Safe application distribution and execution in a wireless environment
Abstract
The present invention provides for secure and guaranteed application distribution and execution by providing a system and method for testing an application to certify that it meets predetermined criteria related to the environment in which the application will be executed. In addition, using change detection techniques such as rule and permission lists, application removal, and digital signatures, the present invention determines whether an application has been tampered with, determines whether it is permitted to run in a given wireless device environment, and removes the application. This provides a mechanism for safely distributing and running tested and untested applications.

Term
Term ended
Projected expiry passed 13 February 2023, 3.6 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
53 claims: 15 independent, 38 dependent
- 1애플리케이션과 식별 정보를 수신하는 단계, 상기 애플리케이션이 소정의 기준을 만족하는 것을 인증하는 단계, 상기 애플리케이션에 허가를 할당하는 단계, 변경 검출 기술을 사용하여 애플리케이션, 허가, 및 식별 정보를 장치로 전송하는 단계, 전송하는 동안 애플리케이션이 변경되었는지를 판정하는 단계, 장치상에 규칙을 저장하는 단계, 허가 및 규칙을 사용하여, 상기 애플리케이션이 처리될 수 있는지를 판정하는 단계, 및 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 구비하는 것을 특징으로 하는 애플리케이션을 분배 및 처리하는 방법.
- 2제 1 항에 있어서, 상기 장치상에서 상기 애플리케이션의 실행을 개시하는 단계, 애플리케이션의 실행을 모니터하는 단계, 및 부적절한 동작을 시도하는 애플리케이션을 검출하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 3제 1 항에 있어서, 상기 애플리케이션은 상기 장치상에서 처리될 허가가 부정되는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 4제 1 항에 있어서, 상기 식별 정보는 상기 장치에 의해 검색되는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 5제 1 항에 있어서, 애플리케이션의 변경을 검출하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 6제 1 항에 있어서, 허가의 변경을 검출하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 7제 1 항에 있어서, 변경 검출 기술은 디지털 서명을 이용하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 8애플리케이션 및 식별 정보를 수신하는 단계, 상기 애플리케이션이 소정의 기준을 만족하는 것을 인증하는 단계, 상기 애플리케이션에 허가를 할당하는 단계, 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 무선 장치로 전송하는 단계, 상기 장치상에 규칙을 저장하는 단계, 및 상기 허가 및 상기 규칙을 사용하여 상기 애플리케이션이 상기 장치상에 처리될 수 있는지를 판정하는 단계를 구비하는 것을 특징으로 하는 애플리케이션을 분배 및 처리하는 방법.
- 9제 8 항에 있어서, 무선 장치상에서 상기 애플리케이션의 실행을 개시하는 단계, 상기 애플리케이션의 실행을 모니터하는 단계, 부적절한 동작을 시도하는 애플리케이션을 검출하는 단계, 및 상기 무선 장치로부터 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 10제 8 항에 있어서, 상기 애플리케이션은 상기 무선 장치에서 처리될 허가가 부정되고, 상기 장치로부터 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 벙법.
- 11제 8 항에 있어서, 상기 식별 정보는 상기 무선 장치에 의해 판정되는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 12제 8 항에 있어서, 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 전송하기 위하여 변경 검출 기술이 이용되는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 13제 12 항에 있어서, 상기 변경 검출 기술은 디지털 서명을 이용하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 14제 12 항에 있어서, 상기 장치로 전송된 애플리케이션의 변경을 검출하는 단계, 및 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 15제 12 항에 있어서, 상기 장치로 전송된 허가의 변경을 검출하는 단계, 및 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 16애플리케이션 및 식별 정보를 수신하는 단계, 상기 애플리케이션에 허가를 할당하는 단계, 변경 검출 기술을 이용하여 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 상기 장치로 전송하는 단계, 전송하는 동안 상기 애플리케이션이 변경되었는지를 판정하는 단계, 상기 장치에 규칙을 저장하는 단계, 상기 허가 및 상기 규칙을 이용하여 상기 애플리케이션이 처리될 수 있는지를 판정하는 단계, 및 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 구비하는 것을 특징으로 하는 애플리케이션을 분배하고 처리하는 방법.
- 17제 16 항에 있어서, 무선 장치상에서 애플리케이션의 실행을 개시하는 단계, 상기 애플리케이션의 실행을 모니터하는 단계, 부적절한 동작을 시도하는 애플리케이션을 검출하는 단계, 및 상기 무선 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 18제 16 항에 있어서, 상기 애플리케이션은 상기 무선 장치상에서 처리될 허가가 부정되고, 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 19제 16 항에 있어서, 상기 식별 정보는 상기 무선 장치에 의해 판정되는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 20제 16 항에 있어서, 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 전송하기 위하여 변경 검출 기술이 사용되는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 21제 20 항에 있어서, 상기 변경 검출 기술은 디지털 서명을 사용하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 22제 20 항에 있어서, 상기 장치로 전송된 애플리케이션의 변경을 검출하는 단계, 및 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 23제 12 항에 있어서, 상기 장치로 전송된 허가의 변경을 검출하는 단계, 및 상기 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 및 처리 방법.
- 24애플리케이션 및 개발자 식별을 수신하고, 애플리케이션과 관련된 허가를 할당하고, 상기 무선 장치에 애플리케이션 정보를 전송하도록 동작할 수 있는 중앙 서버, 상기 애플리케이션이 미리 정의된 기준을 만족하는 것을 인증하도록 동작할 수 있는 서버, 및 애플리케이션 및 개발자 식별을 수신하고 할당된 허가를 평가하도록 동작할 수 있는 무선 장치를 구비하는 것을 특징으로 하는 무선 장치상에 애플리케이션을 분배하고 실행하는 시스템.
