device or platform. However, certification criteria are any criteria that an application must meet prior to running on a wireless device or platform. Such criteria are such that (a) the application works as required by the developer so that the application does not impair the operation of the wireless device (eg, it does not stop the phone from functioning), (b) the application Negative impact on wireless device resources, such as not accessing prohibited data or memory (eg, not accessing other applications, operating systems or platform software), (c) harmfully monopolizing the input and output of wireless devices. Includes verifying that you do not give.
Central server 205 assigns a set of permissions to the list associated with the application. This authorization list is determined by a variety of factors, including an analysis of whether the application passed the authentication process, on which network 220 the application was allowed to run, and whether the wireless device favored the application. Will be done. There are many factors that are used to determine the authorization list and are left to those skilled in the art when implementing the present invention.
The central server 205 receives the developer identification information and correlates it with the application created by the developer 200. If there is something wrong with the application, the central server can identify the source of the application. In one embodiment, the developer information is passed to the wireless device 230, whereby the correlation is performed by the wireless device or other system connected to the wireless device.
In one embodiment, the central server is further connected to the application download server (ADS) 215. The application download server 215 is used to interface with wireless devices over the wireless network 220 to download applications. The central server sends the authorization list and the developer identification associated with the application to ADS and remembers it until it is sent to the wireless device. Applications, authorization lists, and developer identification should be digitally signed by a central server to increase security from changes.
Those skilled in the art will recognize that ADS is used to connect to a large number of networks 220 to distribute applications, files and other information to various wireless devices 230. In addition, wireless and non-wireless networks are used to send application authorization lists and developer identification to wireless devices.
In response to a request for the application, the ADS215 sends the application, authorization list, developer identification and digital signature over the network 220 to the wireless device 230. In one embodiment, the wireless device 230 includes a key for inspecting a digital signature to determine if an application, authorization list and / or developer information has changed.
Desirably, if the digital signature is used in the present invention, the central server uses the secure key to generate the digital signature and installs the key on the wireless device to evaluate the digital signature. By using the security key, the wireless device will have a high level of confidence that the digital signature was generated by a central server rather than by a fraudster.
If the application causes an error on the wireless device, or for some other desirable reason, the wireless device initiates the removal of the application. In addition, the application is removed from the wireless device based on a request from the ADS or central server. This request from the server is initiated for any desired reason. For example, a server wirelessly installs an application for business reasons, indicating that the application was not legitimately running on another device, a new version of the application was distributed, or the application should be removed. Start removing from. This application removal process also protects the wireless device environment from repeated execution of malicious and / or destructive applications.
FIG. 3 shows a wireless network architecture in which an application distribution system is implemented in an exemplary embodiment of the present invention. The central server 302 is an entity that authenticates an application program that is compatible with a set of programming standards or conventions, either by itself or in combination with an authentication server. As mentioned above, these programming standards are established so that the application runs on software platforms such as the BREW platform.
In one embodiment, the central server database 304 identifies for each application program that is downloaded from time to time to each wireless device 330 in network 300 and the electronic service number (ESN) for the individual who downloaded the application protocol. It consists of a record of a unique mobile identification number (MIN) for the wireless device 330 that carries the application program. Meanwhile, the central server database 304 identifies each wireless device 330 in the network 300 of the wireless device model, the wireless network carrier, the area in which the wireless device 330 is used, and which wireless device 330 has which application program. Includes records for any other information that is valid to do. In addition, the central server database stores this developer identification information associated with the application.
In one embodiment, central server 302 includes removal command source 322. The removal command source 322 is the person or entity that makes the decision to remove one or more target application programs. The removal command source 322 is also the entity that constitutes the removal command 316 (discussed below) that broadcasts to the identified wireless device 330 carrying the target application protocol. On the other hand, the removal command source 322 is, without limitation, one or more persons or entities involved in the development and issuance of the target application program, persons or entities involved in the manufacture of the wireless device 330, and / or one of the networks 300. A person or entity involved in the functioning of a department.
The central server 302 preferably communicates with a secure carrier network 310 such as the Internet. The carrier network 310 communicates with the MSC 312 via the Internet and the mundane telephone system (POTS) (abbreviated as 311 in Figure 3). The Internet connection 311 between the carrier network 310 and MSC312 transfers data, and the POTS311 transfers voice information. MSC312 is connected to BTS by Internet 311 (for data transfer) and POTS311 (for voice information). The BTS314 wirelessly sends messages to wireless device 330 via short message service (SMS) or other over-the-air methods.
