Systems and methods for encrypted mobile voice communications.
Abstract
A method of establishing a registration between a mobile device and a server includes receiving at the server an SMS or MMS from a mobile device. The server receives the phone number of the mobile device, verifies the phone number of the mobile device against a whitelist to authorize a registration between the mobile device and the server, and verifies a secure identification code that is input at the mobile device. The secure identification code is provided to a user of the mobile phone before the mobile device is registered with the server. The secure identification code can be provided to the user via an administrator of the server. An encryption key established between the mobile device and the server can be used to provide or enhance encryption of a voice communication, such as a VoIP communication, made using the mobile device.

Term
6.4 yearsleft in the term
Expires 22 February 2033.
- Priority
- Filed
- Granted
- Today
- Expires
24 claims: 9 independent, 15 dependent
- 1CLAIMS REIVINDICACIONES 1. A method for establishing a registry for secure communication between a mobile device and a server, characterized in that said method comprises:1. Un método para establecer un registro para comunicación segura entre un dispositivo móvil y un servidor, caracterizado porque dicho método comprende: receiving on a server a short message service (SMS) or multimedia message service (MMS) messages originated from a mobile device;recibir en un servidor un servicio de mensajes cortos (SMS) o servicio de mensajes multimedia (MMS) mensajes originado a partir de un dispositivo móvil;con el servidor, determinar el número de teléfono del dispositivo móvil desde el cual se origina el mensaje SMS o el mensaje MMS;y, con el servidor, verificar el número de teléfono del dispositivo móvil que origina el mensaje SMS o el mensaje MMS contra una lista blanca para autorizar un registro entre el dispositivo móvil y el servidor. with the server, determining the telephone number of the mobile device from which the SMS message or the MMS message originates;and, with the server, verifying the telephone number of the mobile device originating the SMS message or the MMS message against a white list to authorize a registration between the mobile device and the server.
- 6The method of any of the preceding claims, further comprising the step of taking one or more affirmative steps to facilitate the routing of one or more messages between the mobile device and the server. 6. El método de cualquiera de las reivindicaciones precedentes, que comprende además la etapa de tomar una o más etapas afirmativas para facilitar el enrutamiento de uno o más mensajes entre el dispositivo móvil y el servidor.
- 8A method for establishing a registration between a server and a Voice over Internet Protocol (VoIP) application on a mobile device that has an associated telephone number, characterized in that said method comprises:8. Un método para establecer un registro entre un servidor y una aplicación de Voz sobre Protocolo de Internet (VoIP) en un dispositivo móvil que tiene un número de teléfono asociado, caracterizado porque dicho método comprende: On a mobile device, use a server encryption key to encrypt the registration information, where the registration information includes at least one of an encryption key for a VoIP application en un dispositivo móvil, utilizar una clave de encripción de servidor para encriptar la información de registro, en donde la información de registro incluye al menos uno de una clave de encripción para una aplicación VoIP 170 170 IMPI IMPI ΙΝΤΤΓΠΓΓΟ MEXICANO OE LA PROPERTY IHDUSTMAL and a security identification code known by the server and provided to the user of the mobile device;and, use a short message service (SMS) message or a multimedia message service (MMS) message to send the encrypted log information from the mobile device to the server, where the SMS message or MMS message originates from the device. mobile and thus provides the server with the telephone number associated with the mobile device for comparison with the telephone numbers known to the server;ΙΝΤΤΓΠΓΓΟ MEXICANO OE LA PROPIEDAD IHDUSTMAL y un codigo de identificación de seguridad conocido por el servidor y proporcionado al usuario del dispositivo móvil;y, utilizar un mensaje del servicio de mensajes cortos (SMS) o mensaje del servicio de mensajes multimedia (MMS) para enviar la información del registro encriptada desde el dispositivo móvil al servidor, en donde el mensaje SMS o mensaje MMS se origina en el dispositivo móvil y de este modo proporciona al servidor el número de teléfono asociado con el dispositivo móvil para la comparación con los números de teléfono conocidos por el servidor;en donde la información de registro encriptada puede desencriptarse en el servidor. wherein the encrypted log information can be decrypted on the server.
- 11El método de cualquiera de las reivindicaciones 8 a 10, que comprende además:eleven. The method of any of claims 8 to 10, further comprising: If at least one of the security identification code and the telephone number associated with the mobile device is verified, sending the mobile device an encryption key for communication between the server and the VoIP application on the mobile device. si al menos uno del código de identificación de seguridad y el número de teléfono asociado con el dispositivo móvil es verificado, enviar al dispositivo móvil una clave de encripción para la comunicación entre el servidor y la aplicación VoIP en el dispositivo móvil. - 171 - - 171 -
- 12A method for mobile voice communication 12. Un método para la comunicación de voz móvil IMPI IMPI INSTITUTO MEXICANO MEXICAN INSTITUTE DE LAnOHUA» . INDUSTRIAL segura a través de una red de teléfono móvil, caracterizado porque dicho método comprende:OF LAnOHUA ». INDUSTRIAL secure through a mobile phone network, characterized in that said method comprises: use a mobile device to send a Short Message Service (SMS) or Multimedia Message Service (MMS) message to a server, where the SMS message or MMS message originates from the mobile device and thus provides the phone number from the mobile device to the server so that it can be compared against a white list to authenticate the mobile device;utilizar un dispositivo móvil para enviar un mensaje del servicio de mensajes cortos (SMS) o mensaje del servicio de mensajes multimedia (MMS) a un servidor, en donde el mensaje SMS o el mensaje MMS se origina en el dispositivo móvil y de este modo proporciona el número de teléfono del dispositivo móvil al servidor de modo que puede ser comparado contra una lista blanca para autenticar el dispositivo móvil;and, establishing an encryption key for the purpose of communication between the voice communication application on the mobile device and the server. y, establecer una clave de encripción para el propósito de comunicación entre la aplicación de comunicación de voz en el dispositivo móvil y el servidor.
- 14A system for secure mobile voice communication characterized in that it comprises:14. Un sistema para la comunicación de voz móvil segura caracterizado porque comprende: a control module located in a mobile device, wherein the control module is configured to encrypt an SMS message or an MMS message through an encryption;and, a gateway comprising a server computer configured to communicate with the device un módulo de control ubicado en un dispositivo móvil, en donde el módulo de control se configura para encriptar un mensaje SMS o un mensaje MMS a través de una encripción;y, una puerta de acceso que comprende una computadora de servidor configurada para comunicarse con el dispositivo - 172 - 172 IMPI IMPI INSTITUTO MEXICANO M LA PROPERTY INDUSTRIAL mobile, where the access door is configured to receive the encrypted message from the mobile device and to determine a phone number of the mobile device from the SMS message or MMS message originated by the mobile device;INSTITUTO MEXICANO M LA PROPIEDAD INDUSTRIAL móvil, en donde la puerta de acceso se configura para recibir el mensaje encriptado desde el dispositivo móvil y para determinar un número de teléfono del dispositivo móvil desde el mensaje SMS o mensaje MMS originado por el dispositivo 5 móvil;en donde el módulo de control en el dispositivo móvil se configura para registrase con la puerta de acceso;wherein the control module in the mobile device is configured to register with the access door;en donde el registro con la puerta de acceso comprende al menos uno del número de teléfono del dispositivo 10 móvil que sea miembro de una lista blanca y configurar el módulo de control con un código de identificación único proporcionado a un usuario para introducirse en la puerta de acceso a través del dispositivo móvil;wherein the registration with the gateway comprises at least one of the phone number of the mobile device 10 that is a member of a whitelist and configuring the control module with a unique identification code provided to a user to enter the gateway. access through the mobile device;en donde la lista blanca comprende una lista de where the whitelist comprises a list of
- 1515 números de teléfonos de dispositivos móviles autorizados para registrarse con la puerta de acceso;y, en donde la puerta de acceso y el módulo de control intercambian una clave de encripción para la comunicación de voz entre la puerta de acceso y el dispositivo móvil. fifteen mobile device phone numbers authorized to register with the gateway;and, wherein the gateway and the control module exchange an encryption key for voice communication between the gateway and the mobile device. 20 15. El sistema de la reivindicación 14, en donde la encripción comprende al menos una de encripción simétrica y asimétrica. twenty 15. The system of claim 14, wherein the encryption comprises at least one of symmetric and asymmetric encryption.
- 18A method for establishing a record for secure communication between a server and an application on a mobile device, wherein the mobile device has an associated telephone number characterized in that said method comprises:18. Un método para establecer un registro para comunicación segura entre un servidor y una aplicación en un dispositivo móvil, en donde el dispositivo móvil tiene un número de teléfono asociado caracterizado porque dicho método comprende: con la aplicación, crear la información de registro que incluye al menos uno de una clave de encripción para la comunicación encriptada entre el servidor y la aplicación y un código de identificación de seguridad;with the application, creating the registration information that includes at least one of an encryption key for the encrypted communication between the server and the application and a security identification code;con el dispositivo móvil, enviar al servidor un primer mensaje del servicio de mensajes cortos (SMS) o el servicio de mensajes multimedia '(MMS) originado por el dispositivo móvil y de este modo revelar el número de teléfono al servidor;with the mobile device, sending to the server a first message from the short message service (SMS) or the multimedia message service '(MMS) originated by the mobile device and thus revealing the telephone number to the server;con el servidor, verificar el número de teléfono del dispositivo móvil que origina el mensaje SMS o el mensaje MMS contra una lista blanca para autorizar un registro entre with the server, check the phone number of the mobile device that originates the SMS message or MMS message against a white list to authorize a registration between IMPI IMPI INSTTTUTO MEXICANO DE LA PROPIEDAD INDUSTWAt MEXICAN INSTTTUTE OF INDUSTWAt PROPERTY - 174 el dispositivo móvil y el servidor;- 174 the mobile device and the server;if the registration is authorized, receiving a code sent by the server to the application on the mobile device through a second SMS message or MMS message;and without user intervention, extract the code from the SMS message or MMS message and send at least one of the registration information and the code from the mobile device to the server. si el registro es autorizado, recibir un código enviado por el servidor a la aplicación en el dispositivo móvil a través de un segundo mensaje SMS o mensaje MMS;y sin intervención del usuario, extraer el código del mensaje SMS o mensaje MMS y enviar al menos uno de la información de registro y el código desde el dispositivo móvil al servidor.
Independent claims9
792 paragraphs in 159 sections, as filed
(54) Title: SYSTEMS AND METHODS FOR MOBILE ENCRYPTED VOICE COMMUNICATIONS.
(54) Title: SYSTEMS AND METHODS FOR ENCRYPTED MOBILE VOICE COMMUNICATIONS.
(57) Summary
Systems and methods for handling (eg creating, transmitting, delivering, encrypting, storing and assimilating) secure SMS (short message service) and secure MMS (multimedia message transmission service) communications are described.
(57) Abstract
A method of establishing a registration between a mobile device and a server ineludes receiving at the server an SMS or MMS from a mobile device. The server receives the phone number of the mobile device, verifies the phone number of the mobile device against a whitelist to authorize a registration between the mobile device and the server, and verifies a secure identification code that is input at the mobile device. The secure identification code is provided to a user of the mobile phone before the mobile device is registered with the server. The secure identification code can be provided to the user via an administrator of the server. An encryption key established between the mobile device and the server can be used to provide or enhance encryption of a voice communication, such as a VolP communication, made using the mobile device.
Headlines)!
Home!
Denomination:
Classification!
Inventor (s)!
IMPI,, '- WM · * ·
II
PATENT TITLE No. 348109
CELLTRUST CORPORATION
20701 N. Scottsdale Road, Suite # 107-451, Scottsdale, Arizona, 85255-6499, USA
SYSTEMS AND METHODS FOR MOBILE ENCRYPTED VOICE COMMUNICATIONS.
CIP:
CPC:
H04W4 / 14>. ...
H04i-63/0428 (H04W4 / 14; H04IMV101; H04L63 / 0846; H04W12 / 06;
H04W88 / 16
SEAN MÓSHIR; KEVIN H. Λ * ΚΗΑΝΒΑΝ; JOSHUA LINDSAY • · * ', · «i · 1<sub>F</sub> Z
Number:
MX / a / 2014/010093
Countryf
PRIORITY '·<sup>:</sup>
USi US? 2 dafdbrtfNj de Jtjrtto de
Validity: Twenty years
Date of VMólftiienMt 22 dt February 2033
ExpqÑHjeion Date: 2 & de rrjéyodé 2 (^ 7 1
The patent referencedty | a with fundamerftemaJfMMMtiéulos 1 °, 2 · fraccifp V β *
<img file="MX348109B_D0001.tif" />
industrial and renewable, counted at
<img file="MX348109B_D0002.tif" />
Nú | í $ ero:
61/6(^,072
1-3 / m, 177
Pursuant to Article WA 'PrQpiediílinddsfn ^^^ sinnte paj_ from the date of submission of the application and on the date of submission of the application and' tor * 'Njdto al pagqÁla <^ rA fiSia ^ iantenel in force ".....<sub>x</sub><sup>Hee</sup> · V. j V 1,
Who subscribes this title loAOBltoAfijndBmento em | p diséuestotootkw articles 6 ° inóciones III y7Hts 2 «1e the Industrial Property Law (Official Gazette of the Federation (D'Oif)> ^ 7/06 / 1991.4efcrmdja el β2 / ίβΛ994, / πΛΛ 12/26 / | ΛΤ »7Λΐνΐ999, 01/26/2004, 06/16/2005, 01/25/2006, 05/06/2009, 01/06/2010, W¿« pXl, <06/08 »Í0, '2> f (M / J012 yO9W4αO ^ af & d! R1<sup>,,</sup>, 3ftrag ^ Wtfso a), 4<sup>or</sup> and 12<sup>or</sup> Sections I and III of the Regulations of the Mexican Institute of Local Property (DO rWiart ···; refonpetW A 01 / 8FÍ5w> TO07 / 2004, 07/28/2004 and 09/07/2007); Articles 1®, 3®, 4®, 5® fraction V subsection a), 1 «fraaCÜdHM i and of the tstMyto of Industrial Property (DOF
12/27/1999, amended on 10/10/2002, 07/29/2004, 'l «l9eoqb, Vj> WfWáaA ^ the Agreement that delegates powers to the Deputy General Directors, Coordinator, Divféíorw Directors | és ^ <itutares da <l stoppers, Divisional Assistant Directors, Coordinators
Departmental and other subordinates of the Mexican Institute of .OF 12/15/1999, reformed on 02/04/2000, 07/29/2004,
08/04/2004 and 09/13/2007). <sup>?</sup>
<img file="MX348109B_D0003.tif" />
This document is signed with an advanced electronic signature (FIEL), based on articles 7 BIS 2 of the Industrial Property Law; 3 of its Regulations, and 1 section III, 2 section V, 26 BIS and 26 TER of the Agreement establishing the guidelines for the use of the Payment and Electronic Services Portal (PASE) of the Mexican Institute of Industrial Property, in the procedures indicated.
DIVISIONAL PATENT DIRECTOR NAHANNY CANAL REYES
Ξ
<img file="MX348109B_D0004.tif" />
Ξ Original Chain:
: s NAHANNY MARISOL CANAL REYES | 00001000000403252793 | Administration Service
Tax | 1695 || MX / 2017/43168 | MX / a / 2014/010093 | PCT patent title | 1223 | GAGV | Page (s) 1 | vrfsMlcUaPe / 9sU YeeOpE7YDqEg =
Digital stamp:
jO6ZBjQslJAwPdiu1 + aA3511dSkJLQqNI4WrkvOC5B5IQ96FftV6b007MB04JldQTc / YVJBUG9bg6Ub5LD8fA7Ee4S
P on4MOx6WkDDyEg7kSZt0f767Mr0mjc20xqp7nliqxUvlSpFnlCEsdR8xtq0rQYvR0kvs3PsK5xiJ3 / mrsKLTwXg3t pKbzlyFQQX66Bsoprc8f2 / 6Nr19ierSBGb8P4BCi45yPCr6sBAaQougNwqdO4CCNm8jxtxKQX01470S7o5COP9RuHh 5BH3s / lkbDSNP7srUPctYycsxua4CERc / gtl5gH8xX6mtpbwc8mu0wjNLaa8mymdjNW7BhQ ==
Sand! No 550. Floor 1, Pueblo Santa María Tepepan, Xochimilco. 16020.
Mexico City.
(55) 53340700 w.vw gob mx / impi llllllllllllll
MX / 2017/43168 <sup>!</sup> --------------------<sup>1</sup>
IWHTUTO MEXICANO DE LAMOMWMD INDUSTRIAL <sup>M</sup>
SYSTEMS AND METHODS FOR MOBILE VOICE COMMUNICATIONS
ENCRYPTED
COMMUNICATIONS
RELATED APPLICATION AND PRIORITY CLAIM
This application claims the benefit of
US Provisional Application No. 61602072, filed February 22, 2012, entitled SYSTEMS AND METHODS FOR ENCRYPTED MOBILE VOICE COMMUNICATIONS which is incorporated herein by reference. This patent application is a Continuation Patent Application and claims priority for the US patent application series number 13531 177, filed on June 22, 2012, entitled AUTHENTICATION AND ALARM ACCESS METHODS REGARDING THE PROXIMITY OF ITS LOCATION, which is incorporated herein by reference.
BACKGROUND
The invention relates to systems and methods for handling mobile voice communications and information, including personal information. More particularly, the invention relates to systems and methods for transmitting, receiving, encrypting, storing and the like of encrypted mobile voice communications and personal information. The specific modalities and methods of the present invention relate to wireless communication, cellular telephony, internet-based systems and methods of software, computers or a
IMPI
<img file="MX348109B_D0005.tif" />
rwrmrro müucano
DC lAFWHUMD
INDUSTUM.
combination thereof to send, receive and store messages from the short message transmission service (SMS) and multimedia message transmission service (MMS) and mobile voice communications in an encrypted and secure manner.