- 25제 24 항에 있어서, 상기 중앙 서버는 또한 변경 검출 기술을 사용하여 무선 장치로 애플리케이션을 전송하도록 동작하는 것을 특징으로 하는 애플리케이션 분배 및 실행 시스템.
- 26제 24 항에 있어서, 상기 중앙 서버는 또한 변경 검출 기술을 사용하여 무선 장치로 상기 허가를 전송하도록 동작하는 것을 특징으로 하는 애플리케이션 분배 및 실행 시스템.
- 27제 24 항에 있어서, 상기 애플리케이션을 인증하도록 동작할 수 있는 상기 서버는 중앙 서버인 것을 특징으로 하는 애플리케이션 분배 및 실행 시스템.
- 28제 24 항에 있어서, 상기 무선 장치는, 상기 무선 장치에 저장된 규칙을 사용하여, 할당된 허가를 평가하도록 동작할 수 있는 것을 특징으로 하는 애플리케이션 분배 및 실행 시스템.
- 29애플리케이션 및 식별 정보를 수신하는 수단, 상기 애플리케이션에 허가를 할당하는 수단, 변경 검출 기술을 이용하여 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 장치로 전송하는 수단, 전송하는 동안, 상기 애플리케이션이 변경되었는지를 판정하는 수단, 상기 장치상에 규칙을 저장하는 수단, 상기 허가 및 상기 규칙을 사용하여 상기 애플리케이션이 처리될 수 있는지를 판정하는 수단, 및 상기 장치로부터 상기 애플리케이션을 제거하는 수단을 구비하는 것을 특징으로 하는 무선 장치상에 애플리케이션을 분배하고 실행하는 시스템.
- 30애플리케이션 및 식별 정보를 수신하는 단계, 상기 애플리케이션이 소정의 기준을 만족하는 것을 인증하는 단계, 상기 애플리케이션에 허가를 할당하는 단계, 변경 검출 기술을 이용하여 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 상기 장치로 전송하는 단계, 및 상기 애플리케이션을 장치로부터 제거하는 요구를 개시하는 단계를 구비하는 것을 특징으로 하는 애플리케이션 분배를 처리하는 방법.
- 31제 30 항에 있어서, 상기 수신된 애플리케이션 및 식별 정보를 평가하여 애플리케이션의 개발자의 식별을 판정하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 32제 30 항에 있어서, 상기 변경 검출 기술은 디지털 서명을 이용하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 33애플리케이션 및 식별 정보를 수신하는 단계, 상기 애플리케이션에 허가를 할당하는 단계, 및 변경 검출 기술을 이용하여 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 장치에 전송하는 단계를 구비하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 34제 33 항에 있어서, 장치로부터 애플리케이션을 제거하는 요구를 개시하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 35제 33 항에 있어서, 상기 애플리케이션이 소정의 기준을 만족하는 것을 인증하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 36제 33 항에 있어서, 상기 수신된 애플리케이션 및 식별 정보를 평가하여 상기 애플리케이션의 개발자의 식별을 판정하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 37제 33 항에 있어서, 상기 변경 검출 기술은 디지털 서명을 이용하는 것을 특징으로 하는 애플리케이션 분배 처리 방법.
- 38애플리케이션 및 식별 정보를 수신하고, 허가를 할당하고, 변경 검출 기술을 이용하여 애플리케이션을 전송하도록 동작할 수 있는 중앙 서버, 및 상기 애플리케이션을 검색하기 위하여 상기 중앙 서버에 접속된 네트워크를 구비하는 것을 특징으로 하는 애플리케이션 분배 시스템.
- 39제 38 항에 있어서, 상기 중앙 서버는 또한 상기 애플리케이션이 미리 정의된 기준을 만족하는 것을 인증하도록 동작할 수 있는 것을 특징으로 하는 애플리케이션 분배 시스템.
- 40애플리케이션 및 식별 정보를 수신하는 수단, 상기 애플리케이션이 소정의 기준을 만족하는 것을 인증하는 수단, 상기 애플리케이션에 허가를 할당하는 수단, 및 변경 검출 기술을 이용하여, 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 상기 장치로 전송하는 수단을 구비하는 것을 특징으로 하는 애플리케이션 분배 시스템.
- 41애플리케이션 및 식별 정보를 수신하는 단계, 상기 애플리케이션이 소정의 기준을 만족하는 것을 인증하는 단계, 상기 애플리케이션에 허가를 할당하는 단계, 및 변경 검출 기술을 이용하여, 상기 애플리케이션, 상기 허가, 및 상기 식별 정보를 상기 장치로 전송하는 단계를 구비하는 것을 특징으로 하는 애플리케이션 분배를 위한 컴퓨터 실행가능 명령을 포함하는 컴퓨터 판독가능 매체.
- 42허가를 평가하는 규칙을 저장하는 단계, 변경 검출 기술을 사용하여 애플리케이션, 허가, 및 식별을 구비하는 정보를 수신하는 단계, 무선 장치상에서 애플리케이션을 실행하는 요구를 수신하는 단계, 수신된 정보를 평가하여 수신된 정보가 변경되었는지를 판정하는 단계, 수신된 정보가 변경되지 않았을때는 애플리케이션과 관련된 허가를 평가하는 단계, 및 허가가 부여되면, 애플리케이션을 실행하는 단계를 구비하는 것을 특징으로 하는 무선 장치상에서 애플리케이션을 실행하는 방법.