An example of a message transmitted by BTS 314 in the present invention is removal command 316. As further described below, the wireless device 330 responds by receiving the removal command 316 by uninstalling the target application program stored on the wireless device 330. In one embodiment, the removal program is programmed to additionally or alternatively disable the target application program or reprogram it to run in a different way. The wireless device deletes relevant information such as applications and authorization lists.
Removal command 316 is configured by removal command source 322 (which may or may not be the same person or entity that made the decision to initiate removal of the target application program). The removal command 316 is transmitted by the removal command source 322 over network 300 for broadcast to wireless device 330.
By using the removal commands described in the above embodiments, the security of application distribution and execution is increased by providing a mechanism for uninstalling malicious or unwanted applications. We have described the removal command initiated by the central server, but the wireless device initiates the removal or uninstallation of the application.
Similarly, the above network is used to send applications, authorization lists via MSC and BTS from the central server to various servers 306 via MSC and BTS to wireless device 330.
FIG. 4 shows an internal element in a wireless device and an exemplary embodiment of the invention. This embodiment is directed to, but is not limited to, the wireless device 400 as an example. The present invention limits wireless and non-wireless devices such as personal digital assistants (PDAs), wireless modems, PCMCIA cards, access terminal computers, devices without displays or keypads, or any combination or subcombination thereof. It runs on any form of remote module that can communicate over the network, including none. These examples of remote modules include user interfaces such as keypads, visual displays or sound displays.
The wireless device 400 shown in FIG. 4 has an application specific integrated circuit (ASIC) 415 installed when the wireless device 400 was manufactured. An ASIC is a hardware element driven by software contained within an ASIC. The application programming interface (APT) 410 is installed in the wireless device 400 at the time of manufacture. In one embodiment, API 410 is BREW Represents an API or software platform. API410 is a software program configured to interact with the ASIC. API410 acts as an interface between the ASIC415 hardware and the application programs installed on the wireless device 400 (discussed below). The wireless device 400, on the other hand, includes any other form of circuit that allows the program to operate in a manner compatible with the hardware configuration of the wireless device 400. The wireless device 400 has a storage device 405. The storage device 405 comprises, but is not limited to, RAM and ROM, and is any form of memory such as EPROM, EEPROM, or flash card insert.
The storage area 405 of the wireless device is used to store the received application and authorization list 425. In addition, storage area 405 is used to store one or more "keys" 405. These keys are applicable to digital signatures that use a signature algorithm to determine if the signed information has changed.
Rule 435 is installed on wireless device 400. These rules are used in connection with the allow list to determine if an application is allowed to run. For example, a rule could be that the application is allowed to run if the authentication flag is set in the allow list (ie the application has passed the authentication). The allow list has an authentication flag in a state where it is set or not set depending on whether it passed the authentication or not. By applying the rules to the information contained in the authorization list, authorization to run the application is granted or denied.
The manufacturer of the wireless device 400 (not shown) downloads the application program to the storage device 405 of the wireless device 400 when the wireless device 400 is manufactured. These application programs are any programs that may be useful or entertaining to the user of the wireless device, such as games, books or any type of data or software program. The application program is also downloaded to the wireless device 400 via the air interface after the wireless device is manufactured.
When the removal program is executed by the wireless device 400, it uninstalls one to one or more target application programs stored on the wireless device 400. The target application program is an application program that needs to be uninstalled from the wireless device 400 for various reasons described below.
The wireless device 400 has a local database 420 installed by the manufacturer. The wireless device API is programmed to automatically update the local database 420. A record identifying information about each of the application programs is stored in the wireless device 400. The local database 420 contains a unique signature identification record for each application program stored in the wireless device 402. In addition, the local database 420 can be used to record the location of application programs in storage 420 on wireless device 400 and to track which application programs were downloaded to wireless device 400 and where they exist. Includes any other information.
FIG. 5 shows information used to generate a digital signature and transmitted to a wireless device in an exemplary embodiment of the invention. As is known to those skilled in the art, digital signatures are used to track whether a digital file has been modified. As mentioned above, digital signatures can be applied to any digital file, including documents, applications, databases, and the like. In general, digital signatures are generated by applying a key to a file using a signature algorithm. This digital signature is generated using the information contained within the file. Generally, the digital signature is sent to the recipient along with the file. The recipient of the file and digital signature applies the key to the received file and digital signature to determine if the file was modified during transmission to reception.