Mobile voice communications are vulnerable to ensuring voice communications security breaches, unauthorized access for voice communications, and other problems. The incorporation of mobile devices (often using different networks and mobile phone operating systems) into the information technology (IT) infrastructure of a business or company has proven to be problematic with respect to both integration and security. For example, mobile devices can carry important information (and data) and a communication on the mobile device can create a lack of information (and data) security on the mobile device. Voice communication on a mobile device can be eavesdropped on by a third party on the mobile device and the mobile phone network (eg, mobile phone network hackers, employees, consultants or vendors of the mobile phone network operators or someone else or anyone else who has access to the communication between the mobile device and the mobile phone network, such as tower operators, infrastructure providers and
<img file="MX348109B_D0006.tif" />
IMPI mmruTOMUKANo ocla non HMD
INDUSTRIAL LAND LINKERS). As a result, there is a need for end-to-end mobile voice communications that are also encrypted. Additionally, the enforcement of proprietary and / or regulated information policy on mobile voice communications related to mobile phone networks has proven difficult. This is due to these types of communications between members of an organization and / or one or more members of an organization and its external customers towards a controlled IT environment (where a controlled IT environment is more secure). Standard mobile voice communications are not properly encrypted (or end-to-end), and are thus vulnerable to interception and other unauthorized access. Also, standard mobile voice communications have weak encryption, the encryption is compromised, or the encryption does not prevent service providers (such as mobile phone network operators and / or their vendors) from eavesdropping. mobile voice. Vulnerabilities associated with the security of the communication of private and regulated information between members of the organization and / or companies using their mobile devices can lead to lost revenue and / or fines associated with non-compliance with regulations.
Also mobile voice over IP communications that are encrypted are vulnerable when using SSL (Security Layer).
INSTITUTO MEXICANO JA
DE LA MOHEDAD V— «aZSLj & r INDUSTRIAL
Secure Socket) or TLS (Data Transport Layer Security Protocol) due to different issues. These problems include one or more man-in-the-middle (MITM) attacks, source certificate authority exploitation, the need to rely on a pre-shared key for encryption, and / or related spoof certificate concerns to get have a certificate of origin. A MITM attack on cryptography and computer security uses spies. An MITM attacker makes contact with users and communicates messages between users, causing users to believe that they are communicating directly with each other over a private connection. However, your communication or conversation is controlled by the MITM attacker. The need to rely on a pre-shared key (pre-defined and pre-shared) for encryption introduces challenges and failures for renewing a pre-shared key. Also, the encryption employed by various SSL interactions is not secure enough (eg, the encryption bit may be low for adequate encryption).
In addition, as the number of subscribers to mobile devices and mobile services has grown, the use (eg, transmission and reception) of mobile voice communications has increased greatly and the demand on performance and demand has increased. breadth of
<img file="MX348109B_D0007.tif" />
IMPI
INSTITUTO M1XJCANO DtLAIfcOmDAC INDUSTMAl.
band on the mobile phone network at a rate greater than capacity. As a result, optimal performance or bandwidth over the mobile phone network may not always be available for mobile voice communications.
The invention provides, among other things, a number of methods and modalities to address the issues of security vulnerabilities, integrating mobile devices that are not part of the IT infrastructure into the IT infrastructure of a business or company, performance optimization on the mobile phone network, and the management of mobile devices, IT integration, and policy administration.
Potential for improvement exists in these and other areas that may be apparent to a person skilled in the art who has studied this document.
SUMMARY
Systems and methods configured for handling (ie, creation, editing, viewing, compression, decompression, uninstallation, reinstallation, queuing, propagating, encrypting, decrypting, sending, receiving, responding, directing, storing and / or the like) communications (for example, short message transmission service (SMS) messages, multimedia message transmission service (MMS) messages, and other
INSTITUTO Mexicano DELA MONEDAD industrial transmission of information, and / or the like) in a secure manner (eg, in an encrypted or otherwise secured manner). In one embodiment, a short message transmission service (SMS) system comprises a software module configured for use in a device, such as a mobile device. The software module is configured to encrypt an SMS or MMS message using a first encryption. A networking device is configured to communicate with the mobile device. The networking device is configured to receive the encrypted SMS message from the mobile device.
In another embodiment, the user writes an SMS or MMS message on a mobile device and the message is encrypted therein. The user sends the encrypted message to a networking device or server. The networking device or server decrypts the encrypted message. The networking device determines the destination of the message (eg, another user or a third party). Depending on the destination of the message (and whether or not additional encryption is desired), the networking device may re-encrypt the decrypted message (often using a different encryption), and send the re-encrypted message to the destination (eg, another user or a third). The mobile device of
<img file="MX348109B_D0008.tif" />
IMPI
ΙΝΤΠΤυΤΟ MEXICANO DtLAFWniDAD INDUSTRIAL the receiving party receives the re-encrypted message and decrypts the message. The mobile device of the receiving party may send a delivery receipt, an open receipt, an error message or other desired messages to the networking device. These message status indicators may further be sent via the networking device to the initiator of the message.
In another embodiment, a method of securely delivering a message to a mobile device comprises dividing the message into at least two sub-messages. Sub messages are configured according to the protocol of a short message transmission service (SMS). The sub-messages are encrypted and transmitted to a mobile device according to an SMS protocol. On the mobile device, the at least two encrypted sub-messages are decrypted and combined to form the message.
In another embodiment, a method of securely delivering a message to a mobile device comprises encrypting the message and dividing the encrypted message into at least two sub-messages. The at least two sub-messages are transmitted to a mobile device according to at least one of an SMS protocol or an MMS protocol. On the mobile device, the at least two sub-messages are combined to form the encrypted message; and the encrypted message is
IMPI »-,
MEXICAN INSTITUTE
OF INDUSTRIAL HETHITY IF—<sup>r</sup> decrypts on mobile device.
In yet another embodiment, a method of erasing information on a mobile device comprises transmitting to a mobile device a secure message comprising an erasure instruction. On the mobile device, at least one item of information is deleted in response to the delete instruction.
The contents of this summary section are provided only as a simplified introduction to the description, and are not intended to be used to limit the scope of the appended claims.
The contents of this summary section are provided as a simplified introduction to the description only, and are not intended to be used to limit the scope of the appended claims.
In accordance with the purposes of the invention as widely incorporated and described herein, a method is provided for establishing a registration between a mobile device and a server. The method includes the steps of: receiving on a server a short message transmission service (SMS) or multimedia message transmission service (MMS) messages originating from a mobile device; and with the server, receive the phone number of the mobile device, verify the phone number of the mobile device against a white list to
<img file="MX348109B_D0009.tif" />
- 9 IMPI
MXXICANO INSTITUTE
DE LA MOntDAD INBUSTWAL authorize a registration between the mobile device and the server, and verify a security identification code that is entered in the mobile device. The security identification code is provided to the user of the mobile phone before the mobile device registers with the server. The security identification code can be provided to the user through a server administrator. The method may include establishing an encryption key between the mobile device and the server. The encryption key can be used to provide or enhance the encryption of a mobile communication made using the mobile device. Voice communication can be a Voice over Internet Protocol (VoIP) communication. The encryption key can be renewed based on one or more policies determined by a server administrator. The method may include taking one or more affirmative steps to facilitate the execution of one or more messages between the mobile device and the server.
In accordance with another aspect of the invention, the method may further include measuring the network conditions of a mobile telephone network used by the mobile device; and based on the conditions of the measured network, select a suitable code decoder to handle at least one of the security calls, conference,
<img file="MX348109B_D0010.tif" />
IMPI
INSTITUTO MEXICANO OC LA MOHIDAD INDUSTRIAL video, audio, multimedia and transmit a data stream over the mobile phone network.
Also according to the invention, a method is provided for establishing a registration between a server and a Voice through the application of Internet Protocol (VoIP) on a mobile device that has an associated telephone number. The method includes: on a mobile device, using a unique server key for the encryption registration information, where the registration information includes at least one public key for a VoIP application and a security identification code known to the server and provided to the user of the mobile device; and using a short message transmission service (SMS) message or a multimedia message transmission service (MMS) message to send the encrypted registration information from the mobile device to the server. The SMS or MMS message provides the server with the phone number associated with the mobile device to compare with the phone numbers known to the server. The encrypted registration information can be decrypted at the server using a server's private key and the security identification code, and the mobile phone number associated with the mobile device can be verified by the server. The security identification code can be provided to the user
<img file="MX348109B_D0011.tif" />
IMPI ΙΜΓΠΤυΤΟ MBXICANC Di LA FHOrtlDAT INDUSTRIAL of the mobile device through a server administrator. At least one of the encrypted registration information and the decrypted registration information can be processed using symmetric encryption.
According to another aspect of the invention, the method can also include, if they have verified the security identification code and the telephone number associated with the mobile device, carrying out the steps of: using the public key for the VoIP application to encrypt and send to the mobile device an encryption key for communication from the server to the mobile device; on the mobile device, use a private key for the VoIP application to decrypt the communication encryption key; and using the communication encryption key to provide or enhance security voice communication for the VoIP application.
Also according to the invention, a method is provided for securing mobile voice communication over a mobile phone network. The method may include: using a mobile device to send a short message transmission service (SMS) message or a multimedia message transmission service (MMS) message to a server, where the mobile device's phone number can be compared against a white list to authenticate the mobile device; use the device
<img file="MX348109B_D0012.tif" />
IMPI tmiriuiuMuucANo DELAnOmOAD INDUSTRIAL mobile to send to the server a security identification code associated with the user, where the security identification code is used in the server to authenticate the user; establishing an encryption key for the purpose of communication between the voice communication application on the mobile device and the server; and using the communication encryption key to provide or enhance the communication security of a voice communication application running on the mobile device. The voice communication application may comprise a VoIP application.
In some embodiments, the system may include a network manager to measure one or more network conditions on the mobile phone network. The network manager can be configured to select a code decoder based on one or more conditions of the measured network and the code decoder is suitable to handle at least one of the security calls, conference, video, audio, multimedia and transmit a data stream over the mobile phone network.
In accordance with another aspect of the invention, a method is provided for establishing a registration between a server and an application on a mobile device, wherein the mobile device has an associated telephone number. The method includes: with the application, create
<img file="MX348109B_D0013.tif" />
registration information that includes at least one of a public key for the application, an associated telephone number, and a security identification code; with the mobile device, send the registration information to the server; receiving a code sent by the server to the application on the mobile device through a message from the short message transmission service (SMS) or a message from the multimedia message transmission service (MMS); and without user intervention, extract the code from the SMS or MMS message and send the code from the mobile device to the server. The registration information can be an encryption key to encrypt the registration information; where the server can decrypt the registration information using a server's private key.
BRIEF DESCRIPTION OF THE DRAWINGS
The accompanying drawings, which are incorporated in and constitute part of the specification, illustrate the presently preferred embodiments and method of the invention and, together with the general description given above and the detailed description of the preferred embodiments and methods given below, serve to explain the principles of the invention. The drawings illustrate, among other things, various particular examples of the modalities, and certain examples of the characteristics thereof. Different modalities
IMPI ΙΝΠΓΠΠΤ> MEXICANO Dt LA MOHIDAD INDUSTRIAL
<img file="MX348109B_D0014.tif" />
of elements or acts in the present, known them.
- 14 include various combinations shown in the drawings, described in the art, or a combination of
Figure 1 is a block diagram illustrating, among other things, an example of an environment in which the various modes can operate to handle mobile voice communications in an encrypted and secure manner in accordance with the invention;
Figure 2 is a block diagram illustrating an example of systems for the management and dissemination of information and / or messages for a number of users, which system can be used with the present invention;
Figure 3 illustrates the communications between mobile users and / or third parties by means of a network interconnection device 115 in order to create, send, receive and / or store messages from a short message transmission service (SMS) and messages from a multimedia message transmission service (MMS) securely, and handle personal information for a number of users;
Figure 4 illustrates the installation and registration of a software module on a mobile device;
Figure 4A is a flow chart illustrating an example of a method for providing position sensitization using mobile phones; and
Figure 5 further illustrates communication between mobile users and / or third parties via a networking device 115;
Figure 6 is a flow chart illustrating a method for transmitting a message securely, such as an SMS message or an MMS message;
Figure 7 is a flow chart illustrating an example of a method for erasing a mobile device;
Figure 8 is a flow chart illustrating another method of transmitting a message securely;
Figure 9 is a flow chart illustrating an example of a method, for managing information for at least a plurality of users using the Internet and users' mobile phones;
Figure 10 is a flow chart illustrating an example of a method, authenticating transactions, and methods for authenticating access, in many embodiments, using mobile phones;
Figure 11 is a block diagram illustrating a particular example of a system for the management and dissemination of information for a number of users;
Figure 12 is a block diagram illustrating an environment where server 15 manages and disseminates information to users 21, 22 and 23;
Figure 13 illustrates a flow chart illustrating examples of various methods for using the server
<img file="MX348109B_D0015.tif" />
- 16 IMPI
INSTITUTO MUUCANO M LA ΜΟΗΗΜΠ INtlUSTIUM.
to communicate with one or more of users 21, 22, and 23 to provide information to users 21, 22, and 23.
Figure 14 is a flow chart illustrating an example of a process for code decoder switching in accordance with one aspect of the invention;
Figure 15 is an example of a three-dimensional visualization showing the relationship between bandwidth, latency, and quality (ie, percentage of packets dropped) of a mobile phone network, which can be used for switching between the code decoders in accordance with one aspect of the invention;
Figure 16 is a block diagram illustrating an example of a system for handling and disseminating information and / or messages to handle mobile voice communications in an encrypted and secure manner in accordance with the present invention;
Figure 16A is a block diagram illustrating an example server-side / client-side information flow for one embodiment of a system for handling mobile voice communications in an encrypted and secure manner in accordance with the present invention. ;
Figure 17 is a diagram showing examples of client software process operations for client-to-client communication to organize metadata about calls; and
<img file="MX348109B_D0016.tif" />
- 17 IMPI
MUICANO INSTITUTE
OF INDUSTRIAL PROPERTY
Figure 18 is a flowchart showing an example of the method for handling mobile voice communications in an encrypted and secure manner in accordance with the present invention.
DETAILED DESCRIPTION
The present description provides, among other things, a number of system modalities and methods for handling messages from a short message transmission service (SMS) and messages from a multimedia message transmission service (MMS) in a secure manner. , and to transmit, receive, encrypt, store, and the like, mobile voice communications and personal information. Although the various embodiments are described in sufficient detail to enable those skilled in the art to practice the invention, it should be understood that other embodiments can be made and that various changes can be made without departing from the spirit and scope of the invention. Therefore, the detailed description herein is presented for purposes of illustration only and not as a limitation. For example, the steps cited in any of the method or process descriptions can be performed in any order and are not limited to the order presented.
Also, for brevity, certain sub-components of the individual operating components, the network (creation
<img file="MX348109B_D0017.tif" />
IMPI ιιβτπυτο miuucano ιχ the INDUSTRIAL montBAP of networks ??) conventional data, application development and other functional aspects of systems may not be described in detail here. Furthermore, the connecting lines shown in the various figures contained herein are intended to represent exemplary functional relationships and / or physical and / or electronic couplings between the various elements. It should be noted that many alternative physical connections or a practical system may be present in either functional or additional relationships.
The particular modalities include methods for authorizing actions using mobile phones. The modalities may include actions such as receiving from a person who has authority to authorize the action, an identification of a telephone number to obtain authorization for the action, and receiving from a person requesting the action, a request for authorization of the action . Certain modalities also include actions such as sending a first message through a mobile phone network to the mobile phone, including a description of the action for which authorization is requested, and receiving, from the first mobile phone, a second message. that authorizes the action. The actions that are authorized, in different modalities, include, as examples, access to a computer, physical access and financial transactions. In ΐΝπηυτο mixkuno
DELA ntOPltDAD O'-Q.rfíjScr INDUSTRIAL various modalities, as examples, the telephone number can be received through the mobile telephone network, through the Internet, through a local signal, or directly from the user.
In some embodiments, the user may be able to enter information on a website or may authorize others to enter information on the website, which can be automatically transmitted to the phone for storage. In addition, in some modes, users may be able to enter information through their phone for transfer to the website server. In various ways, third parties, such as airlines, financial institutions such as banks, and the like, can provide information to the website, some or all of which can be transferred to the phone. Furthermore, in some embodiments, some of such information may provide an alert or alarm to the user, for example, about important information such as notification of large deposits or withdrawals, changes in flight information, location of children. In various modes, the user may be able to view other information on the phone, on the website, or both, such as, for example, bank account balances, transaction histories, frequent flyer miles, credit card bills. credit, automatic deposits and withdrawals, insurance information,
<img file="MX348109B_D0018.tif" />
IMPI Mexican institute M LA MtOPISDAD INTAISTMAL guarantees, service contracts and the like.
EXAMPLE OF THE ENVIRONMENT AND SYSTEM
Figures 1 to 8 illustrate an example of an environment in which various modalities may operate and also illustrate several examples of systems, including systems for handling SMS messages in a secure manner. Various embodiments described herein are illustrated for use with a short message transmission service (SMS) protocol. However, other protocols may be suitably used, for example, a multimedia message transmission service (MMS) protocol, an Unstructured Supplementary Services Data (USSD) protocol, or another message transmission protocol and / or the like. . Furthermore, various embodiments described herein are suitable for use when using a message transmission protocol for at least a portion of the communication. System 100 is, among other things, an example of a network-based system configured to handle information that is transferred to, transferred from, and / or stored on a mobile device, which is accomplished in many ways while maintaining a acceptable level of data security. In the example of system 100, users 21, 22 and 23 own, use, control or have access to mobile phones 41, 42 and 43 respectively, which have service through a
<img file="MX348109B_D0019.tif" />
IMPI INnTTUTOMSXKUNO M LA r * INDtimUAL OFFICE network, for example a mobile phone network 40. Although a mobile phone network 40 is shown, some modalities may include or use a number of mobile phone networks 40, which, for example, can be interconnected. As used herein, unless defined otherwise, a mobile phone network can be a cellular network, a satellite network, a WiFi network, a WiMAX network, a wireless network, or any other network suitable for transmission. of information to mobile phones and / or other mobile devices. Furthermore, a mobile device can be connected to a network in any suitable way, for example, via a GSM modem, a CDMA modem, and the like. Additionally, a mobile device can connect to multiple networks simultaneously, for example, to a GSM network of a first carrier via a GSM modem and to a CDMA network of a second carrier via a CDMA modem. Furthermore, the three users 21-23 and the mobile phones 41-43 shown can serve as examples of a large number of users and mobile phones. Many users of System 100 can access the Internet 10. For example, in various embodiments, the user 23 has access to the Internet 10 through a personal computer 13. Furthermore, in a certain embodiment, the mobile phone network 40 is in communication with the Internet 10, or the information is capable to communicate (eg, in one or both directions) between the <sup>22</sup>
ΙΝΤΠΤυΤϋ MEXICAN
Say LA rwniDAO ™ JW
INDUSTRIAL mobile phone network 40 and the Internet 10. In various embodiments, the mobile phone network 40 may be connected to one or more additional mobile phone networks 40 or to other networks in any suitable way, for example, via the Internet. 10, over a public switched telephone network (PSTN) and / or the like.