- 43제 42 항에 있어서, 상기 변경 검출 기술은 디지털 서명을 이용하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 44제 42 항에 있어서, 상기 애플리케이션의 실행을 모니터하여 부적절한 동작이 시도되었는지를 판정하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 45제 42 항에 있어서, 상기 무선 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 46허가를 평가하는 규칙을 저장하는 단계, 변경 검출 기술을 사용하여 애플리케이션, 허가, 및 식별을 구비하는 정보를 수신하는 단계, 무선 장치상에서 애플리케이션을 실행하는 요구를 수신하는 단계, 애플리케이션과 관련된 허가를 평가하는 단계, 및 정보가 변경되었으면, 상기 무선 장치로부터 애플리케이션을 제거하는 단계를 구비하는 것을 특징으로 하는 무선 장치상에서 애플리케이션을 실행하는 방법.
- 47제 46 항에 있어서, 상기 수신된 정보가 변경되지 않았으면, 상기 애플리케이션과 관련된 허가를 평가하는 단계, 및 허가가 부여되었으면, 애플리케이션을 실행하는 단계를 구비하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 48제 46 항에 있어서, 상기 변경 검출 기술은 디지털 서명을 이용하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 49제 46 항에 있어서, 상기 애플리케이션의 실행을 모니터하여 부적절한 실행이 시도되는지를 판정하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 50제 46 항에 있어서, 상기 부적절한 동작이 시도되면, 상기 무선 장치로부터 상기 애플리케이션을 제거하는 단계를 더 구비하는 것을 특징으로 하는 애플리케이션 실행 방법.
- 51애플리케이션 및 허가를 수신하는 입력, 상기 허가를 평가하기 위하여 기억장치에 포함된 규칙, 및 디지털 서명을 평가하기 위하여 기억장치내에 포함된 키를 구비하고, 무선 장치는 상기 허가와 디지털 서명할때 상기 애플리케이션이 실행되도록 동작하는 것을 특징으로 하는 애플리케이션 실행 무선 장치.
- 52허가를 평가하는 규칙을 저장하는 수단, 변경 검출 기술을 이용하여 애플리케이션, 허가, 및 식별을 구비하는 정보를 수신하는 수단, 상기 무선 장치상에서 상기 애플리케이션을 실행하는 요구를 수신하는 수단, 상기 수신된 정보를 평가하여 상기 수신된 정보가 변경되었는지를 판정하는 수단, 상기 수신된 정보가 변경되지 않았을때, 상기 애플리케이션과 관련된 허가를 평가하는 수단, 및 상기 허가가 부여되었을때, 상기 애플리케이션을 실행하는 수단을 구비하는 것을 특징으로 하는 애플리케이션 실행 무선 장치.
- 53허가를 평가하는 규칙을 저장하는 단계, 변경 검출 기술을 이용하여 애플리케이션, 허가, 및 식별을 구비하는 정보를 수신하는 단계, 상기 무선 장치상에서 상기 애플리케이션을 실행하는 요구를 수신하는 단계, 상기 수신된 정보를 평가하여 상기 수신된 정보가 변경되었는지를 판정하는 단계, 상기 수신된 정보가 변경되지 않았을때, 상기 애플리케이션과 관련된 허가를 평가하는 단계, 및 상기 허가가 부여되었을때, 상기 애플리케이션을 실행하는 단계를 구비하는 것을 특징으로 하는 애플리케이션 분배를 위한 컴퓨터 실행가능 명령을 포함하는 컴퓨터 판독가능 매체.
Independent claims53
87 paragraphs, as filed
SAFE APPLICATION DISTRIBUTION AND EXECUTION IN A WIRELESS ENVIRONMENT IN A WIRELESS ENVIRONMENT
BACKGROUND OF THE INVENTION Field of the Invention [0002] The present invention relates to the processing of applications used on wireless devices, and more particularly, to increase the protection, safety, and integrity of applications running on wireless devices.
Wireless communications have grown rapidly in recent years. As consumers or businesses rely more on wireless devices such as mobile phones and personal digital assistants (PDAs), wireless service providers, i.e. carriers, are striving to provide additional functionality to these wireless devices. This additional capability may increase the demand for wireless devices as well as increase usage among current users. However, increasing the functionality, particularly increasing the applications that can be accessed by a wireless device, increases cost and complexity, preventing carriers from providing this functionality.
Also, there is little guarantee that an application once deployed on a wireless device will run properly. Currently, confidence in the ability of an application to run on a wireless device depends on the developer, wireless device manufacturer and/or carrier. As more applications are developed and the number of applications on wireless devices increases, the wireless device environment becomes more dynamic. For example, a wireless device may choose to retrieve or launch many different applications from a large pool of available applications at any given time. Therefore, ensuring that a given application is distributed to the wireless device and executed safely makes control more and more difficult.
This is of particular interest because improper execution of the application may adversely affect the wireless device as well as other network components including other wireless devices and the carrier network. For example, and not limited to, one application may control the power of a wireless device and cause interference between other wireless devices and may reduce any capacity of the cell serving the wireless device.
Currently, neither the wireless device manufacturer nor the carrier is equipped to support application testing and secure distribution in a dynamic application distribution and execution environment. Therefore, it is of interest to see if applications that may be detrimental to the wireless device, carrier network, or other network components are distributed and run on the wireless device.
Also, as many applications are developed, other safety issues arise and the environment in which applications are sent to wireless devices becomes more dynamic. As the number of applications and the number of developers who create them increases, the desire to know the source, ie, the developer, of any given application also increases. A carrier or handset manufacturer will want to know with what degree of confidence the source of the application can be judged to be harmful.
Consequently, there is a need in the art for systems and methods that provide a more secure environment for distributing and running applications on wireless devices.
<b><u>Summary of the invention</u></b>
A system and method according to the present invention tests an application to a predetermined standard, provides a trace function to the developer for nonrepudiation, checks the application for unintended changes, and allows the application to be removed from the wireless device. It overcomes the shortcomings of existing systems by creating a more secure environment for application distribution and execution using rules and permissions that allow for removal and/or define the environment in which applications can be run.