The key used to generate and evaluate the digital signature is used to identify the signer. For example, an entity generates and secures a key to generate a digital signature. This entity can distribute the corresponding key that can be used to evaluate the digital signature. If the key is kept secure and has not been tampered with, the recipient evaluating the digital signature can determine not only whether the information has been modified, but also the identity of the signer.
Third-party entities, on the other hand, can generate keys for special entities in a secure way. Thus, a recipient with a special identity-related key can determine whether the entity was a signer.
In one embodiment of the invention, the digital signature 515 is entered into, for example, a signer's key 525, such as a central server key (see FIG. 2), application 500, authorization list 505, digital signature algorithm 530. Generated by using the developer identity information 510. The result is a digital signature 515, which depends on the information contained in the input.
After generating the digital signature 515, the application 500, authorization list 505, developer identity 510, and digital signature 515 are transmitted to the wireless device 520. The wireless device can then use a digital signature to determine if some or related information in the application (ie, authorization list and developer identity information) has changed. In addition, using one of the above technologies, such as a security key, the wireless device will trust the identity of the signer who sent this information to the wireless device.
FIG. 6 is a flow chart showing steps used by a server (single or plural) in distributing an application in a manner consistent with an exemplary embodiment of the invention. In this exemplary embodiment, processing is initiated by receiving an application and a digital signature (step S600). The digital signature is information related to the application, which allows it to determine whether the application has been modified prior to receipt. In addition, the key used to sign the digital signature must be assigned by a third party to enable the developer signing the entity and application to be the developer who received the assigned key. Is desirable.
After receiving the application and the digital signature, the digital signature is evaluated to determine if the developer who submitted the application is the same as the person who signed the application (step S605). If a third party assigns the key to the developer to generate a digital signature, the third party assigns the key to evaluate the digital signature to the recipient, such as the central server described with respect to Figure 2. ..
The developer's identity, or the entity that created the signature and / or application, is remembered and associated with the application (step S610). The storage medium is stored in a table, database, or other method that can be retrieved later when the developer needs to be identified. In one embodiment, the developer's identification memory is stored in the wireless device and not in the server.
The receiving application is then authenticated to determine if it meets certain criteria (step S615). In one embodiment, the application is written to run on a particular platform, such as the BREW platform, developed by QUALCOMM (based in San Diego, Calif.) And used for wireless devices. Certain platforms or devices have special requirements that must be met before an application can run on the device. For example, a platform or device is required to prevent an application from accessing a particular memory location within the device so that the integrity of the device or other applications located in memory are not tampered with. These criteria are identifiable and the application is tested to determine if these criteria are met. Preferably, these criteria are predetermined and provided to the developer and incorporated into the development of the application.
After authentication, application-related permissions are assigned for the given environment (step S620). Grants are granted on the basis of many factors depending on the environment in which the invention is performed. In one embodiment, the allocation authorization depends, for example, on the carrier network, wireless device requirements, certification test results, developer, carrier or other test environment. Therefore, an example of a permit list shows that the application passes the certification test and runs on the network of a particular carrier.
The server then digitally signs the application, authorization list, and developer identification (step S625). In one embodiment, this signature is performed using a secure key so that the identity of the server can be determined by the recipient of this digitally signed information. There is no need to sign the developer received by the server or send the developer signature to the wireless device.
The application, authorization list, developer identification and signature generated in step S625 are then sent to the wireless device (step S630).
FIG. 7 is a flow chart showing steps used by a wireless device when executing an application in a manner consistent with an exemplary embodiment of the invention. In this embodiment, the wireless device stores the rules to evaluate the permissions associated with the application (step S700). Although the present invention has described examples of rules / permits, there are many examples used within the scope of the invention to grant permissions for applications for a particular device or platform.
The wireless device then receives the application, authorization list, developer identification and digital signature (step S705). In one embodiment, the wireless device evaluates a digital signature received to determine the signer. Digital signatures are also used to determine if an application, authorization list, or developer identity has changed since it was signed.
The wireless device then receives a request to run the application (step S710). This request comes from a user of a wireless device who wants to execute a program. Requests, on the other hand, are generated from some requests sent to the wireless device itself or via a network or a direct connection to the wireless device.