In addition, system 100 can be a public system (eg, a system in which any number of users can use system resources) or a private / closed system (eg, a limited access system with such a circle of trust). so that the user must be authorized to use the particular resources of the system and / or to send and receive communications with other members of the circle of trust). In various embodiments, the system 100 may be configured to allow communication only between users (eg, users 21, 22, and 23) who are members of a particular trusted group. Thus, system 100 may be particularly suitable for businesses, military, law enforcement, governments, and the like, who wish to exchange highly sensitive and confidential information through system 100. For example, system 100 can be configured to allow communication only between members of a predefined trusted group, such as FBI agents, ATF agents, military personnel, and the like.
<img file="MX348109B_D0020.tif" />
Server 15 is in communication with the
IMPI msTmrro Muicano Oí LA rtOF! * DAD INDUSTRIAL
Internet 10. However, server 15 may be in communication with a wireless carrier, private network, mobile phone, other server, and / or the like, through a wireless network or other means so that server 15 does not needs to be in communication with the Internet 10.
In various embodiments, server 15 is part of system 100, and server 15 is configured as a reliable networking device configured for handling encrypted messages. Server 15 may provide any desired functionality to system 100, for example, managing client software installed on one or more mobile devices, updating client software installed on one or more mobile devices, issuing commands to client software. client, tracking of messages sent and received by client software and the like. Server 15 can also handle encryption keys for client software, generate new encryption keys, communicate with a hardware security module (for example, a module located on another server 15 coupled to the present server 15), and provide flexibility to increase the reliability of message delivery. The system 100 further comprises, in the server 15 (at least one) a first software module 61.
The system 100 further comprises, in the server 15,
<img file="MX348109B_D0021.tif" />
IMPI
INSTITUTO MEXICANO Ot LA FHOHEDAD INDUSTRIAL (at least one) a first software module 61. Although it is shown only on server 15, in some embodiments, module 61 can be installed or operated on more than one server. For example, the server 15 may include multiple servers, such as one or more than a firewall server, a database server, an SMS networking device server, a network server, a server domain or any other server. In certain embodiments, the software module 61 can form at least one website 65. In certain modalities, multiple users (eg, 21 to 23) can access or visit the website 65 (for example, through the Internet 10) and choose to send, receive, direct, respond, view, classify and generate reports , including acceptance reports, through system 100 using your mobile devices or other communication devices. Furthermore, one or more users may access or visit the website 65 through any suitable protocol, eg, WAP, https, and the like.
In some embodiments, the first software module 61 provides for example secure storage 64 for each personal user information (eg, 21 to 23) received from the user. In a number of embodiments, storage 64 can also be used to store personal information about users who have signed in.
<img file="MX348109B_D0022.tif" />
IMPI INSTITUTO MEXICANO DE LA PROPIEDAD INDUSTRIAL received by module 61 or server 15 from at least one third party, which can act on behalf of the user, for example to provide information to the user. In the illustrated embodiment, the third party 33 may provide such information to the module 61 via the Internet 10, and the third 31 may provide such information to the module 61 via the mobile phone network 40 may also communicate or instead of, via for example a traditional telephone network, which provides direct wireless telephone service for a number of users.
In many embodiments, the first software module 61 or module 201 (described below) provides secure storage 64 for each user's personal information (eg, 21 to 23), for example, information received from the user, content of SMS messages sent and received and the like. In a number of embodiments, storage 64 can also be used to store personal information about users that have been received by module 61, module 501, or server 15, from at least one third party, who can act on their behalf. of the user to provide the information to the user. In certain embodiments, third party 33 may provide such information to module 61 or module 201 via Internet 10, and third 31 may provide such information to module 61 or module 201 via mobile phone network 40 and the
<img file="MX348109B_D0023.tif" />
IMPI
ΙΝΪΓΠυΤΟ MEXICANO DCLAPROniIMD INDUSTRIA!
Internet 10. In some modalities, the information that is communicated through the mobile telephone network 40 may also be communicated, or instead of, through a traditional telephone network, for example, providing a direct wireline telephone service for a number of users. Additionally, third parties 31, 32, and 33, may choose to deploy the networking device 115 in their respective data center behind their security barrier. This provides each third party with another 10 layer of security. Each third party can handle all access to the server 15 in accordance with its internal security policy. All communications between the networking device 115 and the mobile phone network 40 (eg, the carriers) can be direct.
Module 201 may be self-updating (eg, when a new software update is available, networking device 115 may send a message to module 201 informing module 201 of the available update). The user's phone (or third party) is informed of the update (eg, by means of an SMS or MMS message (eg, formatted with a command)) and permission is requested to update module 201. For example, the message (eg, formatted with a command) asks the user if the user would like to receive the update. If the user agrees to receive the
<img file="MX348109B_D0024.tif" />
IMPI
ΓΝΪΤΠΤΓΓ · MEXICAN
DELAMIOHiüAD INDU5TMAL update, then the module 201 terminates itself, starts a browser to access the server 15 or the networking device 115 and downloads the latest version of the module 201 from the server 15 or the networking device 115. Thus, Once permission to update module 201 is provided, the new version of module 201 is downloaded to the user's (or third party) phone and installed on top of the old version of module 201. A message can be sent to the networking device 115 confirming the installation of the module
201. In addition, module 201 can be configured to communicate with and / or use multiple networking devices.
In various embodiments, adapted versions of module 201 may be provided in order to make module 201 operational and / or available for use on variable hardware, for example, various mobile phones and / or computer platforms (eg, Google Android, Java 2 Mobile Edition, Windows Mobile, Linux, Microsoft Windows, Mac OS, Unix and the like). Furthermore, access to module 201 can be controlled by password, biometrics, and the like. Additionally, module 201 can contain and / or be associated with information configured to identify a third party (eg, a reseller, a referrer, a corporation and the like), in order to provide services.
<img file="MX348109B_D0025.tif" />
IMPI
INSTITUTO MEXICANO Of LA FROflEDAD INDUSTRIAL and / or adapted tracing.
For example, a reseller may receive a commission based on the number of secure SMS messages transmitted by the 201 module (s) associated with the reseller.
REGISTRATION WITH THE INTERCONNECTION DEVICE OF
NETWORKS / SERVER
In addition, module 201 can be configured to use the register with a networking device, for example, networking device 115. In various embodiments, the registration may comprise a user taking affirmative steps, for example, entering a secure identification provided by an administrator of the networking device; enter a short code, a long code, or a telephone number (for example, a number associated with a cellular modem) to facilitate the propagation of one or more messages. Furthermore, the registry may comprise the exchange of encryption keys between a mobile device and a networking device. For example, a public server key can be used to securely send the encryption key from module 201 to a mobile device.
In certain embodiments, the module 201 registers with a networking device 115 in order to facilitate communications between the module 201 and the networking device 115. For example,
<img file="MX348109B_D0026.tif" />
the public bypass can be achieved
IMPI πκτπυτο MEXICAN
DI LA MKW1IDAD INDUSTRIAL registration through the use of a server key, a unique public key from module 201, a short code, and a unique secure identification code. In this way, a module 201 can know how to contact the networking device 115 in order to register. Module 201 encrypts the unique secure identification code and the newly generated module 201 public key with the server's bypass public key and sends the result in an SMS message to the short code. The networking device 115 decrypts the SMS message using a bypass private key from the server. The networking device 115 verifies the unique secure identification code and telephone number associated with the module 201. If the result is not verified, it returns an error message to module 201. If the result is verified, the networking device 115 transmits a new public key from the server to module 201.
The networking device 115 then creates a unique AES key and sends this key, along with the registration information, to module 201 via a registration message encrypted with the public key of module 201. Module 201 decrypts the message using the private key of module 201. Module 201 then transmits an acknowledgment message of receipt of the
INSTITUTE mwcano .Λ
Df LA PROFUIMD INDUÍTWlAL M register, encrypted with a unique AES key associated with module 201, to the network interconnection device 115. Upon receipt of the registration acknowledgment message in the network interconnection device 115, the module 201 is registers with networking device 115.
In some embodiments as illustrated in Figures 1 through 18, system 100 can handle mobile voice communications in an encrypted and secure manner. Some of the problems and vulnerabilities of mobile voice communications have been described. A 1673 network manager can be configured as part of a fourth software module 1672 in Figure 16, module 201 in Figure 2, or second software module 72 or 77 (or separate from modules 1672, 72 and / or 77). The network manager 1673 acts as a module to measure network conditions on both sides (sender / receiver) of a call through the mobile phone network 40. Network conditions can include latency, throughput, and amplitude of mobile phone network band 40. The data collected in this manner by the network manager 1673 is used to make informational decisions about selecting a suitable code decoder to handle calls over the mobile phone network 40. In some embodiments, the fourth software module 1672 can be configured as one or more than one secure module 201
WICKED
INJIIIUIO MUUCANO
OF THE PROPERTY
INDUSTRIAL> * Α_ϊί_Τ * ^ message transmission, a second software module 72, a secure voice module, a secure audio module, a secure video module, a secure video broadcast module, a secure video conferencing module and a secure multimedia module.
Figure 14 is a flow chart illustrating an example of a process for switching a code decoder with one aspect of the invention, where the CALLER can be a mobile phone 41, THE CALLER can be a mobile phone 43 (in Figures 1 and 16), and the headphones can be mobile phones 41 and / or 43 (in Figures 1 and 16). Figure 15 illustrates an example of a three-dimensional visualization of mobile phone network 40 showing the relationship between bandwidth, latency, and quality (ie, percentage of dropped packets) of a mobile phone network, which can used in some embodiments for switching between code decoders. Figure 17 is a flow chart showing examples of client software process operations for client-to-client communication between mobile devices 41, 43 to exchange local network measurements or other attributes of mobile devices. such as GPS and the like.
In Figure 15, each combination of these parameters is associated with a vector in a representation
<img file="MX348109B_D0027.tif" />
IMPI
INSTITUTO MEXICANO DCLAMOHIDAD INDUSTRIAL 3D cylindrical. These vectors are generated during a call on the mobile phone network 40, often at fixed / variable intervals. Depending on the quality of the call, each vector will fall into or out of a 3D volume with fuzzy boundaries. Over time, the 3D volume becomes a display of good audio quality versus poor audio quality over the call. Each code decoder has its own 3D volume so the fourth software module 1672 or the second software module 72 (in Figures 1 and 16) can decide to switch between the code decoders depending on how often the codes drop / go out. vectors of a specific code decoder. Figure 15 shows one of the possible representations of the aforementioned display. The network manager 1673 can periodically operate network measurements with its counterparts so that disruptions in the state of the mobile phone network 40 can be accommodated quickly and with assurance. The conical region defined within the cylinder shows where a call can exist. The dimensions of the region depend on the code decoder and transport in use. The network manager 1673 can find and use the code decoder that best matches the vector within the usable region.
Referring now to Figures 16 and 16A, a
<img file="MX348109B_D0028.tif" />
IMPI
INSTITUTO MEXICANO M LA MOHIDAD INDUSTRIAL system 100 to handle mobile voice communications, in an encrypted and secure way, includes the second software module 72, the software module 201, the fourth software module 1672, the manager 1673 and SIP module 1680. The database in Figure 16A may be in storage 64 (see Figure 1). PBX 1690 is (Private Branch Exchange) Private Business Telephone Switchboard, which is a PSTN telephone network (usually used within a private company). The
Internet 10 and mobile phone network 40 can be combined as Internet and / or mobile phone network 40 (see Figure 1).
The fourth software module 1672 may be a part of the secure message transmission module 201 or the second software module 72 in Figure 1 or be separate from the module 201 or the second software module 72. The server 15, the networking device 15, or the server administrator / networking device 15 can send or communicate a secure identification code or Secure ID to the user through the room 20 software module 1672, module 201 , or second software module 72 (see step 1601 of Figure 18). The secure identification code can be communicated through SMS, MMS, and / or data, or through a communication channel other than SMS, MMS and / or data.
The fourth 1672 software module (configured as
<img file="MX348109B_D0029.tif" />
IMPI
ΙΝίΤΠΤΓΓΟ MUUCAN ·
DE LA MOHEDAL INDLirrUIAL an application on mobile phone 43), module 201 (configured as an application on mobile phone 43), or second software module 72 (configured as an application on mobile phone 43) can send a request to the server 15 indicating an interest or a request to register with server 15 (step 1603). In some embodiments, the request may or may not be encrypted. In some embodiments, the request encryption may or may not use a unique encryption key. In some embodiments, the request encryption may or may not use a pre-established key, which may be a symmetric key or an asymmetric key. Server 15 sends a certification signed by a trusted authority to the fourth software module 1672, module 201, or second software module 72 (step 1605). In some modalities, the certification can be encrypted using the unique encryption key. In some modalities, the encryption of the certification can use a pre-established key, which can be a symmetric key or an asymmetric key.
The fourth software module 1672, module 201, or second software module 72 verifies that the certification of the server 15 is genuine, using a CA (Certificate Authority) of public origin (step 1607). If the certification is not genuine, then the registration process is aborted and in some modalities the incident is reported,
<img file="MX348109B_D0030.tif" />
- 35 IMPI
ΙΝΠΤΠΓΓΟ MEXICAN
Ot THE IMPUTRUAL CURRENCY registers, or alerts the server user 15. If the certification of the server 15 is genuine, then the fourth software module 1672, module 201, or second software module 72 sends its own certification (eg, the certification from the application on the mobile phone 41) to the server 15 (step 1609). The certification from the fourth software module 1672, module 201, or second software module 72 can be encrypted with the certification from server 15 before the certification of the fourth software module 1672, module 201, or second software module 72 is sent to server 15. In some embodiments, the fourth software module 1672, module 201, or second software module 72 may also send the secure identification code or Secure ID from the server 15 (if available) in an encrypted manner with the certification from the host. server 15 to server 15.
In some embodiments, the fourth software module 1672, module 201, or second software module 72 may also send additional information such as one or more of the information from the mobile device (eg, from the mobile phone 41), a version of the application, an encryption version, a list of installed applications and a version of the Operating System in an encrypted manner using the certification from server 15 to server 15.
Server 15 sends a registration confirmation including
IMPI a key to the fourth software module 1672, module 201, or second software module 72 (confirmation can be encrypted with the certification from the fourth software module 1672, module 201, or second software module
72) (step 1611).
ΙΝΓΓΓΤνΤΟ MEXICAN DE LA PROPBDAC INDUSTRIAL
In some embodiments, the server 15 may also send the policies to instruct the fourth software module 1672, module 201, or second software module 72 to change its configuration (which can also be in an encrypted manner using the fourth software module certification). 1672 software, module 201, or second software module 72). In some embodiments, the fourth software module 1672, module 201, or second software module 72 confirms that the confirmation from the server 15 is received and processed correctly. In some embodiments, the confirmation may be encrypted with the key received from the server 15 (step 1613). In some embodiments of Figure 14 through 16, all or some of the steps are sent via SMS. In other embodiments of Figure 14 through 16, some or all of the steps are through a data channel of the mobile telephone network 40. In other embodiments of Figure 14 through 16, all or some of the steps are sent via SMS / MMS.
ENCRYPTION
A number of modalities of the system and methods
IMPI (NSTITUTU MEXICANO DE LA M0M1DAD INDUSTRIAL of the present invention use encryption to address the problems associated with existing encryption models and processing limitations in mobile voice communications over a mobile telephone network. Although some standard features of the mobile device, such as the calendar, allow information to be shared between the voice calls and the SMS editor on the mobile phone 41, the challenges induced by the differences have resulted in the retention of the secure module 201 of SMS and the secure voice module (fourth software module 1672, module 201, or second software module 72) as separate applications on the mobile device. For example, differences between data channel and control channel encryption techniques have resulted in retaining the secure SMS module 202 and the secure voice module (fourth software module 1672, module 201, or second module software 72) as separate applications on the mobile device. One of the important characteristics of the traffic channel is to support the Internet Protocol (IP) that is not available or feasible in the control channel. Therefore, in this invention when the characteristics of the traffic channel are discussed, any channel capable of supporting IP can be assumed. Some channels can be any part of the mobile phone network or the
Internet.
<img file="MX348109B_D0031.tif" />
Some modalities and methods of the invention
IMPI
MUUCANO INSTITUTE
INDUSTRIAL PftDMKDAD establish secure voice communication based on a unique encryption key that is established between a first software module of the server and a fourth software module 1672, module 201, or second software module 72 of the mobile device. The secure SMS registration process to establish such a unique encryption key uses SMS / MMS data, or a combination thereof may include using one or more or any combination of AES (Advanced Encryption Standard). ), Blowfish encryption, ECC (Elliptical Curve Cryptography), RSA encryption, or any other suitable encryption. Furthermore, the invention uses a dynamic code decoder switch to accommodate changes in the mobile phone network for a variety of parameters such as latency, drop rate, and bandwidth in the mobile phone network. Furthermore, the invention allows a switching on the call of the code decoders (exchange of hot code decoders) and uses a network manager. The network manager can be configured as a part of the fourth software module 1672, module 201, or second software module 72 (or separate from them) and acts as a module to measure network conditions or both sides (transmit / receive ) of a call over the mobile phone network. The network manager
<img file="MX348109B_D0032.tif" />
IMPI ηβτπττο Mexican di la noni DAD
INDUSTRY!
it can also switch communications from a mobile phone network to the Internet, a WiFi network, or a local network (and vice-versa). Network conditions can include latency, throughput, and bandwidth of the mobile phone network. The data collected in this way by the network manager is used to make informational decisions about selecting a more suitable code decoder to handle calls over the mobile telephone network.
Mobile communication takes place through the traffic and control channels of a mobile phone network 40. While the traffic channel is basically used to carry signals such as voice, data and multimedia calls, the control channel is used for SMS (short message transmission service) among other operation signals. Other operation signals can include synchronization signals, search signals, and access signals. One of the common protocols for the transmission of voice communication over the Internet Protocol (IP) is Voice over IP (VoIP). VoIP is commonly used for end-to-end encryption of voice communication. VoIP takes place over the traffic channel as it uses data signals for transmission. Similar to voice calls a main assumption for VoIP communication is that both sides of
<img file="MX348109B_D0033.tif" />
IMPI
MEXICAN INSTITUTE
Dt LA MOHEDAL industrial communication are online in real time and are simultaneously available for communication.