Authenticating that an application meets certain standards provides the advantage of discovering possible errors that may occur during execution quickly in time. This helps to prevent detrimental effects on the execution of the application.
Traceability provides the advantage of non-repudiation. If there is any problem with the application, it is beneficial to go back to the source of the application, ie the developer, and correct the problem. In addition, tracing prevents developers from creating applications with harmful consequences, whether intentional or unintentional.
Additionally, the ability to determine if an application has changed prior to receiving the application on the wireless device provides the added benefit of increased security by ensuring that the received application is identical to the one sent. As applications become more freely distributed in the wireless environment, the ability to determine whether an application has been altered increases the certainty that the application received by the wireless device has not been accidentally or intentionally altered.
Providing a set of rules and permissions that define when an application can be executed improves the safety of the application distribution and execution system by preventing unauthorized execution of the application on a platform, e.g., on an unauthorized system or environment. also increase
The ability to remove applications from wireless devices also increases the security of the application distribution system. When an application is installed by the manufacturer or via a downloaded application, having a mechanism for the application to uninstall the application due to unpredictable negative consequences is the safety of the application distribution and execution system by removing harmful and unwanted code that can be compromised. to increase
Systems and methods according to the present invention may practice the techniques disclosed herein or more. By practicing all of the techniques disclosed and referenced herein, the systems and methods related to the present invention provide for high quality and secure distribution and execution of applications.
According to an embodiment of the present invention, a method of distributing and processing an application includes the steps of: receiving an application and identification information; authenticating that the application meets a predetermined criterion; assigning a permission to the application; sending the application, permission, and identification information to the device using a change detection technique, determining if the application has changed during the transfer, storing the rule on the device, using the permission and rule, the application determining whether it can be processed, and removing the application from the device.
According to another embodiment of the present invention, a method of executing an application on a wireless device comprises the steps of: storing a rule for evaluating a permission; receiving information comprising the application, the permission, and an identification using a change detection technique; receiving a request to run an application on the wireless device, evaluating the received information to determine whether the received information has changed, evaluating the permissions associated with the application if the received information has not changed, and if the permission is If granted, executing the application.
According to another embodiment of the present invention, a method of running an application on a wireless device comprises the steps of: storing a rule for evaluating a permission; receiving information comprising the application, permission, and identification using a change detection technique; receiving a request to run an application on the wireless device, evaluating the received information to determine whether the received information has changed, when the received information has not changed, evaluating the permissions associated with the application; and if the permission is granted, running the application.
BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings, which are incorporated in and constitute a part of this specification, show a preferred embodiment of the present invention, which together with the general description given above and the preferred embodiment given hereinafter serves to explain the principles of the present invention.
1 is a flowchart illustrating a high-level process of secure application distribution and execution of an exemplary embodiment of the present invention;
Fig. 2 is a block diagram showing a system configuration in which an exemplary embodiment of the present invention can be implemented;
3 is a block diagram illustrating a wireless network configuration in which a secure application distribution processing system may be implemented in an exemplary embodiment of the present invention;
4 is a block diagram illustrating a wireless device and several internal components in an exemplary embodiment of the present invention;
5 is a block diagram illustrating information used to generate a digital signature and transmitted to a wireless device in an exemplary embodiment of the present invention;
6 is a flowchart illustrating steps used by a server or servers in distributing an application in an exemplary embodiment of the present invention;
7 is a flow chart illustrating steps used by a wireless device in executing an application in an exemplary embodiment of the present invention;
Reference numerals are provided to detail exemplary and preferred embodiments of the present invention as described in the accompanying drawings, and the same reference numerals refer to the same or corresponding parts in several drawings. The features, objects and advantages of the present invention will become apparent to those skilled in the art from the following detailed description in conjunction with the accompanying drawings.
The present invention provides secure and guaranteed application distribution and execution by providing a system and method for testing an application to certify that it meets certain criteria related to the environment in which it will be run. In addition, using change detection techniques such as rule and permission lists, application removal and digital signatures, the present invention is tested by determining whether an application has been altered, is authorized to run in a given wireless device environment, and if it is desirable for the application to be removed. It provides a mechanism to safely distribute and run untested and untested applications.
Those skilled in the art will recognize that what has been described above is in the form of distributed and executed application files for the sake of simplicity of description. An "application" may also include files having executable content, such as object code, scripts, Java files, bookmark files (or PQA files), WML scripts, byte code, and perl scripts. Also, "application" referred to herein may include files that cannot be executed in nature, such as documents that need to be opened or other data that need to be accessed.
1 is a flowchart illustrating a high-level process of secure application distribution and execution of a method according to an exemplary embodiment of the present invention; Embodiments of the present invention allow developer identification to be associated with an application, test the application against the environment in which the application runs, assign permissions that can be used to indicate that a device or system is capable of running the application, Remove the application when it performs illegal or undesirable behavior.
It is desirable for systems and methods to employ all of these techniques to increase the secure distribution and execution of applications. However, it will be appreciated that employing one or more of these techniques increases the secure distribution and execution of applications.
The high-level process begins by associating the application with developer identification (step 100). This process can be done by associating application and developer identification as distributed. Alternatively, the associated developer identification may be stored according to the corresponding application on a server in the system. In addition, the developer identification information is preferably stored so as not to be easily changed and associated with the application information.
The application is then tested for improper behavior (step 105). An application may be used in an environment where improper operation may not only affect the device on which the application is run, but also other devices connected or networked with that device. During its operation, it is desirable to test the application so that it does not adversely affect the device or other connected devices or make inappropriate system calls. In one embodiment, this test is performed by a certification process in which the application is tested to determine whether it meets predetermined criteria. It is also desirable to have a certification process independent of the developer to test the application. The independence of this certification process promotes accurate and reliable testing.