After receiving the request, the wireless device evaluates the digital signature and the authorization list associated with the application prior to its execution (step S720). As mentioned above, in one embodiment, the wireless device uses rules for evaluating the authorization list. If it is determined by evaluating the digital signature that the application, authorization list or developer identification has not changed, the wireless device evaluates the authorization list using the stored rules. If there is no change and the evaluation of the rule against the allow list indicates that the application has been granted permission to run within the wireless device, processing proceeds to run the device arm application (step S730).
If the evaluation in step S720 indicates that the application, authorization list or developer identification has changed after signing, or the application has been denied permission to run on the wireless device, the application runs. Not done (step S725). The process transitions to remove the application from the wireless device (step S750). It is desirable that the authorization list and developer identification be removed from the wireless device.
Following step S730, application execution is monitored to determine if it has performed illegal or incorrect behavior (step S735). The wireless device or the platform used by the wireless device defines certain behaviors as illegal or fraudulent. These actions include accessing a limited area of memory or a memory location used by another program or file. In addition, these actions include the detrimental use of the resources of the wireless device, which not only affects the wireless device, but also other devices on the network to which the wireless device is connected. ..
If such illegal or misbehavior is attempted, the application will be stopped running (step S745) and preferably removed from the wireless device along with the developer identification and authorization list (step S750). As mentioned above, the removal process involves stopping the application, thereby preventing its execution and retaining the application on the wireless device.
If any illegal, illegal, or unwanted behavior is performed in step S735, the application is allowed to continue running (step S740).
Conclusion Secure and secure source application distribution and execution by using mechanisms that authenticate and detect changes, identify sources, assign permissions, and incorporate the ability to remove applications, systems and methods in line with the present invention. Increase. Systems and methods implement some or all of these mechanisms. The more the mechanism is executed, the higher the degree of safety achieved.
In one embodiment, the developer sends an application to a server. The developer signs the application to protect against unauthenticated changes. The server verifies the identity of the developer and performs certification tests on the application. The server also assigns permissions for the application and generates a permission list. The application, authorization list, and developer identification are digitally signed by the server and sent to the wireless device along with the digital signature. The wireless device checks for changes and digital signatures on the allowed list against stored rules before running the application. In one embodiment, these checks are performed prior to each attempt to run the application on the wireless device. If the check indicates that the application has been modified or denied permission to run, the application will not run and will be removed from the wireless device. In addition, if the application attempts to execute illegally or illegally while running, the application will be stopped and removed from the wireless device.
The above description of the practice of the present invention has been presented for purposes of illustration and description. It is not complete and does not limit the invention to the disclosed form. Modifications and modifications are possible from the above doctrine and are obtained from the practice of the present invention. For example, the described embodiments include software, and one embodiment of the invention is performed as a combination of hardware and software or by hardware alone. The present invention is implemented by object-oriented and non-object-oriented program systems. In addition, aspects of the invention have been described as being stored in memory, but those aspects to those skilled in the art can be described as hard disks, floppy disks, or 200 million devices such as CD-ROMs, the Internet or other transmissions. You will recognize that it is storable on other types of computer-readable media, such as carrier waves from the medium, or other forms of RAM or ROM. The scope of rights of the present invention is defined by the appended claims and their equivalents.