In contrast to voice and VoIP calls, SMS is a store-and-forward technique, which does not require an end-to-end connection to be available simultaneously. Furthermore, SMS is optimized for the transmission of short messages (as compared to longer messages used for voice, multimedia, or other). Traditionally, when VoIP communication is secured, the encryption techniques used to encrypt VoIP depend on the characteristics of the data channel and therefore vary from the techniques used for SMS encryption (which are based on the characteristics of the control channel).
The embodiments and methods of the present invention can take advantage of some of the characteristics of the control channel to improve the encryption of VoIP communication. In addition, they can take advantage of combining a secure SMS module 201 with a secure 1672 voice module, secure audio module, secure video module, secure video transmission module, secure video conference module, and secure multimedia module. As well as a secure IP (Internet Protocol) SMS that sends SMS through the traffic channel, IPSMS is a way to emulate SMS but not all SMS features on a control channel will be available in IPSMS.
<img file="MX348109B_D0034.tif" />
A number of modalities and methods use the
IMPI
ΙΝΤΠΤνΤΟ MEXICANO DE LA PROPERTY INDUSTRIAL encryption to address the issues associated with the vulnerability of using SSL / TLS in mobile voice communications. They can use a control channel of a network
5, mobile telephony (eg, to transmit / receive SMS / MMS messages) when possible, and can carry out a security greeting such as when using a secure SMS module 201 or API. The control channel of a mobile phone network can be used with a registration process, which provides additional confidence and a higher level of security for voice communication. Such a methodology uses a secondary communication method or channel (eg, using both the control channel and the traffic channel), which is more difficult for attackers to exploit. Furthermore, when using SMS / MMS the phone number of the sender (or user) can be verified and a whitelist process can establish the list of mobile devices authorized for registration. The white list is defined herein and may also include a process for determining what types of information or data are allowed to be transmitted or received over the mobile phone network. Also, when SMS is used, then the control channel of the mobile phone network is used (which is more flexible and uses less bandwidth). Using the white list on control channel 25 is safer than using the data channel.
<img file="MX348109B_D0035.tif" />
Among other things, the registration process (which takes
IMPI INSTITUTO MMICANO n * la nonsDA · INDUSTRIAL place through the control channel using SMS) authenticates the user of the mobile device (if I reject), the same mobile device and the server (network interconnection device). Mobile device authentication is one of the most important logging features through the control channel that is not available on the traffic channel. An authenticated mobile device acts like what it has, which improves security like what you know. Traditionally it has been established as what you have through the security key that is provided to each individual user which is expensive compared to the mobile device (which is already owned by the user).
Additionally, through the registration process, a secure communication connection is established between the mobile device and the server and a unique encryption key is established between the mobile device and the server. The unique encryption key can be renewed based on the policy decided by the system administrator.
Once the registration process is established through the control channel, all other modules operating on the traffic channel can use the unique encryption key that has been established for communication (transmission and reception of information). Other benefits of combining the secure SMS module 201 with others
DC THE NONITY
UNWUSTIUAL. ^ RR-ÜL-ÍS<sup>1</sup>* ^ modules is the sharing of one or more secure address books between all modules, having a single signature process, having common configuration, sharing storage area, improved user experience, all improved efficiency to combine secure SMS communication with secure voice communication, and more.
By combining the secure SMS and secure voice modules, the secure SMS module can also benefit from the traffic channel features including sending and receiving information such as IPSMS, policy information, group information over IP. In this invention, the secure SMS and secure voice can synchronize the phones stored in the secure address books with the server and identify the phones in the secure address book that have similar software and are capable of secure communication.
In some embodiments, the unique encryption key from the registration process is used in conjunction with SSL / TLS, and SIP (Session Initiation Protocol) packets are encrypted and decrypted on the server and mobile device. In other embodiments, the unique encryption key or registration process is used in conjunction with SRTP (Secure Real Time Transport Protocol) and packets are encrypted and decrypted on the server and mobile device.
<img file="MX348109B_D0036.tif" />
A SIP packet containing the key is encrypted
IMPI
INSTITUTO MEXICANO Di LA INDUmUAL PROPERTY unique encryption on the server 15 before transferring through a TLS / SSL channel through the mobile phone network 40 to the mobile phone 41. Secure communication such as SMS is used to authenticate more reliably the mobile phone 41. Using secure communication such as SMS, the server 15 is able to verify the phone number of the mobile phone 41.
Furthermore, secure communication (eg, SMS message) is encrypted to prevent eavesdropping and further strengthen the security of the communication between the server 15 and the mobile phone 41. In an alternative embodiment, an MMS message may be used.
Some embodiments and methods of the invention utilize encryption, a unique encryption key, mobile device configuration, and dynamic command delivery via encrypted mobile communications (eg, SMS / MMS message). This is to address the problems associated with the vulnerability of using mobile voice communications. As illustrated in Figures 1 through 18, an encryption key or keys can be used and settings and other information can be communicated via an encrypted method. The key or keys can also be changed dynamically through an encrypted method. The commands to carry out the
<img file="MX348109B_D0037.tif" />
IMPI INSTITUTO MUUCANO MLAnoniDAT INDUSTRIAL tasks can be additionally delivered to a mobile device (such as a headset) or an application through an encrypted method.
In the past, mobile applications that have primarily used data for communication rely on advanced technology to determine if the server intends to send information to the mobile application. In other words, the mobile application periodically contacts the server to determine if the server has any information that needs to be sent to the mobile device. This process is not considered very efficient as it uses the resources of the mobile device excessively. Up to this point, some of the manufacturers of the Mobile Operation System introduced the concept of push notification, whereby the mobile application is based on push technology where the message is inserted from the server to the mobile application.
Since the push notification is not reliable or for the purpose of redundancy, it is possible to send an SMS or MMS message, either encrypted or plain text to a mobile application running on the mobile device to instruct the application to make contact with the server. This technique can be used in conjunction with the push notification or by itself. Mobile apps
<img file="MX348109B_D0038.tif" />
IMPI
INSTITUTO MUKAN · DELA ERORROA »INDUSTRIAL voice security systems mainly use a data channel and are in constant communication with the server to find out if there is a task waiting for them. For example, to find out if there is a phone call waiting to connect with the mobile device. If secure voice communication also uses SMS or MMS are described herein, the server can send a message to the mobile device when there is a phone call waiting to connect, and the SMS can wake up the mobile application and instruct it to contact the mobile device. server. Thus, with some embodiments and methods of the invention, the commands to carry out the tasks can be delivered to the handset or application through an encrypted method such as Secure SMS; including but not limited to the ability to stop activity on the application and data channel, or put to sleep to conserve battery and device resources, as well as wake up a data connection via SMS, Push Notification, or other method.
Some embodiments and methods of the invention utilize an encrypted address book scan and encrypted mobile communications (eg, SMS / MMS message) to address the problems associated with the vulnerability of using mobile voice communications. Depending on the server configuration, the user's address book can be browsed on the
<img file="MX348109B_D0039.tif" />
IMPI nwrmrro Mexican MumomoAD fNBUSTNAL the user's mobile device, and the server may find others who have such a secure communication software module or application on their mobile devices, if such other users have chosen to enlist. This makes it convenient for the user to establish secure calls with other users using their mobile devices and encrypted mobile voice communications. Users can also share a secure contact list between the applications on the mobile device and the server and / or between the applications on the mobile device. Users can also share unique login, establishment, configuration and other characteristics using secure mobile voice communications. All information between users is transferred in an encrypted way (eg, voice (speaking on the mobile device), text (SMS / MMS messages), data or any other.
Once the registration process has been established through the control channel, all other modules operating the traffic channel can use the unique encryption key that has been established for communication (transmission and reception of information). Other benefits of combining the secure SMS module 201 with other modules is to share one or more secure address books among all modules, having a single process of
<img file="MX348109B_D0040.tif" />
IMPI
INSTITUTO MUJCANO I HEARD LA MOnSOAD industrial firm, having a common configuration, sharing the storage area, improved user experience, all improved efficiency to combine secure SMS communication with secure voice communication, and more.
By combining the secure SMS and secure voice modules, the secure SMS module can also benefit from the features of the traffic channel including sending and receiving information such as IPSMS, policy information and group information over IP. The secure SMS and secure voice can synchronize the phones stored in the secure address books with the server and identify the phones in the secure address book that have similar software and are capable of secure communication.
In some modes, the unique encryption key from the registration process is used in conjunction with SSL / TLS and the SIP packet is encrypted and decrypted on the server and mobile device. In other modes, the unique encryption key or the registration process is They are used together with SRTP (Secure Real Time Transport Protocol) and packets are encrypted and decrypted on the server and mobile device.
A SIP packet containing the unique encryption key can be encrypted on the server 15 before being transferred over a TLS / SSL channel over a network
<img file="MX348109B_D0041.tif" />
IMPI msrrrui · Mexican DCMMtOniDAP INDUSTRIAL mobile phone 40 to mobile phone 41. Secure communication such as SMS is used to more reliably authenticate mobile phone 41. Using secure communication such as SMS. The server 15 is able to verify the telephone number of the mobile telephone 41. Furthermore, the secure communication (eg, SMS message) is encrypted to prevent eavesdropping and further strengthen the security of the communication between the server 15 and the mobile phone 41. In an alternative embodiment, an MMS message may be used.
Figure 18 illustrates an exemplary method of handling mobile voice communications in an encrypted and secure manner in accordance with the present invention. As shown in Figure 18, the IS server / networking device / administrator sends / communicates the secure identification code / Secure ID to the user (act 1601). The fourth software module 1672 (or 72 or 201) then sends a request to the server / networking device 15 / administrator with the interest / request for registration with the server / networking device IS / administrator (act 1603). The server / networking device IS / administrator sends a certification signed by a trusted authority to the fourth software module 1672 (or 72 or 201) (act 1605). The fourth 1672 software module (or 72 or
<img file="MX348109B_D0042.tif" />
IMPI
ΙΝΠΤη / rO MUIGANQ DCMPROHIDAD INDUTHUAL
201) then verifies the certification of the server / network interconnection device 15 / administrator as genuine using a CA (Certification Authority) of public origin (act 1607). If the certification is not genuine, then the registration process is aborted; otherwise, if the certification is genuine, then the fourth software module 1672 (or 72 or 201) sends its own certification to the server / networking device IS / administrator (act 1609). The server / networking device 15 / administrator sends the registration confirmation with a key to the fourth software module 1672 (or 72 or 201) (can be encrypted with certification) (act 1611). The fourth software module 1672 (or 72 or 201) then sends the confirmation that can be encrypted with the key received from the server / networking device IS / administrator (1613).
STORAGE AND PROCESSING OF THE INFORMATION AVAILABLE ON THE MOBILE DEVICE
Some embodiments and methods of the invention can store or process available information, elements, functionality, or a combination thereof, on a mobile phone. The various modalities include a software application loaded on a mobile phone that stores certain information for user access.
- 51 IMPI
ΙΜΤΠυΤΟ MEXICAN
OF THE REDUCTION
INDUSTRIAL
<img file="MX348109B_D0043.tif" />
In addition, various embodiments of the invention include an Internet website through which certain information can be transmitted to the telephone. In some modalities, the information on the website can be updated over the phone, by the user through a personal computer, or both. Also, in some modes, various third parties such as merchants, companies, banks, airlines and the like, can provide information to the website. Information can be transmitted from the website to the telephone, or vice versa, through a telephone signal or through a mobile phone network, for example at certain times or as needed. In some modes, a user can be alerted to certain information or changes to the information that meets certain criteria.
The various embodiments and methods of the invention provide as an object or benefit that partially or completely addresses one or more of the needs, potential areas for a benefit or improvement, and the functions described herein. For example, modalities can provide a higher level of data security, be easier to use, achieve more functions, contain more useful information, provide a better level of control, provide easier handling and replace if it is lost or stolen. , or a combination thereof compared to
<img file="MX348109B_D0044.tif" />
IMPI
INSTITUTO MEXICANO Oí LA MOmDAD INDUSTRIAL several of the prior art. The various modalities can for example handle personal information for a number of users, classify certain information, provide alarms, transfer information between a server and mobile phones, and store information on mobile phones in a way that is easy for the user to access. . Furthermore, the features and advantages of the invention may be apparent to those skilled in the art.
In particular embodiments, this invention provides, for example, systems for managing personal information for a plurality of users, each user having a mobile telephone operating over a mobile telephone network. In particular modalities, the system includes at least a first software module that operates on at least one server and forms at least one website where a plurality of users visit the website through the Internet and choose to have their personal information managed through the system using their mobile phones. Furthermore, in these embodiments, the first software module provides secure storage for each personal information of the user received from the user and from at least one third party acting on behalf of the user to provide information to the user, and the first software module filters the information staff and select chunks
<img file="MX348109B_D0045.tif" />
IMPI ιμϊτγπγγο Mexican DE LA MOHEnAD INDVTHUA1 of the personal information that the first software module sends to the mobile phone. Furthermore, such systems also include a second software module that operates independently on at least a plurality of mobile phones, and the second software module is configured to receive chunks of the user's personal information from the first software module via the Internet and through the mobile phone network, and to store personal information on the mobile phone so that the personal information can be accessed later by the user even when the mobile phone is not connected to a mobile phone network, by observing a folder containing the pieces organized by matter object.
In some such embodiments, for at least a plurality of users, the second software module is downloaded by users from the first software module to the mobile phone via the website and via the mobile phone network. Furthermore, in some embodiments, for at least a plurality of users, the first software module includes instructions for searching at least a plurality of emails for keywords, identification numbers, or both and for selecting chunks of information. personal from emails using keywords or identification numbers. In some of such
<img file="MX348109B_D0046.tif" />
IMPI
INSTITUTO MEXICANO DE LA PROMUMD INDUSTRIAL modalities, for at least a plurality of users the first software module contains instructions to receive a command from the user through the mobile phone network to dispute a financial transaction for a particular account described in the sections of personal information, and upon receipt of the command, communicate or transmit a controversy of the transaction to the manager of the particular account, for example through the Internet.
In addition, in some embodiments for at least a plurality of users, the second software module contains instructions to allow the user to select at least a portion of the personal information that is stored in the mobile phone, select or enter an identifier of a different party, a different party's mobile phone, or both, and choose to send (at least a) portion of the different party's mobile phone personal information. In many embodiments, for at least a plurality of users, the first software module further contains instructions for evaluating whether the mobile phone of the different party contains a copy of the second software module, and whether the mobile phone of the different party contains a copy of the second software module, then send (at least one) portion of the personal information to the copy of the second module of
<img file="MX348109B_D0047.tif" />
IMPI
ΙΝΓΓΠυΐΟ MUtlCAN
OF THE «INDUSTRIAL OPIIDaD software in the mobile phone of the different party through the mobile phone network. In some such embodiments, for at least a plurality of users, the first software module contains instructions for receiving a command from the user through the mobile phone network, and upon receipt of the command, transmitting at least a portion of chunks of personal information to a different party over the Internet.
In other embodiments, the invention provides various methods for handling information for at least a plurality of users, using the Internet and users' mobile phones. In one such particular embodiment, the method includes for each of the plurality of users, (in any order) receiving a first set of personal information of the user from the user through the Internet, the user's mobile phone, or both. , where the first set of personal information includes the identification of an alarm criterion, and for each of the plurality of users, receive a second set of personal information on each user from at least one third over a network. In this mode, the method also includes, for each of the plurality of users, selecting a fraction of the second set of personal information, and for each of the plurality of users, transmitting the fraction of the
<img file="MX348109B_D0048.tif" />
IMPI
INSTITUTO MEXICANO DE LA PWRIDAD INDUSTRIAL second set of personal information to the users 'mobile phone through the mobile phone network to be stored on the users' mobile phone using a second software module that resides on the phone. Furthermore, in this embodiment, the second software module organizes the fraction of the second set of personal information and makes the fraction of the second set of personal information accessible to the user. This modality also includes, for each one of the plurality of users, repeating at least a plurality of times the reception of the second set of personal information, the selection of the fraction, and the transmission of the fraction. And this method also includes, for each of the plurality of users, using the second software module, providing an alarm to the user if at least a portion of the fraction of the second set of personal information meets the criteria.
Another embodiment of such method includes receiving a first set of user's personal information from the user via the Internet or via the user's mobile phone (or both), and upon instruction by the user, downloading a second software module. to the user's mobile phone via the mobile phone network.
This modality also includes receiving a second set of personal information of the user from at least one third to
<img file="MX348109B_D0049.tif" />
IMPI ΙΝΛΠυΤΟ MEXICAN OF THE PROPERTY iNmmuAt through a network. This modality also includes selecting a fraction of the second set of personal information, encrypting the fraction of the second set of personal information, and transmitting the fraction of the second set of personal information to the user's mobile phone through the mobile phone network to stored on the user's mobile phone using the second software module residing on the phone.
In addition, this modality includes describing the fraction of the second set of personal information and using the second software module that resides in the phone, organizing the fraction of the second set of personal information based on the topic, as well as using the second software module that resides on the phone to make the fraction of the second set of personal information accessible to the user based on the topic of the information. Still further, this modality includes repeating at least a plurality of times the reception of the second set of personal information, the selection of the fraction, the encryption of the fraction, the transmission of the fraction, the decryption of the fraction, the organization of the fraction and making the fraction accessible to the user, and the repetition further includes synchronizing at least a portion of the fraction of the second set of personal information that is stored in the user's mobile phone with the
IMPI
INSTmnO MIXICAFK r DE LA NOFLIDA · INlXtmiAL - corresponding personal information that was still stored in the mobile phone, while maintaining the organization of the information based on the topic of the information.
In various forms of any of these methods, for each of the plurality of users, the first set of personal information includes an identification of at least one financial account, the second set of personal information includes an identification of the deposits in the account , withdrawals from the account, and an account balance, and providing an alarm includes (or an alarm is provided that includes) setting an alarm if a withdrawal exceeds a first identified threshold within the criteria, setting an alarm if the account balance falls below a second identified threshold within the criteria, or both. In addition, in some of these methods, for each of the plurality of users, the first set of personal information includes travel information, an identification of a common carrier or travel agent, or a combination thereof, the second set personal information includes the identification of a departure time and a departure point, and providing an alarm includes (or an alarm is provided that includes) setting an alarm if there is a change in the departure time, the departure point, or both.