Before running the application, a check is made to determine if the application is authorized to run on the device (step 110). This check can be performed using the permissions and rules described below or other permission mechanisms known to those skilled in the art. Also, it is desirable to check the application each time before running the application. This continuous check process increases the safety of application execution. For example, it protects against applications with Trojan horses that have injected the application onto the execution device via another application.
Applications performing inappropriate or undesirable actions are then removed from the device (step 115). This prevents the application from doing any further damage and also frees up memory in the device for other uses. Alternatively, the application is not necessarily removed from the application. Uninstalling an application may mean leaving the application on the device unattended or disabling the application.
Fig. 2 shows a system configuration in which an exemplary embodiment of the present invention can be implemented. Developer 200 creates an application to be used on wireless device 230 . As noted above, although the foregoing description has been described as including application file types, those skilled in the art will recognize that other file types may be used. In addition, those skilled in the art will recognize that the present invention may be used with other wireless or non-wireless devices and may employ wireless networks, non-wireless networks, or combinations thereof.
In general, the developer 200 will have a set of development plans for developing applications that run on the wireless device 230 . In one embodiment, the wireless device is a BREW developed by Qualcomm Corporation of San Diego, California, USA.<sup>TM</sup> Includes a soft platform that assists in interfacing applications with wireless devices, such as software. The developer is a software platform or BREW<sup>TM</sup> Applications, design standards, and conventions that satisfy the software can be created.
In one embodiment, developer 200 is connected to central server 205 to electronically transmit applications to central server 205 . In one embodiment, the central server is an Application Control Center Headquarter server used for application distribution to wireless devices. Developer 200 digitally signs the application (discussed below) to determine if the application has been tampered with. It will be appreciated that a physical connection to the central server is not required. For example, the developer 200 may transmit the application to the central server 205 stored on the CD-ROM via first-class mail or the like.
In addition, the developer transmits various source identification information to the central server 205 . This source identification information may include any form of information that may be associated with an application that identifies a developer, such as a company name, tax identification of the company, or other identification information.
The central server 205 is used for analysis and authentication of applications either by itself or using the authentication server 210 . In one embodiment, the Application Control Center (ACC) may be used as an authentication server. The authentication server 210 may be used to analyze the application to determine whether the application meets certain authentication criteria. The criteria may include determining whether the application meets a development design for execution on a wireless device or platform. However, the authentication criteria may be any criteria that an application must satisfy before running on a wireless device or platform. These criteria ensure that (a) the application is not detrimental to the operation of the wireless device (e.g., the phone does not fail), the application functions as required by the developer, and (b) data or memory that the application should not access is protected. not access (e.g., not access data or files owned by other applications, operating systems, or platform software); This may include demonstrating that there is no effect.
The central server 205 may also assign a set of permissions in the list associated with the application. This permission list is determined by various factors including whether the application has passed the authentication process, which networks 220 have authorized the application to run, and whether the wireless device supports the application. There are many factors used to determine this permission list and it is left to those skilled in the art when implementing the present invention.
The central server 205 receives the developer identification information and correlates the developer identification information with the application created by the developer 200 . If there is any problem with the application, the central server can identify the source of the application. In one embodiment, developer information is passed through wireless device 230 so that correlation can be performed by the wireless device or other system connected to the wireless device.
In one embodiment, the central server is also connected to an application download server (ADS) 215 . The application download server 215 is used to interface with a wireless device via the wireless network 220 to download applications. The central server may also send the permission list and developer identification associated with the application to the ADS, which may be stored until transmitted to the wireless device. Applications, permission lists, and developer identification are preferably digitally signed by a central server to increase security from tampering.
Those skilled in the art will recognize that ADS can be used to connect to multiple networks 220 for distributing applications, files, and other information to various wireless devices 230 . Additionally, wireless and non-wireless networks may be employed to transmit the application's permission list and developer identification to the wireless device.
In response to the request for the application, the ADS 215 will send the application, permission list, developer identification, and digital signature(s) to the wireless device 230 over the network 220 . In one embodiment, the wireless device 230 will include a key that checks the digital signature to determine if the application, permission list, and/or developer information has changed.
If a digital signature is employed in the present invention, the central server preferably uses the secure key to generate the digital signature and installs the key in the wireless device to evaluate the digital signature. By using the secure key, the wireless device will have a high degree of confidence that the digital signature was generated by a central server and not by a crook.
If the application throws any error on the radio or for any other reason, the wireless device may initiate the removal of the application. In addition, applications can be removed from the wireless device based on requests from the ADS or central server. This request from the server can be generated for any reason. For example, the server may initiate the removal of the application from the wireless device for business reasons such as the application being improperly performed on another device, a new version of the application being distributed, or the application being uninstalled. This application removal process may also protect the wireless device environment from repeated execution of erroneous and/or destructive applications.
3 shows a wireless network configuration in which an application distribution system can be implemented in an exemplary embodiment of the present invention. The central server 302 is an entity that authenticates an application program that is compatible with a set of programming standards or rules defined by itself or in association with an authentication server. As discussed above, these program standards require that applications<sup>TM</sup> It may be established to be executable on a software platform, such as a platform.
In one embodiment, the central server database 304 contains a record of identification for an application program downloaded at any time to each wireless device 330 of the network 300, an electronic service number (Electronic Service) for the entity from which the application program was downloaded. Number: ESN), and a Mobile Identification Number (MIN) unique to the wireless device 330 with an application program. Alternatively, the central server database 304 may have a record for each wireless device 330 of the network 300 of the wireless device model, the wireless network carrier, the area in which the wireless device 330 is used, and an application program. and any other information that can be used to identify the wireless device 330 . In addition, the central server database may also store this developer identification information associated with the application.