The accompanying drawings, which are incorporated into the specification and constitute a portion thereof, show the present preferred embodiments of the present invention, along with the general description above and the detailed description of the preferred embodiments described below, as well as the principles of the invention. It has the role of explaining.<figref num="1">It is a flowchart which shows the high level process of secure application distribution and execution in an exemplary embodiment of this invention.</figref><figref num="2">It is a block diagram which shows the system architecture which carries out the exemplary embodiment of this invention.</figref><figref num="3">FIG. 6 is a block diagram illustrating a wireless network architecture in which a secure application distribution processing system is implemented in an exemplary embodiment of the present invention.</figref><figref num="4">FIG. 6 is a block diagram showing internal elements in a wireless device and an exemplary embodiment of the present invention.</figref><figref num="5">FIG. 6 is a block diagram showing information used to generate a digital signature and transmitted to a wireless device according to an exemplary embodiment of the present invention.</figref><figref num="6">It is a flowchart which shows the step used by the server in distributing an application in an exemplary embodiment of the invention.</figref><figref num="7">FIG. 6 is a flow chart showing steps used by a wireless device when executing an application in an exemplary embodiment of the invention.</figref>
Every citation, both waysCites: the store holds 1 of 2
| Document | Relation | Office |
|---|---|---|
| JP6103058A | Cites | Japan |
| 関、外3名,”暗号を利用した新しいソフトウェア流通形態の提案 ”,情報処理学会研究報告,日本,(社)情報処理学会,1993年7月20日,第93巻、第64号(93-IS-45),第19~28頁 | Non-patent | – |
43 members in 20 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 09872418 | United States of America | – | |
| 87241801 | United States of America | A | |
| 87241801 | United States of America | A | |
| 0216485 | United States of America | W | |
| 0216485 | United States of America | W | |
| 2001872418 | – | – | – |
| 2002016485 | – | – | – |
| US20010872418 | – | – | – |
| WO2002US16485 | – | – | – |
Members43
| Document | Office | Kind | |
|---|---|---|---|
| CA2448979A1 | Canada | A1 | |
| US2002183056A1 | United States of America | A1 | |
| WO02097620A2 | World Intellectual Property Organization (WIPO) | A2 | |
| PE20030021A1 | Peru | A1 | |
| KR20040004361A | Republic of Korea | A | |
| MXPA03010890A | Mexico | A | |
| WO02097620A3 | World Intellectual Property Organization (WIPO) | A3 | |
| IL159117A0 | Israel | A0 | |
| EP1438657A2 | European Patent Office (EPO) | A2 | |
| AR036043A1 | Argentina | A1 | |
| CN1537273A | China | A | |
| HK1069451A | Hong Kong, China | A | |
| HK1069451A1 | Hong Kong, China | A1 | |
| RU2003137835A | Russian Federation | A | |
| JP2005517220A | Japan | A | |
| BR0209741A | Brazil | A | |
| TWI252701B | Taiwan Province of China | B | |
| CN1258141C | China | C | |
| NZ529867A | New Zealand | A | |
| US7099663B2 | United States of America | B2 | |
| KR100634773B1 | Republic of Korea | B1 | |
| US2006287958A1 | United States of America | A1 | |
| RU2295753C2 | Russian Federation | C2 | |
| AU2002312041B2 | Australia | B2 | |
| JP2009054165A | Japan | A | |
| EP1438657B1 | European Patent Office (EPO) | B1 | |
| AT447739T | Austria | T | |
| ATE447739T1 | Austria | T1 | |
| DE60234267D1 | Germany | D1 | |
| ES2334336T3 | Spain | T3 | |
| EP2163986A2 | European Patent Office (EPO) | A2 | |
| US7684792B2 | United States of America | B2 | |
| JP4440983B2 | Japan | B2 | |
| US2010173608A1 | United States of America | A1 | |
| CA2448979C | Canada | C | |
| JP4795636B2This record | Japan | B2 | |
| US8112076B2 | United States of America | B2 | |
| EP2163986A3 | European Patent Office (EPO) | A3 | |
| US2012137349A1 | United States of America | A1 | |
| US8588766B2 | United States of America | B2 | |
| BRPI0209741B1 | Brazil | B1 | |
| EP2163986B1 | European Patent Office (EPO) | B1 | |
| USRE48001E | United States of America | E |
28 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Re-examination (zenchi) completed and case transferred to appeal boardAppealJAPANESE INTERMEDIATE CODE: A912A912 | A912 | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 4795636
- Publication, DOCDB
- 4795636
- Publication, EPODOC
- JP4795636B
- Application
- 2003500736
- Application, DOCDB
- 2003500736
- Application, EPODOC
- JP20030500736
Titles2
- Japanese
- サーバによるアプリケーションの処理及び配布のための方法、及びアプリケーションの処理及び配布のためのシステム
- English
- A method for processing and distributing applications by the server, and a system for processing and distributing applications.
Classification
- CPC, 12
- G06F21/51
- G06F8/54
- G06F8/61
- H04W12/10
- H04L63/0823
- H04W4/60
- H04W12/35
- Y10T29/49947
- A63B69/0093
- A63B71/04
- A63G31/007
- E04H4/0006
- IPC, 9
- G06F9 445
- G06F21 22
- H04W12 00
- G06F
- G06F1 00
- G06F5 00
- G06F21 00
- H04W4 60
- H04W12 10