In many modalities the method also includes,
IMPI® *
MUUCANO INSTITUTE
DI UntefUDAC tj * - “™ JSf INDVJTMAL for each of the plurality of users, use a local signal transmission hardware located on the user's mobile phone, and use the second software module, under user control, transmit a local signal including at least a portion of the first set of personal information or the second set of personal information (or both) to a reader within proximity of the mobile phone. In addition, in the particular modalities, for each of the plurality of users, the first set of personal information includes loyalty or identification information of a merchant or a service provider (or a combination thereof), the first set of personal information or the second set of personal information (or both) includes the loyalty information, the local signal includes at least a portion of the loyalty information, and the local signal transmission includes the (at least a) portion of the loyalty information to the merchant, service provider, or both. Furthermore, in the particular modalities, the method also includes using a signal reception hardware located in the user's mobile phone, and using the second software module, under the user's control, to receive a local signal from a transmitter within the proximity of the mobile phone.
Furthermore, in the various modalities, the method
<img file="MX348109B_D0050.tif" />
IMPI wrrmjro mixjgano nunomiMD IKDVmUAL further includes, in any order, for at least a plurality of users, upon instruction by the user, transmitting at least a portion of the second set of personal information to a mobile phone of the different party via the mobile phone network to be stored in the mobile phone of the different party, to be accessed by the different party. In some embodiments the method further includes, in any order, for at least a plurality of the users, upon command by the user, wherein the command is provided through the user's mobile phone, transmitting at least a portion of the second set. of personal information to a different party over the Internet. And in the particular modalities, the portion of the second set of personal information includes a travel itinerary.
Still further, in some embodiments, the method further includes, for each of the plurality of users, before transmitting the fraction of the second set of personal information to the user's mobile phone, encrypting the fraction of the second set of personal information, compressing the fraction of the second set of personal information, or both and the repetition includes repeating the encryption, compressing, or both. In some such methods, for each of the plurality of users, the second software module organizes the fraction of the second
<img file="MX348109B_D0051.tif" />
IMPI
INSTITUTO MEXICANO gives the rwomoAD INDUSTRIAL set of personal information based on the topic and makes the fraction of the second set of personal information accessible to the user based on the topic of the information.
Additionally, in many embodiments, for each of the plurality of users, the repetition includes replacing at least a portion of the fraction of the second set of personal information that is stored on the user's mobile phone, while maintaining the organization of the information. based on the topic of the information. And in various embodiments, for each of the plurality of users, the repetition includes synchronizing at least a portion of the fraction of the second set of personal information that is stored in the user's mobile phone with the corresponding personal information that is still stored. on the mobile phone, while maintaining the organization of the information based on the topic of the information, the receipt of the second set of personal information, the selection of the fraction, and the transmission of the fraction, are all carried out by the first software module that resides on a server connected to the Internet, where the first software module also forms at least one website of the Internet.
SECURE COMMUNICATION OF MESSAGE TRANSMISSION
Some modalities and methods of the invention are configured to handle (ie, create, edit, observe,
<img file="MX348109B_D0052.tif" />
IMPI
INSTITUTO MUUCAM) DC LA MIOIIUMD IMeUmUAL compress, decompress queue, route, disassemble, reassemble, encrypt, decrypt, send, receive, reply, dispatch, communications (for example transmi ssion of short messages of transmission of messages store and / or lo similar) service messages (SMS), multimedia service messages (MMS), and other transmission of information, and / or the like) in a secure manner (eg, in an encrypted or other manner). In one embodiment, a short message transmission service (SMS) system comprises a software module configured for use in a device, such as a mobile device. The software module is configured to encrypt an SMS or MMS message through a first encryption. A networking device is configured to communicate with the mobile device. The networking device is configured to receive the encrypted SMS message from the mobile device.
In yet another embodiment, a method for erasing information on a mobile device comprises transmitting, to a mobile device, a secure message comprising a cleaning instruction. On the mobile device, at least one item of information is erased in response to the cleaning instruction.
Referring to Figur e 18, a
<img file="MX348109B_D0053.tif" />
IMPI Mexican iNjrmro EU LA FXUHWAI »INDUSTRIAL registration process (steps 1601 to 1613) to authenticate the user, mobile phone 41, and server 15, and to create secure communication between mobile phone 41 and server 15.
Additionally, module 201 may be configured to support methods for determining unauthorized access to module 201 (ie, intrusion detection, and the like). For example, if the correct password to access module 201 is not provided three (3) consecutive times (or any desired value selected by a user or a networking device administrator), the data stored by module 201 and / or the module 201 itself can be erased.
Additionally, a module 201 in a mobile device can register with multiple networking devices 115 simultaneously. For example, a module 201 may register with a first networking device 115 associated with a GSM network of a first carrier, and communications between the module 201 and the first networking device 115 can be transmitted over a GSM modem. The same module 201 can also register with a second networking device 115 associated with a CDMA network of a second carrier and the communications between the module 201 and the second networking device 115 can
<img file="MX348109B_D0054.tif" />
IMPI
INSTITUTO MEXICANO DE LA non AGAD INDUSTRIAL be transmitted through a CDMA modem. The module 201 may register with any number of suitable networking devices 115 to facilitate communications with various intended message recipients. Similarly, a networking device 115 can be configured to communicate with a first group of modules 201 associated with a first carrier through a first GSM modem configured to communicate with a second group of modules 201 associated with a second carrier. through a second GSM modem configured to communicate with a third group of modules 201 through a dedicated short code, and so on. In this way, the networking device 115 can communicate with multiple modules 201 via a cellular modem and / or other communication device appropriate for each particular module 201 (eg, based on the particular mobile phone hardware, eg ).
In certain embodiments, the networking device 115 can be configured to allow an SMS message from one module 201 to be delivered only to other modules 201 that are in a common circle of trust with the sender of the message. Described another way, in various embodiments, only one module 201 can be allowed to communicate with other members of a predefined group. For example, a module 201 can be allowed
<img file="MX348109B_D0055.tif" />
IMPI fwrrnvro MEXICANO ot la noriUAD iKtximiAi used by a sensitive government agency to communicate only with other members of the same agency. Furthermore, the networking device 115 can also be configured to allow an SMS message from a module 201 to be delivered only to other modules 201 that are in a common circle of trust with each other, but not with whoever sends the message. In this way, the networking device 115 can be further secured, since unintended and / or unwanted communications outside of a particular circle of trust or other groups can be reduced or eliminated. Furthermore, the networking device 115 can be configured to allow an SMS message from one module 201 to be delivered to any other module 201. In addition, the networking device 115 can be configured to contact another networking device 115 for information regarding a module 201 registered with the other networking device 115. The networking device 115 can also be configured to propagate at least one message from module 201 to another networking device 115.
In various embodiments, the networking device 115 can be configured with a whitelist comprising an approved list of modules 201 and / or
<img file="MX348109B_D0056.tif" />
IMPI
MUICAN INSTITUTE
OF THE INDUSTRIAL PWnUMD mobile devices that may be authorized to register with the network interconnection device 115.
For example, a user 21 may wish to enroll in mobile banking services offered by a third party 31. User 21 communicates his wish to the third party 31, who approves the request. The module 201 associated with the user 21 can then be added to a whitelist on the networking device 115 associated with the third party 31. The user 21 can then register his module 201 with the networking device 115. In this way, a set of trusted pre-approved modules 201 can be defined and / or registered in such a way that communications between whitelist members and / or one or more third parties can be facilitated. Additionally, each module 201 and / or mobile device on a whitelist can be configured with a unique identification code. The unique verification code can be valid for a limited period of time, for example, six hours. In this way, security can be improved, since module 201 may be required both to be a member of the whitelist and to provide a unique identification code in order to register with the networking device 115 and / or to communicate. with other modules 201 through the networking device 115.
In certain modalities, the third party 32 also
<img file="MX348109B_D0057.tif" />
IMPI
ΜΠΠΜΟ MUCAMO MunawAD IMXTniLAL provides information to module 61 or module 201 in server 15 through a communication medium other than the Internet 10. Such communication medium can be, for example, a private network, a local area network ( LAN), a wide area network (WAN), a telephone network, a financial or bank card network, etc. Third parties 31, 32 and 33 are examples of data providers, or providers of personal data. Third parties 31 to 33 may be, for example, lottery organizers or operators (eg, a government agency, a state or gaming organization), brokers for lottery organizers (eg, resellers, convenience stores, or the server 15) , distributors for lottery organizers (e. g., resellers, convenience stores or the server 15), financial institutions, airlines, bank card providers, merchants, an employer or employee of the user, news providers, health care providers, insurance companies, stock brokers , government agencies, non-governmental organizations, etc., or any of these that may be functional online.
Module 201, server 15, and / or networking device 115, or other components that use encryption, can use any suitable encryption techniques and / or security models to encrypt, decrypt, compress, decompress, or otherwise ,
<img file="MX348109B_D0058.tif" />
manipulate and / or process information, eg, a symmetric key, an asymmetric key, an AES, a block cipher, and the like. Also, module 201, server 15,
IMPI ΐΝΓΠτυτο miucano Df THE PWPWDAD INDUSTRY!
the networking device 115 and / or other components may update, revise, expand, replace or otherwise modify the security model and / or the encryption technique used, as desired.
Module 201 can be configured to store a set number of messages on server 15, on networking device 115, or on the user's telephone. Module 201 can be configured to store the most recently specified number of messages (set by user, server 15, or networking device 115). Older messages can be deleted to make room for new messages (although permanent storage media can also be used). Users can flag messages to be exempted from this deletion process. Such flagged messages can be stored until manually deleted by the user, server 15, or networking device 115.
In certain embodiments, users 21, 22 and 23 can communicate with each other via SMS messages or other messages in a secure manner. For example, module 201 or a second software module 72 (described below) in
INSTITUTO MBUCANO ot la rwmnAB INOUSTRIAl the user's mobile phone 21 can send an SMS message destined to be delivered to a user's mobile phone 22. Module 201 is accessed and installed on the user's mobile phone, very similar to how the module 61 or module 72 and are installed in the user's mobile phone. In many embodiments, it may be necessary for a text message, a large text file, or other information to be transmitted to be in a particular format in order to be able to be transmitted using one or more SMS messages (eg, due to to the limitation of the number of characters that can be transmitted in an SMS message). In one example, numerous text messages are sent from server 15 (or user 21's phone 41) to user 22's phone 42, the text messages are compiled on user 22's phone, and user 22 reviews a large file text (or text message) on phone 42. In this example, the transmission of one text message or multiple text messages is negligible for user 22 (eg, user 22 receives a large text file or text message (instead of multiple text messages)). This format can be useful in sending information using text messages without limiting the number of characters typically found in the transmission of text messages. Described another way, when the size of the desired piece of information exceeds the size threshold of the
<img file="MX348109B_D0059.tif" />
IMPI
I WrrrUTO MUOCAN ·
Of LA CURRENCY industrial message, multiple messages can be used to transport such desired information to and / or from a mobile device.
Now, with reference to Figures 3, 4 and 5, and in various modalities, communications between one or more users 21/22/23 and / or third parties 31/32/33 can be propagated through a networking device 115 reliable. In this way, the security of the system can be improved. The networking device 115 communicates with one or more third parties 31/32/33 and / or users 21/22/23 (for example, via mobile phones 41/42/43) to send, receive and store messages from a short message transmission service (SMS) and messages from a multimedia message transmission service (MMS) securely. The networking device 115 can also communicate with users 21/22/23 in a conventional (unsecured) manner, if desired. Additionally, users 21/22/23 and / or phones 41/42/43 can download software (eg, secure SMS module 202) from a server 15. Networking device 115 can be notified of such installation and configured. to communicate with module 201 accordingly.
In one embodiment, the networking device 115 may be configured as software as a service (SaaS). The device can be accessed
- 71 IMPI
<img file="MX348109B_D0060.tif" />
INSTITUTO MUICANO MUFftOmtMD INBVSTUAL interconnection of networks 115 by third parties authorized to use SaaS through a secure connection to the network, such as HTTPS. The performance of the networking device 115 can be scaled, for example, through the use of load balanced server farms. In addition, the networking device 115 can connect to wireless bearer networks through multiple redundant connections. In this way, the networking device 115 can be configured to support a scaled number of users.
In another embodiment, the networking device 115 can be configured as an on-site enterprise server. Thus, the networking device 115 can be accessed by internal resources of the organization, for example, by a dedicated short code hosted with any supported aggregator or bearer. Furthermore, the networking device 115 can be configured to support a limited access circle of trust that allows communication only between certain authorized users. The networking device 115 may also be configured with an adaptive encryption scheme, message and / or file storage functionality, and other features, as desired, by a particular organization that deploys the networking device.
<img file="MX348109B_D0061.tif" />
IMPI
INSTITUTO MEXICANO DE LA FUDMEDAD INDUSTRIAL networks 115 on site.
In another embodiment, the networking device 115 can be configured as a service handled by a wireless bearer. The networking device 115 may therefore be partially or fully integrated into a wireless carrier networking device, for example, a wireless carrier short message transmission service center (SMSC). Alternatively, the networking device 115 can operate as a stand-alone system. For example, the networking device 115 may communicate with an SMSC of a first wireless bearer and with an SMSC of a second wireless bearer. Furthermore, the networking device 115 may be associated with and / or coupled to any number of SMSCs. Similarly, an SMSC can be associated with and / or coupled to any number of networking devices 115. In this way, the networking device 115 can be configured to support a scalable number of users in a bearer environment. wireless, and the networking device 115 can facilitate the secure delivery of messages over various networks.
Now, with reference to Figure 6 and in various modalities, one or more third parties 31, 32 and 33, can create a
<img file="MX348109B_D0062.tif" />
IMPI
INSTITUTO MEXICANO IXLAMtOnEMD INDUSTRIAL has an association with the network interconnection device
115 (step 602). Third parties 31, 32 and 33 notify users 21, 22 and 23 to download module 201 on phones 41, 42 and 43 (step 604). Alternatively, the third parties 31, 32 and 33, can send the module 201 to the users 21, 22 and 23 through a pulse of MMS (multimedia message transmission service) or WAP (wireless application protocol) (step 606 ). The user downloads module 201 (step 608). One or more APIs (application programming interfaces) and https (hypertext transfer protocol over a secure cap layer) or http (hypertext transfer protocol) can be used between the server 15 or the networking device 115 and third parties 31, 32 and 33 or users 21, 22 and 23. Furthermore, the server 15, the networking device 115, the third parties 31, 32 and 33 and / or the users 21, 22 and 23, can communicate through any suitable protocol, method, or means. Accordingly, the methods of the present disclosure are suitable for use in global system for mobile communications (GSM) networks, code division multiple access networks (CDMA), time division multiple access networks (TDMA), frequency division multiple access (FDMA) networks, transmission control protocol / internet protocol (TCP / IP) networks, satellite communications networks and / or the like,
<img file="MX348109B_D0063.tif" />
IMPI
INSTITUTE MSX1CANO
OF THE INDUSTRIAL RETURN and / or any combination thereof.
The third parties 31-33 use a secure SMS API to send an SMS or MMS message to the networking device 115 or to the server 15 (step 610). A
Secure SMS API can use HTTPS, network services, Java API, and / or any other suitable protocol. A determination is made as to whether the user has a module 201 loaded on their telephone 41, 42 or 43 (step 612). If the user has a module 201 loaded on their phone, then the user receives a secure SMS or MMS message on their phone at module 201 (step 614). An acknowledgment message may be sent back to the sender of the message (eg, user 21, 22 or 23 or third party 31, 32, or 33) (step 616). Once the receiving user opens the message he received (step 618), another acknowledgment message can be sent to the sender through the server 15 or the networking device 115 confirming that the user opened the message (step 620 ). If the user does not have module 201 loaded on their phone, then the user can receive a link to download module 201 on their phone (step 622), the message can be sent in clear text, the message can be omitted, a method can be used anonymous message retrieval (as discussed below) and / or the like.
In various modalities, continuing with reference to
<img file="MX348109B_D0064.tif" />
IMPI
TWTT1UTO MEXICANO deiafuohumd iNOvrruAi Figure 6, a user downloads module 201 (step 624).
When the user chooses to send a message from their phone to the phone of another user or third party (step 626), the user enters one or more phone numbers to send them a message on their phone (alternatively, the user can select from an address book secure on the user's phone) (step 628). For example, when using a secure address book, the user can import his general address book content (from his phone) into his secure SMS address book (eg, located in a database created by module 201 ). The information in the secure SMS address book is encrypted and stored on the phone. In this way, if your phone is lost or stolen, you can prevent those with access to the phone from extracting personal contact information (or other sensitive information) from the phone.
The user's message is encrypted and sent to the networking device 115 (step 630). As previously discussed, a determination is made as to whether the receiving user has module 201 loaded on their phone (step 612). If the user has module 201 loaded on their phone, then the user receives a secure SMS or MMS message on their phone at module 201 (step 614). An acknowledgment of receipt (for example a delivery confirmation) is
<img file="MX348109B_D0065.tif" />
IMPI
INHTnjT · MEXICANA »t INDUSTRIAL HUMIDITY sends the sender back (step 1616). Once the receiving user opens the message they received (step 618), then another acknowledgment (for example, a read confirmation) is sent to the sender through the server 15 or the networking device 115 confirming that the user opened the message (step 620).
In certain embodiments, when a user responds to or directs a message, a message identification is included in the message to allow tracking of which message was answered, directed, and the like. In some embodiments, additional information may be incorporated into the message, for example a total number of messages, a representative number of the sub-messages in the message chain, and the like. In this way, a series of related messages can be handled.
In various embodiments, the sender could register with a website associated with server 15 or networking device 115 to determine whether the message has been delivered and opened. In another example, when the receiving user opens the message, the module 201 automatically deletes the message within a predetermined period of time after the message is opened. In another example, when the receiving user opens and closes the message, module 201 automatically deletes the message (either immediately or within a period of time
<img file="MX348109B_D0066.tif" />
IMPI
Mexican dffrrniro
MIAnomDAD
INDWHUAI default after closing the message). The server 15, the networking device 115 or the module 201 can create such an automatic suppression process by including a field in the message header (or in the body of the message) with a command to suppress the message to one of the events instances (or other event, time period and the like defined). Users and third parties can view the status of each message. For sent messages, users and third parties can know when each message was sent, when each message was delivered, and when each message was opened (eg, through time, date, and status information about the message). For example, one or more icons may be provided (eg, within module 201, via a web browser and the like) in order to indicate the status of a particular message / eg, sent, delivered, read, responded to, addressed. , deleted and the like).