In one embodiment, the central server 302 may include a remove command source 322 . The uninstall command source 322 is a person(s) or entity(s) that determines whether to uninstall one or more target application programs. The uninstall command source 322 is also an entity that makes up the uninstall command 316 (discussed below) to be provided to the identified wireless device 330 having the target application program(s). Alternatively, and without limitation, the remove command source 322 may be one or more persons or entities involved in the development and publication of a target application program, persons or entities involved in the manufacture of the wireless device 330 , and/or of the network 300 . A person or entity related to the function of a part.
The central server 302 communicates with one or more computer servers 306, eg, ADS, preferably via a network 308, such as a secure Internet. Server 306 also communicates with carrier network 310 via network 308 . The carrier network 310 communicates with the MSC 312 via the Internet and POTS (Plain Ordinary Telephone System; collectively denoted 311 in FIG. 3 ). The Internet connection 311 between the carrier network 310 and the MSC 312 transmits data, and the POTS 311 transmits voice information. MSC 312 is connected to multiple base stations (BTS) 314 . The MSC 312 is connected to the BTS by an Internet 311 (for data transmission) and a POTS 311 (for voice transmission). The BTS 314 wirelessly transmits a message to the wireless device 330 by a short message service (SMS) or any other broadcast method.
An example of a message sent by the BTS 314 of the present invention is the remove command 316 . As further described herein, the wireless device responds by uninstalling the target application program stored on the wireless device 330 in response to receiving the uninstall command 316 . In one embodiment, the uninstall program may additionally or alternatively be programmed to disable or reprogram the target application program to perform differently. The wireless device may also delete any relevant information, such as applications and permission lists.
The uninstall command 316 is constituted by the uninstall command source 322 (which may or may not be the same as the person(s) or entity(s) determining to initiate the uninstallation of the target application program). The remove command 316 is transmitted by the remove command source 322 over the network 300 in simultaneous communication to the wireless device 330 .
Using the uninstall command described in the above embodiment, the security of application distribution and execution is increased by providing a mechanism to uninstall erroneous or undesirable applications. Those skilled in the art will recognize that although the uninstall command described above is initiated by the central server, the wireless device may also initiate the uninstallation or uninstallation of the application and its associated information.
Likewise, the above network can be used to transmit applications, authorization lists and associated digital signatures from a central server to various servers 306 (eg, ADS) to the wireless device 330 via the MSC and BTS.
4 shows a wireless device and some internal components in an exemplary embodiment of the present invention. Although this embodiment relates to wireless device 400, this embodiment is used as an example without any intended limitation. The present invention includes wireless and non-wireless devices such as, but not limited to, personal digital assistants (PDAs), wireless modems, PCMCIA cards, access terminals, personal computers, devices without displays or keypads, or any combination or subcombination thereof. It may alternately be performed on any type of remote module capable of communicating over the containing network. Examples of these remote modules may also have a user interface such as a keypad, visual display or sound display.
The wireless device 400 shown in FIG. 4 has an application specific integrated circuit (ASIC) 415 installed when the wireless device 400 is manufactured. An ASIC is a hardware component driven by software contained within the ASIC. An application programming interface (API) 410 is also installed in the wireless device 400 at the time of manufacture. In one embodiment, API represents a BREW API or software platform. API 410 is a software program configured to interoperate with an ASIC. The API 410 is provided as an interface between the ASIC 415 hardware and an application program (described below) installed on the wireless device 400 . Alternatively, wireless device 400 may include any other type of circuitry that allows programs to operate in a manner compatible with the hardware configuration of wireless device 400 . The wireless device 400 also has a storage area 405 . The storage area 405 is composed of RAM and ROM, but may alternatively be any type of memory such as EPROM, EEPROM or flash card insert.
The wireless device's storage area 405 can be used to store received applications and permission lists 425 . Also, the storage area 405 may be used to store one or more keys 405 . These keys can be applied to a digital signature using a signature algorithm to determine if the signed information has been tampered with.
Rule 435 may also be installed on wireless device 400 . These rules are used in conjunction with the permission list to determine if the application is allowed to run. For example, a rule indicates that an application is allowed to run if the authentication flag is set in the permission list (ie, indicating pass-through authentication of the application). The permission list will have an authentication flag set or unset depending on whether the application has passed authentication. By applying the rule to the information contained in the permission list, permission to run the application is granted or denied.
A manufacturer (not shown) of the wireless device 400 may download an application program to the base area 405 of the wireless device 400 when the wireless device 400 is manufactured. These application programs may be any program that is potentially useful to or entertaining the user of the wireless device, such as a game, book, or any other form of data or software program. The application program may also be downloaded to the wireless device 400 via broadcast after the wireless device is manufactured.
When executed by the wireless device 400 , the uninstall program uninstalls one or more target application programs from one of the applications stored on the wireless device 400 . The target application program is an application program that needs to be uninstalled from the wireless device 400 for various reasons described below.
The wireless device 400 has a local database 420 installed by the manufacturer. The wireless device's API is programmed to automatically update the local database 420 with records identifying information for each of the application programs stored on the wireless device 400 . The local database 420 contains a record of the signature identification unique to each application program stored on the wireless device 402 . The local database 420 also contains a record of the location of the application program within the airspace area 405 on the wireless device 400 and any other information useful in maintaining a track where the application program has been downloaded and located on the wireless device 400 . may include.
5 is a block diagram illustrating information transmitted to a wireless device used to generate a digital signature in an exemplary embodiment of the present invention. As is known to those skilled in the art, digital signatures can be used to track whether a digital file has been tampered with. As noted, digital signatures can be applied to any digital file, including documents, applications, databases, and the like. Typically, a digital signature is created by applying a key to a file using a signature algorithm. This digital signature is created using the information contained within the file. Typically, the digital signature is sent along with the file to the recipient. The recipient of the file and digital signature applies a key to the received file and digital signature to determine if the file has been tampered with during transmission to the recipient.
The key used to generate and evaluate the digital signature can be used to determine the identity of the signer. For example, a key may be generated and kept secure for an entity to generate a digital signature. This entity may distribute a corresponding key that may be used to evaluate the digital signature. If the key is kept secure and not compromised, the recipient evaluating the digital signature can determine the identity of the signer as well as determine whether the information has been tampered with.
Alternatively, the third entity may generate a key for a particular entity in a secure manner. Thus, a recipient with a key associated with a particular identification will be able to determine whether the entity was a signer.
In one embodiment of the present invention, digital signature 515 is the signer's key 525 input to digital signature algorithm 530, e.g., the key of a central server (see FIG. 2), application 500, permission List 505 , and developer identification information 510 . The result is a digital signature 515 that relies on the information contained in the input.
After generating the digital signature 515 , the application 500 , the permission list 505 , the developer identification information 510 , and the digital signature 515 are sent to the wireless device 520 . The wireless device can then use the digital signature to determine which of the applications or related information (ie, permission list and developer identification information) has changed. In addition, using one of the techniques described above, such as a secure key, the wireless device can also have certainty of identification of the signer who sent this information to the wireless device.
6 is a flowchart illustrating steps that may be used by a server or servers in distributing an application in a method related to an exemplary embodiment of the present invention. In this exemplary embodiment, the process is initiated by receiving an application and a digital signature (step 600). A digital signature is information related to an application so that it can be determined whether the application has been tampered with prior to its receipt. It is also desirable that the key used to sign the digital signature be assigned by a third party to confirm that the entity or developer that signed the application is the developer receiving the assigned key.
After receiving the application and digital signature, the digital signature is evaluated to determine whether the developer who sent the application is the same person who signed the application (step 605). When a third party assigns a key to a developer to generate a digital signature, the third party can also assign a key to evaluate the digital signature for a recipient, such as the central server described with respect to FIG. 2 .
An identification of the developer or whether an entity has signed and/or created the application is then stored and associated with the application (step 610). Storage may be done in a table, database, or some other way so that the developer's identity can be retrieved later when needed. In one embodiment, the developer's identification is not stored within the server, but within the wireless device.
The received application is then authenticated to determine if it meets certain criteria (step 615). In one embodiment, the application is BREW developed by Qualcomm Corporation, located in San Diego, CA, USA, used in a wireless device.<sup>TM</sup> It can be written to run on a specific platform, such as a platform. A particular platform or device may have specific requirements that an application must satisfy before the application can run on the device. For example, a platform or device may require that an application not access a particular memory location within the device so that the integrity of the device or other applications located in the memory is not compromised. These criteria can be specified and the application can be tested to determine if these criteria are met. Preferably, these criteria are predetermined and may be provided to the developer and incorporated into the development of the application.
After authentication, the permissions associated with the application for the given environment are assigned (step 620). Permissions may be assigned based on many factors depending on the environment in which the present invention is practiced. In one embodiment, the application is for a wireless device. In this embodiment, the assignment of permissions may depend, for example, on the carrier network, the requirements of the wireless device, the certification test results, and the developer, carrier or other test environment. Thus, an example of an authorization list indicates that an application can pass an authentication test and run on a particular carrier's network.
The server then digitally signs the application, permission list, and developer identification (step 625). In one embodiment, this signing is performed using a secure key so that the identity of the server can be determined by the person receiving this digitally signed information. The developer's signature received by the server need not also be signed or the developer's signature transmitted to the wireless device.
The application, permission list, developer identification, and signature created in step 625 are then sent to the wireless device (step 630).
7 is a flowchart illustrating steps used by a wireless device in executing an application in a method according to an exemplary embodiment of the present invention. In this embodiment, the wireless device stores a rule for evaluating the permissions associated with the application (step 700). Those skilled in the art will recognize that while the present invention describes a rules/permissions pattern, there are many paradigms that can be used to grant permissions to applications for a particular device or platform, and these are within the scope of the present invention.
The wireless device then receives the application, permission list, developer identification and digital signature (step 705). In one embodiment, the wireless device may evaluate the received digital signature to determine the signer's identity. Digital signatures can also be used to determine if an application, permission list, or developer identification has changed since it was signed.
The wireless device then receives a request to run the application (step 710). This request may originate from a user of the wireless device wishing to run the program. Alternatively, the request may be generated by the wireless device itself or from several requests sent to the wireless device via a network connection or direct connection to the wireless device.
After receiving the request, the wireless device evaluates the digital signature and permission list associated with the application before execution (step 720). As noted, in one embodiment, the wireless device may use a rule to evaluate the grant list. If evaluating the digital signature determines that the application, permission list, or identification of the developer has not changed, the wireless device uses the stored rules to evaluate the permission list. If there is no change and evaluation of the rule against the permission list indicates that the application has granted permission to run on the wireless device, processing proceeds to run the application on the device (step 730).
If the evaluation in step 720 indicates that the application, permission list, or developer identification has changed since signing, or that the permission for the application to run on the wireless device is denied, then the application is not executed (step 725) . Processing proceeds to remove the application from the wireless device (step 750). It is also desirable that the permission list and developer identification be also removed from the wireless device.
After step 730, application execution is monitored to determine whether it is performing illegal or inappropriate actions (step 735). The wireless device or the platform on which the wireless device is used may define any behavior that is illegal or inappropriate. These operations may include accessing restricted areas of memory or locations in memory used by other programs or files. Additionally, these operations may involve detrimental use of the wireless device's resources so as not to affect the wireless device as well as other devices on the network to which the wireless device is attached.