With reference now to Figure 7 and in some modalities, third parties 31, 32 and 33 and / or users 21, 22 and 23, can choose to delete their phones (eg, delete one or more elements of information or data) from remotely (step 702). For example, if a phone is lost, misplaced, or is no longer in use, you may want to erase the phone of all personal information, messages, or other information. Third parties 31, 32 or 33 and / or users 21,
<img file="MX348109B_D0067.tif" />
IMPI
ΜΠΤΠΠΟ MUKANO DiunoniiMD industrial or 23 can use a secure SMS API or other method to send a delete command to one or more phones (step 704). In one example, the user may access a third party website on server 15 in order to send a delete command to the user's phone (step 706). The networking device 115 authenticates the user, encrypts the erase command, and sends the encrypted erase command to the user's phone via an SMS or MMS message, or through another suitable method (eg, within the body of a message, in the header of a message, and the like) (step 708). Module 201 on the user's phone receives the encrypted erase command and decrypts the encrypted erase command (step 710). The secure SMS database (created by module 201) on the user's phone is deleted based on the decrypted delete command (step 712). Furthermore, the wipe command may also result in the deletion of different or additional data to a secure SMS database. For example, through a wipe command, the contents of the memory of a phone or the data for other applications can, at least partially and / or completely, be erased, deleted, restored and the like. Additionally, module 201 can be configured to automatically delete a secure SMS database and / or the entire memory of a phone in response to repeated
<img file="MX348109B_D0068.tif" />
IMPI rm 11 lino mwcano MLAnomnu) INDUSTRIAL failed local authorization attempts or other desired reasons. In this way the security of data located on a phone can be improved.
Additionally, in various embodiments, one or more components of the system 100 may be configured to log, record, or otherwise monitor communications between a phone and a server, for example, to detect attempts to interfere with or otherwise tap into one phone or another. telecommunications device, or otherwise simulating the origin or other attributes of one or more messages. The system 100 can also inform the user, a system administrator, a third party and the like, of the contents of such records, for example, attempts to simulate the identity of a user or to send messages that supposedly come from a particular user or a particular mobile device.
Turning now to Figure 8, in some embodiments, the user sends a message from one telephone to another (eg, from telephone 41, 42 or 43 to telephone 41, 42 or 43) in a secure manner (step 802). Prior to sending the message, the message is encrypted at the first phone (eg, using a first encryption key) (step 804). The encrypted message is sent to the networking device 115 (or server 15) (step 806) and the networking device 115 (or server 15) receives the
<img file="MX348109B_D0069.tif" />
IMPI
ΙΝΠΤΠΓΤυ MUUCAHO
IX THE FMNVDAD
INDUfflUAL
The encrypted message is interconnected networks 115
- 80 encrypted message (step 808). decrypts at the device (or server 115) (eg, using the first encryption key) (step 810). A determination is made as to whether the message is coming from one phone to another of a user (step 812). If the message does not come from one user's phone to another (eg, from a user's phone to a third party), then the message is sent to the third party's server, for example, using network services, invocation of the Java remote method (RMI), HTTP / S Post, and the like (step 814). A delivery confirmation can then be sent to the phone. If the message comes from one phone to another of a user, then the message is encrypted (eg, using a second encryption key) at the networking device 115 (or at the server 15) for the receiving user (step 816 ). The encrypted message is sent to the receiving user's phone (step 818). The receiving user's phone receives the encrypted message (step 820). A delivery confirmation is sent to networking device 115 (or server 15) that the message was delivered to the receiving user's phone (step 822). The encrypted message is decrypted (eg, using the second encryption key) on the receiving user's phone and opened. A delivery confirmation can be displayed on the telephone number of
<img file="MX348109B_D0070.tif" />
INSII'IUIU MUCAMO associated with the status page message. Once the message is decrypted,
- 81 who sends by changing the sent icon, or can be shown in one that the receiving user opens the sending an open acknowledgment or other appropriate read confirmation to the networking device 115 (or to the server 15) (step 824) . The networking device 115 or the server 15 can direct the open acknowledgment to the sender's phone. The acknowledgment of open receipt can be displayed on the sender's phone by changing the icon associated with the sent message, it can be displayed on a status page and / or the like.
In various embodiments, the original sent message is encrypted differently from the finally received message, so that only users or third parties who have the relevant encryption key can decrypt, open and read the message. Each user or third party can have their own unique password, so that the user or third party cannot access, open or read the message of another user or third party. Each unique key can also be changed as desired, eg periodically, for additional security. Furthermore, a user can modify his own encryption key manually or in a specific time interval. This password change made by the user is communicated to the networking device 115 to
<img file="MX348109B_D0071.tif" />
IMPI
MUUCANU INSTITUTE
Say LA PSOrUDAt)
INDUSTRIAL keep module 201 in sync with networking device 115. Additionally, the encryption key associated with a particular mobile device can be stored outside of the mobile device for additional security.
In certain modes, a key. encryption associated with a particular module 201 can be updated. The networking device 115 is configured with two encryption keys per module 201, a current key and a new key. Module 201 is configured to use the current key. In response to a predetermined interval, a key change request from module 201, and / or a key change instruction from networking device 115, module 201 is configured to replace the current key with the new key. The current key is kept active in the networking device 115 and a new key is generated. A password change command, including the new password, is sent to module 201. Module 201 status changes from current to pending. Messages to and from module 201 are kept in a row at the networking device 115 until the status of module 201 returns to current.
When the password change command is received in module 201, module 201 stores the new password in the
IMPI ΙΝΓΠΐυΐυ MUIGANO MIA NtOHUMD o- ”* TÁ <Q INDUSTRIAL place of the current key and transmits an acknowledgment of the key change to the networking device 115 using the new key. When the networking device 115 receives the key change acknowledgment from module 201, the new key is copied to the current key, and the new key is set to a blank value. Module 201 status changes to current. Messages in the row for module 201 can then be processed using the current key (which was previously the new key) and messages sent and / or received using the old key (previously the current key) will fail and can be logged.
In case module 201 does not return a password change acknowledgment after sending the password change command to module 201, the networking device 115 can forward the password change command to module 201 one or more more times. If the key change acknowledgment from module 201 is not received, for example, within a predetermined period of time, in response to a predetermined number of transmitted key change commands, and the like, the status of module 201 can be changed to suspended. Additionally, the networking device 115 may be configured to periodically verify all pending key change requests, to resend password change commands.<sup>84</sup> IMPI »^
ΓΝΙΙΙΤΙΗΟ MEXICAN nciAnoHVM ·
INDUSTRIAL key and / or to disable one or more modules 201, as appropriate.
If module 201 is suspended in response to an incomplete key change, or is disabled by an administrator associated with networking device 115, module 201 may be required to re-register with networking device. 115. Upon re-registering with the networking device 115, the status of module 201 can be set to current and queued messages for module 201 can be processed.
In various embodiments, one or more messages may be queued and / or otherwise stored in networking device 115. Queued messages in networking device 115 can be encrypted via a third encryption key. , for example, a storage encryption key associated with the networking device 115. Queued messages can be marked for automatic or manual processing. Messages marked for automatic processing can be processed when the associated module 201 returns to the current state. Messages marked for manual processing can be processed through a systems administrator or other manual process. Messages can be kept in a row for a period of
- 85 IMPI
INSTITUTO MUUCAN · ocia norwMP INDUSTRIAL
<img file="MX348109B_D0072.tif" />
default time, for example, three days. Messages that have been in a row for more than a predetermined period of time can be archived.
As discussed above, in various embodiments, the module 201 may have a status associated with it, for example pending, whitelisted, current, suspended, disabled, and the like. A whitelisted module 201 has been whitelisted but has not registered with the networking device 115. A current module 201 has been registered with the networking device 115 and its encryption key is up to date . A pending module 201 has registered with the networking device 115 and a key change command has been sent to module 201, but the key change acknowledgment has not yet been received from module 201. A suspended module 201 has registered with the networking device 115 and a key change command has been sent to module 201, but the acknowledgment of the key change from module 201 has not yet been received within the time allowed, within a predetermined number of requests, and the like. A disabled module 201 was once registered with the networking device 115, but has been disabled by an administrator or other supervisory entity associated with the networking device 115,
<img file="MX348109B_D0073.tif" />
IMPI INSTITUTO MEXICANO os la nongpAP INDUSTRIAL for example, in response to an unpaid bill, a report of a lost mobile device, the repeated entry of an incorrect password, and the like.
When module 201 is pending, messages can be queued. When module 201 is whitelisted, messages can be queued. When module 201 is current, messages can be processed. When module 201 is suspended, messages can be queued. When module 201 is disabled, messages can be marked invalid and / or suppressed. In addition, module 201 can be associated with any appropriate state, and messages associated with module 201 can be queued, processed, deleted, and the like, in any way suitable to allow secure communications between module 201 and the device. network interconnection 115.
The sender of a message can direct reports to determine which messages have been received and / or read / opened. In addition, server 15 and / or networking device 115 can be configured to store miscellaneous information related to a user, for example, a mirror or duplicate copy of one or more items of information stored on a user's phone. (eg, personal information, credit card information, credit card information,
<img file="MX348109B_D0074.tif" />
IMPI iwmvro Mexicano M LA PROPERTY INDUSTRIAL identification, financial information, health records, and the like), records of user messages sent and received, and the like. Because the server 15 and / or the networking device 115 can track, monitor and / or store each 'message in and out of the server 15 and the networking device 115 (and if the message was delivered and opened and the like), such information tracing may be used for compliance reports (eg, under the Sarbanes-Oxley Act or the Federal Information Security Management Act), evidence tracing of intervention, internal control of company information within the company (eg, through information technology) or within and outside the company, evaluation and detection of risk of fraud or any other intended use. Since the networking device 115 tracks the delivery of each message, the networking device 115 can be configured to re-forward a message that has not been delivered (eg, due to an error or any other reason). The networking device 115 may be configured to set the duration between forwarding a message to a predetermined period of time or based on the status of the message (eg, received, opened, and the like).
The present description also provides methods including, for example, methods for handling
IMPI
INSTITUTO MiXJCANO M LA r * OH IDAD INDUSTRIAL
<img file="MX348109B_D0075.tif" />
information for a number of users, methods for authorization of actions, methods for authentication of transactions, methods for authentication of access and alarm methods regarding proximity to a location. Figures 9 and 10 illustrate examples of such methods, and the different methods according to various embodiments may include a selection of operations or actions shown in Figures 9 and 10, described herein, or both, that may be carried out or be accomplished in the order presented, or in many ways, in a different order.
Turning now to Figure 9, this figure is a flow chart illustrating examples of various methods including, for example, methods for handling information for a number of users to use the Internet or users' mobile phones. Many modes have some, but not all, of the actions shown in Figure 9. In certain embodiments, method 900 includes receiving information from a user (action 905). This may include, in some embodiments, that at least some of the users receive a first set of personal information (eg, the user) from the user through at least one of the Internet and the user's mobile phone.
For example, user 23 shown in Figure 1 can access website 65 through computer 13
<img file="MX348109B_D0076.tif" />
IMPI iwrmiTOMjxu¿ANo DE LA PROPERTY INDUSTRIAL account and can enter etc.
Information
- 89 and the Internet 10, you can open information, select options, can be entered or selected can include, for example, names of financial institutions, account numbers, names of airlines, frequent flyer numbers, names of insurance companies, numbers of insurance policies, driver's license numbers, passport information and the like. In some cases this personal information may be complete, while in other cases, the first set of personal information may include information that facilitates receiving or completing the information from one or more third parties (eg, 31 to 33) such as by identifying third parties, accounts and the like.
In certain embodiments, method 900 further includes downloading a module from the mobile phone (action 910). In some embodiments, eg for multiple users, the user instructs the server (eg, 15) or selects a website (eg, 65) to download a module from a mobile phone, eg, the second software module 72 , 77 or both, shown in Figure 1. In a particular embodiment, for example, the second software module 172 is downloaded from the first software module 61 through the Internet 10 and the mobile phone network 40 to the mobile phone 41, at the user's instruction 21. In others modalities, the software module 72 can be downloaded to the mobile phone
<img file="MX348109B_D0077.tif" />
IMPI
INSTITUTO MJUUCANO DE LA FROFLEDAD INDUSTRIAL
43, for example, through the Internet 10, and the computer
13, for example via a USB port or a wireless network. In other embodiments, the software module 72, 77, or both, can be loaded onto the phone at the store where the mobile phone was purchased or at an establishment of the entity that controls the server 15, which operates the website 65 or that provides an information management service or system for a number of users.
In various embodiments, method 900 further includes transmitting the information to a different person (action 955). In many such embodiments, the user can select (eg, first) or otherwise provide instructions or commands to send certain information to the third party (evaluated at action 950). In particular, in some modalities, (eg, in the order indicated or in another order), at least for several of the users, the method 900 may include, to the user's instruction (eg, evaluated in action 950), transmit (eg, in action 955) at least a portion of the second set of personal information (eg, received in action 915, selected in action 920, transmitted in action 935 or a combination thereof) to the mobile phone of a different person. In some embodiments, this can be accomplished via the mobile phone network (eg, 40) for storage on the different person's mobile phone, eg for the
IMPI
ΙΝΠΤΗΠΟ MEXICAN INDUSTRIAL DATAMOnXTY
<img file="MX348109B_D0078.tif" />
different person's access.
With reference to Figure 1, for example, user 21 may provide an instruction or command (eg, at action 950), for example, via mobile phone 41 of user 21, to send at least a portion of the information received (eg, at action 935) to a different user 22, specifically via mobile phone 42. In different embodiments, the mobile phone 41 can send the portion of the information to the mobile phone 42, for example, through the mobile phone network 40 or the mobile phone 41 can instruct the server 15 or the first software module 61 to send the portion of the information to the mobile phone 42, for example, via the Internet 10, the mobile phone network 40, or both, as an example. In some modalities, the delivery can be certified, or the delivery can be tracked and the sender can be notified when the delivery was completed or, alternatively, when the delivery was not successful.
In some embodiments, the first software module 61 receives a command (eg, at action 950) from the user (eg, 21), for example, through the mobile phone network 40 and upon receiving the command (eg, at action 950) transmits (eg, in action 955) at least a portion of the chunks (eg, 78) or fraction of the personal information to the different person (eg, 22) through the
<img file="MX348109B_D0079.tif" />
IMPI
ΙΜΤΓΠυΤΟ MKUCANO DE LA nonBMC INDUSTRIAL
Internet 10.
In some embodiments, the system (eg, system 100) can send the particular information, a fraction of it, or chunks, in different ways (eg, in action 955), depending on whether the different person is a user of the system 100 [eg, you have visited website 65 and have chosen to have system 100 handle your personal information, or have downloaded (eg, in action 910) or otherwise received, or installed, the second software module 72 on your mobile phone].
In some modalities, the user (eg, 21) can select (eg, in action 950) at least a portion of the personal information that is stored in the mobile phone (eg, 41), select or enter (eg, in action 950) an identifier of at least one of a different person (eg, 22) and the mobile phone of a different person (eg, 42), and choose (eg, in action 950) to send (eg, in action 955) the at least a portion of the personal information to the mobile phone of the different person (eg, 42). In many embodiments, the first software module 61 assesses whether the different person's phone (eg, 42) contains a copy of the second software module 72, and whether the different person's phone (eg, 42) contains a copy of the second software module 72, then first software module 61 sends (eg, in action 955) the portion of personal information to the copy
IMPI '' W'TJUTOMIXICAN
FROM THE NOTICE of the second software module 72 on the phone the different person (eg, 42), for example, to the mobile phone network 40 (eg, via SMS). In some modalities, the delivery can be certified or a notification message can be sent (eg, via SMS to user 21) when the delivery has been completed or, alternatively, after a certain amount of time or number of attempts when the delivery has not been completed. success.
Still referring to Figure 9, in many embodiments, method 900 further includes receiving a local signal (action 960), transmitting a local signal (action 965), or both. As used herein, a local signal is a signal that is transmitted and received bypassing the main transmitter that the mobile phone uses to make phone calls and bypassing the main receiver that the mobile phone uses to receive. phone calls. Also, a local signal does not pass through the mobile phone network (eg, 40). For example, a local signal from mobile phone 42 may be transmitted by local transmitter or communications device 82 and received (ie, directly) by reader or communications device 88, or vice versa. Examples of local signals include Near Field Communication (NFC) signals and Bluetooth communication signals, for example, using transmitters, receivers, or both (eg, the
<img file="MX348109B_D0080.tif" />
IMPI
INSTnVTOMWCAHO
DC THE MOBILE INDUSTRIAL CURRENCY Receiver Found Used for
- 94 device 82) on the telephone separated from the transmitter and the telephone conversations.
In particular embodiments, method 900 further includes, for each of the multiple users, using signal receiving hardware (eg, device 82 shown in Figure 1) located on the user's mobile phone (eg, 42), and using the second software module (eg, 72) under the control of the user (eg, user 22), which receives (eg, in action 960) a local signal from a transmitter (eg, device 88) in proximity to the phone mobile (eg, 42). In addition, some modalities include, for example, for each of a number of users, using local signal transmission hardware (eg, device 82) located on the user's mobile phone (eg, 42) and using the second signal module. software (eg, 72) under the control of the user (eg, 22) that transmits a local signal (eg, at action 965) that includes at least a portion of at least one of the first set of personal information (eg, received at action 905) and the second set of personal information (eg, received at action 915) to a reader (eg, device 88) in proximity to the mobile phone (eg, 42). As used herein, proximity, in this context, means within ten (10) feet, and close proximity
<img file="MX348109B_D0081.tif" />
- 95 IMPI
INSTITUTO MEXICANO DE ΙΛ INDUSTRIAL PROPERTY means within one (1) foot.
In certain embodiments, method 900 further includes organizing certain information (action 970), for example, information handled by system 100. For example, in many embodiments, the second software module 72 organizes (action 970) on the mobile phone) eg, 41), the fraction (eg, chunks 78, 79 or both) of the second set of personal information (eg, selected in action 920 and transmitted in action 935), which may include, in various modalities, if applicable, decrypting the information, decompressing the information, dialing the fraction of the second set of personal information accessible to the user (action 975), for example, on the user's mobile phone, or a combination thereof. In some modalities, the second software module (eg, 72) organizes (action 970) the fraction of the second set of personal information based on the topic and makes accessible (action 975) the fraction of the second set of personal information (eg, the chunks 78, 79 or both) to the user (eg, 21), for example, based on the information topic (eg, in folder or folders 76).
In various embodiments, some or all of the actions of method 900 can be repeated. For example, in some modalities, (eg, for each of some or all users) method 900 may involve repeating, at least a number of times, the reception (action 915), for example, of the second set of information personnel, the selection of the fraction (action 920) and the transmission of the fraction (action 935). In many embodiments, if applicable, encryption (action 925), compression (action 930), provision of an alarm (action 945), transmission of information to a different person (action 955), reception or transmission ( or both) of local signals (actions 960, 965 or both), the organization of the information (action 970), the provision of the information to the user (action 975) or a combination thereof, can be repeated as appropriate. Furthermore, in some embodiments, the receipt of user information (action 905) may be repeated, but may be less repeated than certain other actions, such as the receipt of information from third parties (action 915), for example.
In many modalities (eg, for each of the multiple users), repetition includes (eg, as part of action 970), replacing at least a portion of the fraction of the second set of personal information that is stored in the mobile phone of the user, while maintaining the organization of the information, for example, based on the topic of the information. Furthermore, in various modalities, for each of more than one of the users, the repetition includes (eg, as part of action 970) synchronizing at least a portion of the fraction
<img file="MX348109B_D0082.tif" />
IMPI iwrnvro Mexican
Industrial DELAnomOAD of the second set of personal information that is stored in the user's mobile phone with the corresponding personal information that was already stored in the mobile phone, while maintaining the organization of the information based on the topic of the information. As used herein, information synchronization includes both replacing and appending information, while classifying or maintaining a classified organizational structure based on topic. Topics can include, for example, travel information, account information (which can be classified for different accounts), bank card information, loyalty information, insurance information, etc.
In various embodiments, a user (eg, 22) may be able to use a mobile phone (eg, 42) to gain access to a physical space, such as an elevator, floor or area of a building, parking garage, etc. Access can be obtained, in some modalities, for example, by passing the telephone (eg, 42) through or over a reader (eg, a communications device 88), which transmits a local signal (eg, in action 865), by For example, using Near Field Communication (NFC). In some embodiments, for example, user 22 selects the desired code or number on telephone 42 and then rubs the
IMPI
Dt IA INDUSTRIAL NOTICE telephone 42 against reader or device 88 or passes telephone 42 over or through device 88. In certain embodiments, user 22 may provide or select the code by name, for example, elevator, which may be selected from a menu on mobile phone 42 or entered as a voice command, for example.
In some modalities, the mobile phone (eg
software module 72 on phone 41) can prevent the user (eg, 21 or another user who might not be authorized) from accessing module 201 or module 72 if the software (eg, 72) or the phone (eg, 41) has not been used for a specified period of time (for example, one minute, two minutes and the like), if the user has failed to provide the correct password for the software (eg, 72), if a remote closing command by telephone 41, and the like. Access to module 201 and / or module 72 can be restored later, for example, by entering the correct password. In other embodiments, software (eg, software module 72 on phone 41) can provide the phone's GPS coordinates (eg, module 61 on server 15) at regular intervals, when accessing or exiting the software (eg, 72), when accessing the phone, when sending a secure message, when turning off the phone, when turning on the phone, when the battery runs out, or a combination
IMPI
WJfflVTO MEXICAN
DELAnOHIDAD JVMT
INDUSTRIAL of the same, as examples. In various embodiments, GPS coordinates or other location data can be transmitted as a secure SMS message from module 72 on phone 41 to module 61 on server 15. In addition, a delivery receipt, an acknowledgment of open receipt and / or the like, it can also include GPS coordinates, time stamp information, central tower triangulation information and / or the like.
As described herein, specific modalities include, among other things, ways of communicating information to other electronic devices and, in certain embodiments, ways of making affirmative selections.
In some embodiments, the device or electronic reader (eg, device 88) may request from the telephone (eg, 42) the particular information needed, it may follow a greeting routine, or both. In some embodiments, an affirmative action of assent may be required, at least for certain functions, for example, to authorize a transaction or payment or to authorize access. Such assent action may include, in some embodiments, for example, user 22 entering a personal identification number (PIN) or password on a graphical user interface or on the keyboard on the mobile phone, providing a signature on a touch pad, swipe the phone (eg, 42) through an NFC reader (eg, the
- 100
IMPI
Dvrrruro MuucANo DE LA MOCEDAD
<img file="MX348109B_D0083.tif" />
device 88) or the like.
Furthermore, in some of these modalities, as yet another example, the first software module (eg, the module
61) includes programming instructions to receive (eg, in action 905) instructions from the user identifying at least one threshold for the alarm (eg, used in action 940) for at least a portion of the particular information (eg, the chunk 78). In some of these embodiments, at least one of the first software module (eg, 61) and the second software module (eg, 72) includes programming instructions for comparing (eg, at action 940) at least a portion of the particular information with the threshold. And, in some such embodiments, at least one of the first software module (eg, 61) and the second software module (eg, 72) includes programming instructions to provide an alarm (eg, at action 945) to the user. if the particular information passes the threshold (eg, in action 940).
Now, referring to Figures 1, 2 and 11, in a particular embodiment provided as an example, system 202 handles personal information and / or enables secure communication for any number of users and includes a SEGURE MOBILE INFORMATION MANAGEMENT ™ platform ( SMIM) (Secure Mobile Information Management) 200 and personal data providers 209. The SMIM 200 platform is a
101
<img file="MX348109B_D0084.tif" />
IMPI Mixjcano Institute
MUroOHHMD
INDUSTRIAL example of a technological platform for system 100, which allows mobile phone users (eg, 21 to 23) to have access to certain personal information through their mobile phone (eg, 41 to 43), in some ways, even when there is no signal or Internet connection for the cell phone (eg, from the mobile phone network 40). In this mode, the SMIM 200 platform includes one or more blocks of codes configured to provide the structure and foundations of the system 100 and encompasses the functionality from the definition of standards under which development takes place to define security, for the communication between components and various core software applications.
In certain modalities, the SMIM 200 platform includes module 201 (eg, the MICRO AGENT ™ module or the MICRO AGENT TECHNOLOGY ™ (MAT) module) and module 203 (eg, the WEB SERVICES module or the CELLTRUST WALLET WEB SERVICES module ™). In this example of an embodiment, the module 201 operates on mobile phones and is an example of the second software module 72, or a portion thereof, and the module 203 is an example of the first software module 61, or a portion of the same. In this example, module 203 is a code or software block that operates on server 15 and communicates, or exchanges data with, module 201 on phones, on website 65, and in secure storage
102
IMPI iwrnvro Mexican M la «DAT iNDurnuM.
64, for example. Module 203 can be a communication layer between module 201, website 65, and storage 164, for example. The module 203 can provide or allow authentication, communication, protocol definition, data integrity intervention, prevention of unauthorized access, and so on, and can allow access to the website 65 from the Internet 10. Module 201 allows users 21, 22, and 23 to create, send, receive and store secure SMS and MMS messages through phones 41, 42, and 43.
The module
203 also in several modalities it allows third parties (eg, 31 to 33) or personal data providers 209 (eg, banks, airlines, merchants, health care providers, and the like) to communicate with a customer (for example, to update your customer accounts or personal information in storage 64, on website 65, and / or in secure areas thereof, to change electronic medical records in a HIPAA compliant manner, to provide information and / or flight log and so on). Module 201 or second software module 72 provides a user interface, local storage, synchronization, and alerting components, in this mode, on one or more phones 41 to 43. In addition, in certain modes, a user interface, within the phone
103
<img file="MX348109B_D0085.tif" />
second software module 72, you can combine mobile 41 or
IMPI
INSTITUTO MEXICANO Oí LA Í'WOHWMX 'INDUSTRIAL user information (eg, ¿i) and provide the information back to the user. For example, providers of personal data 209 include financial institutions, airlines, retailers, or merchants. Module 203 allows personal data providers 209 to update customer personnel such as bank account, account information, or flight information and status, credit card information and charges.
In some embodiments, local storage (eg, folder 76 on mobile phone 41) allows the application (eg, second software module 72) to store information (eg, information chunks 78 and 79) on the phone (eg , 41), which can provide faster access, reduce dependency on the network (eg, mobile phone network 40, Internet 10, or both), and you can reduce the total cost of ownership by limiting the amount of data communication over the mobile phone network 40 that takes place (eg, on behalf of the user 21). In some embodiments, data (eg, chunks 78 and 79) on the phone (eg, 41) is synchronized with the data on server 15 to ensure that the user (eg, 21) has access to up-to-date information both in your phone (eg, 41) as well as on the network (eg, Internet 10, to which
104
IMPI
INSTITUTO MEXICANO de la nonaiMo INDUSTRIAL can be accessed, at least by user 23, through computer 13, for example).
In certain embodiments, the data is compressed, encrypted, or both for communication with the phone or mobile device (eg, between module 201 and module 203 or between the first software module 61 and the second software module 72 ). Furthermore, in some embodiments, the alerts can provide substantially real-time notification of various events or activities that can be sent to a module 201 that operates the telephone (eg, 41) (an example of module 72 or a portion thereof). For example, alerts can inform the user of an important or critical event such as a large account withdrawal or flight cancellation, flight changes, door changes, or the like. Also, in some embodiments, module 207 provides a middle row between users (eg, 23) operating on their computers (eg, 13) and module 205, module 201, or both. In some embodiments, module 203 can provide the information (eg, from personal data providers 209) to module 207, which can then be provided to module 205, module 201 (eg, on mobile phones), or both.
As used herein, passive or passive means not powered by the phone's battery or electrical system or electrically connected to the phone.
- 105
<img file="MX348109B_D0086.tif" />
IMPI
INSTITUTO MEXICANO ocuntomnAD INDUSTRIAL telephone (or any other battery or electrical system).
Also, as used herein, in this context, the phone component excludes disposable packaging for the phone (which may contain a barcode for product tracking or sales purposes, for example). Furthermore, in some embodiments, the component comprises the back of the mobile phone, the battery cover of the mobile phone, a battery for the mobile phone or a case for the mobile phone, as examples.
Furthermore, in some embodiments, the mobile phone has a phone number and the passive code comprises the phone number of the mobile phone. Also, in some embodiments, for another example, the passive code comprises a number that is unique to the component of all other mobile phone components and all other mobile phones. In other embodiments, the passive code may comprise or include the name of the user, an indicator for the user, an indicator for an account, a portion thereof, or a combination thereof, as examples.
With further reference to Figure 1, the website 65 may include a home or home page (or more than one such page) to which new users and new third parties may be directed. New users can be directed to this page or pages or to website 65 by means of
- 106 -
<img file="MX348109B_D0087.tif" />
IMPI
MEXICAN IMIIIUIU
MU * IK »®AD
INWJnKAL from search engines, advertisers, sellers, agents, or the like, as examples. Users may be assigned (or asked to choose) (eg, 21 to 23) usernames, user IDs, passwords and / or the like, which they can use to access secure areas or pages of the website 65, for example , where your personal information can be entered, displayed, updated and / or the like. In some embodiments, security can be provided to such areas, for example, using new systems and methods that may be described herein, for example. In some modalities, these secure areas can include information entered by third parties (eg, 31, 32 and 33). Furthermore, in some modalities, third parties (eg, 31 to 33) may have their own secure areas (eg, which are password-protected, or protected as described herein), for example, within the website 65 or on server 15 or another server, in which third parties (eg, some or all of 31, 32 and 33) may be able to enter, display, or a combination thereof, the information for a number of users.
In some embodiments, the first software module 61 filters the personal information and selects the pieces of personal information that the first software module 61 sends to the mobile phone (eg, 41) of the appropriate user (eg, 21). As used herein, a
- 107 -
<img file="MX348109B_D0088.tif" />
IMPI
INSTITUTO MEXICANO MumonuMD INDUSTRIAL piece of information is a discrete piece of information that is a subset of the total information. The pieces of information can be in digital form, for example, and can be in text form, in the form of numbers or values, or a combination thereof, as examples. In some embodiments, the chunks may include photographs, text, graphics, or the like, as additional examples. These chunks can be sent, for example, through a mobile phone network 40, for example, and can be sent as text, MMS messages or SMS messages, for example. In some embodiments, the server 15 can access the mobile phone network 40 through the Internet 10, for example.
In various embodiments, a second software module 72 operates (eg, independently) on more than one of the mobile phones (eg, 41 to 43, although module 72 is shown only on phone 41). Furthermore, in this embodiment, the second software module 72 is configured to retrieve pieces of the user's personal information (eg, 21) from the first software module 61 through the Internet 10 and through the mobile phone network 40 , and to store the personal information in the mobile phone 41 so that later the user 21 can access the personal information, for example, even when the mobile phone 41 is not connected to the telephone network
<img file="MX348109B_D0089.tif" />
iwrrmrro mxxicano
MIANOTIJMi
IMDUSTNAL mobile 40. User 21 can access personal information, for example, by viewing folder 76 containing chunks 78 and 79, which can be organized by subject matter, for example. One such subject may be financial information, for example, which may include account balances, transaction records and the like, and another such subject, in some forms, may be travel information, as another example, which may include, eg departure times and flight locations, and the like. Other examples of subject matter are described herein and include insurance information, bank card information, medical records, appointments, and the like.
In some such embodiments, for multiple users (eg, 21 to 23), the second software module 72 can be downloaded by users from the first software module 61 to mobile phones (eg, 41 to 43), for example, through the website 65, through the Internet 10, through the mobile phone network 40 or a combination thereof. Also, in some embodiments, for many of the users (eg, 21 to 23), the first software module 61 includes instructions to search some or all of the emails received by or for the users (eg, 21 to 23) for passwords. , identification numbers or both and to select chunks (eg, and 79) of personal information from emails
109
IMPI
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL passwords,
<img file="MX348109B_D0090.tif" />
of electronics using the identification numbers, or both. For example, the software module 61 can search the emails received by a specific user (eg, 21, 22 or 23) by account numbers, flight numbers, names of third parties (eg, one or more of 31, 32 and 33), etc., and can extract the pieces of information that concern them. In some embodiments, the software module 61 can search all emails (eg, sent to particular users), while, in other embodiments, only emails from certain sources or from certain email addresses can be searched.
Furthermore, in some such modalities, for many or all users, the second software module 72 contains instructions to allow the user (eg, 21) to select at least a portion of the personal information that is stored on the mobile phone ( eg, select chunk 78), select or enter an identifier from at least one from a different party (eg, 22) and a mobile phone from a different party (eg, 42), and choose to send the personal information (eg, chunk 78) to the mobile phone of the different party (eg, 42). Examples of such different parties are other users, for example, for user 21, users 22 and 23 can be different parties and their phones 42 and 43 can be phones.
- 110 -
<img file="MX348109B_D0091.tif" />
IMPI
ΙΜΠΠη / TO MUUCANO MIAIHOFHMD INDVSTMM.
mobiles of different parts. Examples of such an identifier include the name of the different party, the telephone number for the different party, a user identification number, and so on. In many embodiments, for multiple users, the first software module 61 further contains instructions for evaluating whether the mobile phone of the different party has certain functionality or contains a copy of the particular software, such as a second software module 72.
In some such embodiments, if the mobile phone of the different party contains a copy of the second software module 72, for example, then the first software module 61 may send the (at least one) portion of the personal information to the copy of the second software module 72 on the mobile phone of the different party, for example, via the mobile phone network 40, the Internet 10, or both. On the other hand, in some embodiments, if the mobile phone of the different party does not contain a copy of the second software module 72, for example, or, in some cases, other software that has adequate equivalent functionality, then the first software module 61 may send the (at least a) portion of the personal information to the mobile phone of the different party, in another way, for example, in the form of a standard email or text message.
- 111 IMPI iwsnruro MixiCANo
MlAntOrriTY
INDUSTRIAL
<img file="MX348109B_D0092.tif" />
In other embodiments, the software module 72 may send the information directly to the different party instead of the first software module (eg, module 61). In some embodiments, for more than one of the users, the first software module 61 further contains instructions for receiving a command from the user (eg, from user 21), for example, via mobile phone network 40, and at receive the command, to transmit at least a portion of the pieces of personal information to a different party (eg, to user 22 or 23 or, specifically, in some modalities, to their phones 42 or 43), for example, through from the Internet 10.
Furthermore, in some embodiments, for many or all users, the first software module 61 contains instructions for receiving a command from the user (eg, one of the users 21 to 23), for example, via the mobile phone network. 40, to dispute a financial transaction for a particular account described in the pieces of personal information. In particular embodiments, for example, upon receiving the command, the first software module 61 may contain instructions to transmit a transaction dispute to a manager of the particular account over a network, such as the Internet 10, for example. The account manager can be the third party 33, for example, and can be a bank or financial institution, for example.
- 112 IMPI Mexican institute
OF THE RROMSDAD
INDUSTRIAL
<img file="MX348109B_D0093.tif" />
Such a dispute of the transaction can be transmitted to the third party (eg, 33) in the form of an email or text message, for example, sent via the Internet 10, the mobile phone network 40, or both, while in others modalities, the dispute of the transaction can be sent through a private or financial network, as another example.
In various embodiments, software module 72, software module 61, and / or various other components, can be configured to support a particular application and / or user group, eg, mobile banking, healthcare information entry. , domain registration, airline registration, intra and inter government agency communication, communication between companies, and the like.
Furthermore, in some embodiments, some or all of the mobile phones (eg, 41 to 43) can be configured to transmit, receive, or both, local signals. For example, the mobile phone 42 includes a local transmitter, a receiver, an antenna, or a combination thereof, and a local communication device 82, which, in this embodiment, communicates with the local communication device or reader 88. In different embodiments, device 88 can read signals, send signals, or both. Communications devices 82 and 88 can exchange signals in one or both directions through near field communications, a personal area network, Bluetooth,
- 113 -
<img file="MX348109B_D0094.tif" />
IMPI iwrrmnn Mexican DEUMOmOAD INDUSTRIAL bars, WiFi, or the like, as examples.
Various modalities also include the second software module 77 to operate (eg, which is operating) on the user's mobile phone (eg, the appropriate one from phones 41 to 43). The second software module 77 may include programming instructions to store (eg, in folder 76) the particular information on the user's mobile phone (eg, the appropriate one from phones 41 to 43) and provide access to the particular information by the user (eg, one of users 21 to 23). Such a second software module 77 may be recorded on a computer-readable medium, for example, such as a hard disk drive, a random access memory (RAM), a read-only memory (ROM), a disk, a memory. , or the like, as examples.
In some embodiments, the second software module 77 may be stored or registered with a server (eg, server 15) for downloading to the user's mobile phone (eg, the appropriate one or more of phones 41 to 43). In a number of embodiments, the second software module 77 may be registered in memory within the user's mobile phone (eg, in the appropriate one of phones 41 to 43), for example. Such a second software module 77 may be, for example, part of the software module 72 shown in Figure 1 on the mobile phone 41.