If such illegal or inappropriate operation is attempted, execution of the application is halted (step 745) and is preferably removed from the wireless device along with the developer identification and permission list (step 750). As described above, alternatively, the uninstall process may include disabling the application to prevent its execution and maintaining the application on the wireless device.
If no illegal, inappropriate or undesirable action is performed in step 735, the application is permitted to continue running (step 740).
<b><u>conclusion</u></b>
Using mechanisms that incorporate authentication, change detection, source identification determination, grant assignment, and the ability to remove applications, systems and methods in accordance with the present invention increase secure application distribution and execution. The systems and methods may implement any or all of these mechanisms. The more mechanisms implemented, the higher the degree of stability achieved.
In one embodiment, the developer sends the application to the server. Developers can sign applications to protect against unauthorized changes. The server checks the identity of the developer and performs an authentication test for the application. The server also assigns permissions to applications while creating a list of permissions. The application, permission list, and developer identification are digitally signed by the server and sent to the wireless device along with the digital signature. The wireless device checks the digital signature against the list of changes and permissions against the stored rules before running the application. In one embodiment, these checks are performed prior to running the application on the wireless device. If the check indicates that the application has been altered or permission to run is denied, the application is not executed and is removed from the wireless device. Also, if, during execution, the application attempts illegal or improper operation, the application is terminated and removed from the wireless device.
The foregoing description of implementations of the present invention is for the purpose of explanation. It is not intended to be limited to the precise form disclosed. Changes and modifications are possible in light of the foregoing description and may be acquired from practice of the present invention. For example, although the implementation described above includes software, an embodiment of the present invention may be implemented in hardware alone or in combination of hardware and software. The present invention can be practiced with object-oriented and non-object-oriented programming systems. Also, while forms of the present invention have been described as being stored in a memory, those skilled in the art will recognize that these forms may be used in secondary storage devices such as hard disks, floppy disks, or CD-ROMs; carrier waves from the Internet or other radio media; or in other forms of computer readable media, such as other forms of RAM or ROM. The scope of the invention is defined by the claims and their equivalents.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR100751159B1 | Cited by | Republic of Korea | Search report |
43 members in 20 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 09872418 | United States of America | – | |
| 87241801 | United States of America | A | |
| 0216485 | United States of America | W |
Members43
| Document | Office | Kind | |
|---|---|---|---|
| CA2448979A1 | Canada | A1 | |
| US2002183056A1 | United States of America | A1 | |
| WO02097620A2 | World Intellectual Property Organization (WIPO) | A2 | |
| PE20030021A1 | Peru | A1 | |
| KR20040004361AThis record | Republic of Korea | A | |
| MXPA03010890A | Mexico | A | |
| WO02097620A3 | World Intellectual Property Organization (WIPO) | A3 | |
| IL159117A0 | Israel | A0 | |
| EP1438657A2 | European Patent Office (EPO) | A2 | |
| AR036043A1 | Argentina | A1 | |
| CN1537273A | China | A | |
| HK1069451A | Hong Kong, China | A | |
| HK1069451A1 | Hong Kong, China | A1 | |
| RU2003137835A | Russian Federation | A | |
| JP2005517220A | Japan | A | |
| BR0209741A | Brazil | A | |
| TWI252701B | Taiwan Province of China | B | |
| CN1258141C | China | C | |
| NZ529867A | New Zealand | A | |
| US7099663B2 | United States of America | B2 | |
| KR100634773B1 | Republic of Korea | B1 | |
| US2006287958A1 | United States of America | A1 | |
| RU2295753C2 | Russian Federation | C2 | |
| AU2002312041B2 | Australia | B2 | |
| JP2009054165A | Japan | A | |
| EP1438657B1 | European Patent Office (EPO) | B1 | |
| AT447739T | Austria | T | |
| ATE447739T1 | Austria | T1 | |
| DE60234267D1 | Germany | D1 | |
| ES2334336T3 | Spain | T3 | |
| EP2163986A2 | European Patent Office (EPO) | A2 | |
| US7684792B2 | United States of America | B2 | |
| JP4440983B2 | Japan | B2 | |
| US2010173608A1 | United States of America | A1 | |
| CA2448979C | Canada | C | |
| JP4795636B2 | Japan | B2 | |
| US8112076B2 | United States of America | B2 | |
| EP2163986A3 | European Patent Office (EPO) | A3 | |
| US2012137349A1 | United States of America | A1 | |
| US8588766B2 | United States of America | B2 | |
| BRPI0209741B1 | Brazil | B1 | |
| EP2163986B1 | European Patent Office (EPO) | B1 | |
| USRE48001E | United States of America | E |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Annual fee paymentFPAY | FPAY | |
| Written decision to grantGRNT | GRNT | |
| Decision to grant or registration of patent rightE701 | E701 | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 |
Numbers
- Publication
- 10-2004-0004361
- Application
- 107002109
Titles4
- Korean
- 무선 환경에서의 안전한 애플리케이션 분배 및 실행
- English
- Secure application distribution and execution in wireless environments
- Unlabeled
- 무선 환경에서의 안전한 애플리케이션 분배 및 실행 {SAFE APPLICATION DISTRIBUTION AND EXECUTION IN A WIRELESS ENVIRONMENT}
- Unlabeled
- SAFE APPLICATION DISTRIBUTION AND EXECUTION IN A WIRELESS ENVIRONMENT IN A WIRELESS ENVIRONMENT
Classification
- CPC, 12
- G06F21/51
- G06F8/54
- G06F8/61
- H04W12/10
- H04L63/0823
- H04W4/60
- H04W12/35
- Y10T29/49947
- A63B69/0093
- A63B71/04
- A63G31/007
- E04H4/0006
- IPC, 8
- G06F9 445
- G06F
- G06F1 00
- G06F5 00
- G06F21 00
- G06F21 22
- H04W4 60
- H04W12 10