114
IMPI »^ mwcan institute ·
MLAHIOnUMD
INOUSTIUAI
The particular information may be, may include, or be included within, for example, chunks 78, or both, for example, as described herein.
Furthermore, in some embodiments, the first software module 67 or 61 includes programming instructions to encrypt the particular information before sending the particular information to the user's mobile phone (eg, 41). In some embodiments, the second software module 77 or 72 includes programming instructions for decrypting the particular information. Still further, in some embodiments, the first software module 67 or 61 includes programming instructions for compressing the particular information before sending the particular information to the user's mobile phone (eg, 41). And, in some embodiments, the second software module 77 or 72 includes programming instructions for decompressing the particular information. Decryption and compression can be used together or separately in the different modes.
Additionally, in certain embodiments, the first software module 67 or 61 includes programming instructions to receive instructions from the user (eg, user 21) identifying at least one alarm threshold for at least a portion of the particular information. In such particular modalities, the first software module 67 or
115
IMPI iwrmrro mjuucamo
DC LAMOmiMD
INDUSTUAL
<img file="MX348109B_D0095.tif" />
or a second software module 77 or 72 (or a combination thereof) includes programming instructions to compare at least a portion of the particular information to the threshold. Additionally, in some embodiments, the first software module 67 or 61 and the second software module 77 or 72 (or a combination thereof) include programming instructions to provide an alarm to the user if the particular information passes the threshold. Such an alarm may be, for example, in the manner described herein, such as an audible alarm, a light or a display, a vibrating alarm, or a combination thereof.
In some modalities, for example, for one or more of multiple users (eg, users 21-23), the particular information includes financial account information, which may include, for example, amounts of withdrawals or debits from an account, such as a financial or bank account. In certain embodiments, the (eg, at least one) threshold may be, or may include, the amount of a withdrawal or debit, for example, and the first software module 67 or the second software module 77 (or both) may include programming instructions to provide an alarm to the user (eg, the appropriate one (or more) of users 21 to 23), if a withdrawal or debit (or both) exceeds the threshold. In another example, in some modalities, for each of a number of users (eg,
- 116 -
<img file="MX348109B_D0096.tif" />
users 21 to 23), the particular information includes travel information, including a departure time, a
IMPI
ΙΝΓΠΤνΤΟ MEXICANO DELAFWOrnKMD iNDtrrnuAL starting location (eg, a starting gate), or both. In some such embodiments, the first software module 67 or the second software module 77 (or both) includes programming instructions to provide an alarm if there is a change in the departure time or departure location (or both). , as examples. In other embodiments, alarms may be provided for other thresholds or other criteria.
Furthermore, in a number of modes, for one or more of the users (eg, users 21 through 23), the second software module 77 contains programming instructions to allow the user (eg, user 21) to select at least one portion of the particular information that is stored in the mobile phone (eg, 41), select or enter the mobile phone number of a third party (eg, the phone number of the user 22), and selecting to send at least a portion of the particular information to the mobile phone of the third party (eg, to the mobile phone 42 of user 22). In some embodiments, at least for many of the users (eg, user 21), the first software module 67 further contains instructions for evaluating whether the third party's mobile phone (eg, user 22's mobile phone 42) contains a copy second software module 77, module 72, or both. In some such embodiments, if the mobile phone of the third party (eg, mobile phone 42 of user 22) contains a copy of the second software module 77, for example, then the first software module 67 can send the portion of the information staff to copy the second software module 77 to the third party's mobile phone (eg, mobile phone 42 of user 22), for example, via mobile phone network 40, the Internet, or both.
The invention also provides various methods for handling information for a number of users, methods for authorizing actions, methods for authenticating transactions, methods for authenticating access, and methods for triggering an alarm on proximity to a location. Figures 2 to 4 illustrate examples of such methods and different methods according to the invention and a selection of different methods according to the invention may be included from the operations or actions shown in Figures 2 to 4, described herein or both. , which can be performed or carried out in the order presented, or in many modalities in a different order.
Turning now to Figure 9, this figure is a flow chart illustrating an exemplary information management method for a number of users using the Internet and users' mobile phones. Some methods of the
118
<img file="MX348109B_D0097.tif" />
IMPI tMTnvroMUKANQ
OF THE PROPERTY
INDUSTRIAL invention may include some of the actions shown in Figure 9. In the particular embodiment illustrated, method 900 includes receiving information from a user (action 905). This may include, in some embodiments, at least for each of the plurality of users, a first set of personal information (eg, of the user) originating from the user through at least one of the Internet and the user's mobile phone.
For example, user 23, shown in Figure 1 can go to or access website 65 through computer 13 and the Internet 10, can open an account, and can enter information, select options, and so on. Information that can be entered or selected can include, for example, names of financial institutions, account numbers, airline names, frequent flyer names, names of insurance companies, insurance policy number, driver's license numbers, information passport, etc. In some cases, this personal information may be completed, although in other cases, the first set of personal information may include information to facilitate the receipt or completion of information from one or more third parties (eg, 31 to 33), such as by identifying the third, account, etc.
In addition, in some forms, the first set of personal information includes identification or information
- 119 -
<img file="MX348109B_D0098.tif" />
IMPI
INSTITUTO MEXICANO Dt LA HtoraDAD INDUSTRIAL that is important to the user, which may include criteria for alarm. Such criteria (eg, received in action 905) can be entered by the user or selected from one or more menus, for example, The criteria can include, for example, a choice to receive an alarm and a withdrawal, debit or charge from a financial account, exceeds a threshold that is entered or selected by the user. In some embodiments, the criteria (eg, received in action 905) may include a selection or indication of whether the user receives alarms during the day, or only during certain hours of the day, as another example, which may vary depending on the nature of the alarm or the particular threshold. Other examples of alarms include whether travel departure times, departure locations or the like, have changed, if bills are due, if insurance coverage has expired, if stock prices have changed, if weather conditions or forecast or other environmental conditions meet certain criteria, if a document or credential is close to expiring, if someone has requested a particular action or access, if the children have traveled to a region of interest, etc.
In certain embodiments, method 900 further includes downloading a mobile phone module (action 910). In some embodiments, for example for at least a plurality of users, the user instructs the server
120 • <STnvTOMU »c * jjo
OF THE HIOW1DAP
INDUrrUAL (eg, 15) or select on a website (eg 65 to download a mobile phone module, for<sup>1</sup>'For example, the second software module 72, shown in Figure 1. In a particular embodiment, for example, the second software module 72 is downloaded from the first software module 61 via the Internet 10 and the mobile phone network 40 for mobile phone 41, after user instruction 21. In other embodiments, software module 72 can be downloaded to mobile phone 43, for example, through the Internet 10, and computer 13, for example, through a USB port or a wireless network. In other embodiments, the software module 72 can be loaded onto the phone at a warehouse where the mobile phone was purchased, or at an establishment of the entity that controls the server 15, operates the websites 65, or provides a service. or system to manage the information of the users' numbers.
In a number of embodiments and methods of the invention, and in particular that shown in Figure 9, method 900 includes receiving information from a third party (action 915). In some embodiments, for example, for each of the plurality of users, this action (915) includes receiving a second set of personal information of each user from at least one third, for example, over a network (eg, the Internet 10). In many modalities, this
121
IMPI® * instituto mjuucano Dt LA INDUSTRIAL MOHIDAD action (915) can be carried out or carried out. By a particular user, after receiving the personal information (action 905) of the particular user, which can identify the third party, provide the information with which the third party can identify the particular user, identify the particular information that the particular user authorizes or requests to be provided from the third party, identify the bank account, etc.
In many modalities, the user can directly request a third party to send the information, For example, the user can visit a third party website (eg, through the Internet 10), register the third party's website and provide the third party's information through the website to identify the user in system 100 (Figure 1), which could also indicate the user's willingness for the third party to send the information. In various modalities, the information received from the third party (eg, in action 915) may include one or more balances, one or more account transaction descriptions (eg, an amount of a withdrawal, which may include, who made the withdrawal ), flight information, changes to flight information, insurance information, loyalty information, passwords, access codes, calendar entries, navigation information, access numbers, number of bank cards, location information concerning regions of interest,
- 122 -
<img file="MX348109B_D0099.tif" />
IMPI
ΠΛΤΓΠΓΓΟ MEXICAN M LA INDVJTRiAl PROPERTY etc.
In the illustrated embodiment, a method 900 further includes selecting a fraction of the information (action 920). In some embodiments, a fraction of the information received from the third party (eg, action 915) can be selected, for example, by the first software module 61. As used herein selecting a fraction of certain information means selecting less of all information. For example, particular subsets or pieces of information may be selected. In some modalities, the fraction of the information can be selected (eg, action 920) using a criterion that has been predefined (eg, in module 61). In some modalities, the fraction of the information can be selected (eg, action 920) using the criteria (eg, received in action 905).
In various embodiments, at action 920, particular information that is considered to be of particular importance or important to the user is selected. Examples include changes in departure times, status, or departure location for a flight that the user has booked, withdrawals from an account that exceeds a threshold, account balances, etc. In particular embodiments, for each of the plurality of users, for example, action 920 may include selecting a fraction of the second set of personal information described herein, while in
INSTITUTO MEXICANO Dt LA FROFIIDAD INDUSTRIAL various modalities, action 920 may include selecting a fraction of the first set of personal information, instead, or in addition.
Various embodiments and methods of the invention include encrypting the fraction of the information (action 925). The fraction that is encrypted can be the fraction of the information that is selected in action 920, for example. In some embodiments, a fraction of the second set of personal information is encrypted (eg, in action 925), for example.
The information can be encrypted (eg, in action 925), for example, to keep it confidential. Information can be encrypted (eg, at action 925), for example using PGP (Pretty Good Privacy), public key cryptography, asymmetric key encryption or the like, as examples.
Additionally, various embodiments of the invention include compressing the information fraction (eg, action 930). The fraction that is compressed may be the fraction of the information that is selected in action 920, for example. In some embodiments, a fraction of the second set of personal information is compressed (eg, in action 930), for example. The information can be compressed (eg, in action 930), for example, to make it easier, faster,
- 124
<img file="MX348109B_D0100.tif" />
or less expensive to transmit, store, or both.
IMPI
IXJTTTUTO MEXICANO Di LA FROEUbDAI) INDUSTRIAL
In different modes, the information can be compressed (eg, at stock 930), encrypted (eg, at stock 925), or both, in any order. In some embodiments, method 900 further includes, for each of the plurality of users, prior to transmission of the fraction of the second set of personal information (eg, action 935), for example, to the user's mobile phone, to the minus one encryption (eg, action 925), the fraction of the second set of personal information (eg, selected from action 920) and compress (action 930) and compress the second set of personal information (eg, selected in action 920). In certain modalities, the encryption (eg, action 925) and compression (action 930), for example, of the fraction of the second set of personal information (eg, selected in action 920), can be repeated, for example, together with other actions, as described herein.
In the illustrated embodiment, method 900 also includes, as mentioned, transmitting information (action 935). Such information may include, for example, the fraction of the second set of personal information (eg, selected in action 920), In various embodiments, the receipt (action 905), for example, of the first set of personal information, the receipt ( action 915), for example,
125
IMPI Mexican institute
Ot THE MOMITY
INDUSTRIAL
<img file="MX348109B_D0101.tif" />
of the second set of personal information, the selection of the fraction (action 920), and the transmission of the fraction (action 935), all are carried out by the first software module 61 that resides on the server 15 connected to the Internet 10 .
And in some embodiments, the first software module 61 further forms the (at least one) Internet website 65. In some embodiments, the methods include, for example, for each of the plurality of users, transmitting the fraction (eg, selected in action 920), of the second set of personal information to the user's mobile phone, for example, to via the mobile phone network (eg, network 40 shown in Figure 1) to be stored in the mobile phone, for example, using the second software module 72 (eg, residing in the phone).
In this mode. Method 900 further includes evaluating whether the information satisfies a criterion (action 940). Such criteria can be, as described herein or provided or selected by the user (eg, at action 905). If the information (the fraction of the information selected in action 920, transmitted in action 935, or both) satisfies the criteria (eg, to trigger an alarm, for example, as determined in action 940), then it can be provide an alarm
<img file="MX348109B_D0102.tif" />
(action 945). In some embodiments, the method includes, for each of the plurality of users, for example, using the second software module, providing an alarm to the user (action 945) if at least a fraction of the second set of personal information satisfies the criteria . Such an alarm (eg, from Action 945) may be audible, visual or for example, in the form of a vibration. In some embodiments, a sound or vibration can be produced by the user's mobile phone (eg, at action 945), and the reason for the alarm can be displayed on the phone screen, for example. In some embodiments, the phone's preset ring tone or an existing phone ring setting can be used for the alarm (eg, in action 945), as examples.
In some embodiments, the user may ask to acknowledge the alarm or description of the reason for the alarm, or may ask to make a response or take affirmative action to provide consent, for example, for the reason for the alarm, or a event described in the description. For example, if the reason for the alarm is that a withdrawal has been made from the user's bank account, the mobile phone may ring or vibrate. The user can then open the phone or press a button on the phone to acknowledge the alarm. The phone can then display the withdrawal amount, for example, together
IMPI
MEXICAN INSTITUTE
OF THE PROPERTY
INDUSTRIAL and transaction. In
<img file="MX348109B_D0103.tif" />
You can ask to make consent for the account description with some modalities, the user a selection to provide withdrawal, for example. In another scenario the phone may ring to provide an alarm that the user's flight has been delayed, as another example. The user can open the phone to acknowledge the alarm, and a brief description of the delay, and the new estimated exit time, can be provided on the screen of the mobile phone, for example. Other examples are described herein.
In some such methods, for example, for each of the plurality of users, the first set of personal information (eg, received in action 905) includes an identification of at least one financial account, the second set of personal information ( received in action 915) includes an identification of deposits to the account, withdrawals from the account and an account balance, and the provision of an alarm (action 945) includes at least one of triggering an alarm if a withdrawal exceeds a first identified threshold within the criteria, and triggering an alarm if the account balance falls below a second center identified threshold. of the criterion. As used herein such withdrawal may be a form of debit or a charge to the account, as examples.
As another example, in some methods, for each
128
<img file="MX348109B_D0104.tif" />
IMPI
MUICANO INSTITUTE
FROM THE HK * ODAD tNDUniUAL one of the plurality of users, the first set of personal information (eg, received in action 905) includes at least one of travel information (eg, frequent flyer information such as an identification number of frequent flyer) and an ID of at least one from a common carrier and a travel agent. Also, in some embodiments, the second set of personal information (eg, received in action 915) includes travel itinerary, which may include identification of a departure time and a departure location, for example. And, providing an alarm (action 945) may include triggering an alarm if there is a change in at least one of exit time and exit location in some modes. In many modalities, if the information (eg the fraction of the information selected in action 920, transmitted in action 935, or both) does not satisfy the criteria (eg, to trigger the alarm, for example, as determined in action 940), then an alarm may not be provided , and you can skip action 945, at least for that particular iteration of method 900).
In various embodiments, method 900 further includes transmitting information to a different party (action 955).
In many such modalities the user (eg, first) selects or otherwise provides instructions or commands to send certain information to the third party (evaluated
- 129 -
<img file="MX348109B_D0105.tif" />
IMPI ixsmvro MEXICANO Dt LA FltQfltDAD mtwrruAL in stock 950).
In particular, in some embodiments, (eg, in the indicated order or in another order) for at least a plurality of users, the method may include, upon instruction by the user (eg, evaluated in action 950), transmit (eg, in action 955) at least a portion of the second set of personal information (eg, received in action 915), selected in action 920, transmitted in action 935 or a combination thereof) to a different third party mobile phone. In some embodiments, this can be carried out via a mobile phone network (eg, 40) to store on the third party's mobile phone, for example, for access by the different third party,
Referring to Figure 1 for example, user 21 may provide an instruction or command (eg, at action 950), for example, via mobile phone 41 of user 21 to send at least a portion of the received information (eg , in action 935), for the different user 22, specifically through the mobile phone 42. In different embodiments, the mobile phone 41 can send the portion of the information to the mobile phone 42, for example, through the mobile phone network 40, or the mobile phone 41 can instruct the server 15 or the first software module 61 , to send the portion of the information to the mobile phone 42, for example, via the Internet 10. The mobile phone network 40 or both, as examples. In
IMPI Mexican iNsrmrro
ΜΙΑΜΟΗΒΟΛΟ
INDVSTUAL
<img file="MX348109B_D0106.tif" />
- 130 some modalities, the delivery pnpdp r.prt if icable or the delivery can be traced and the sender can be notified when the delivery has been made, or alternatively, when the delivery has not been successful.
In some embodiments, the first software module 61 receives a command (eg, at action 950) from the user (eg, 21), for example, through the mobile phone network 40 and upon receipt of the command (eg, at action 950) transmits (eg, in action 955) at least a portion of the portions (eg, 78) or fraction of the personal information to a different third party (eg, 22) through the
Internet 10. In some modalities, the system (eg, system 100) can send the particular information, fraction of it, or portions by different paths (egm in action 955), depending on whether the different third party is a user of the system 100 [eg, you have visited website 65 and chosen to have your personal information managed by system 100, or have downloaded (eg, action 910) or otherwise received or installed, the second software module on your mobile phone.
In some modalities, the user (eg, 21) can select (eg, in action 950) at least a portion of the personal information that is stored in the mobile phone (eg 41), select or enter (eg, in the action 950) an identifier of at least one of a different
131
<img file="MX348109B_D0107.tif" />
IMPI πητπυτο Mexican
Dt LAFROFIEDAC
IN »OST1UAL third party (eg, 22) and a different third party mobile phone (eg, 42) and choose (eg, in action 950) to send (eg, in action 955) the at least a portion of the personal information of the mobile phone of the different third party (eg, 42). In many embodiments, the first software module 61 assesses whether the mobile phone of the different third (eg, 42) contains a copy of the second software module 72, and whether the mobile phone of the different third (eg, 42) contains a copy of the second software module 72, then the first software module 61 sends (eg, in action 955) the portion of the personal information for the copy of the second software module 72 on the mobile phone of the different third (eg, 42), for example, through the mobile phone network 40 (eg by SMS). In some embodiments, the delivery can be certified or a notification message (eg SMS to user 21) can be sent when the delivery has been made or alternatively after a certain amount of time or number of attempts when the delivery has not been successful.
In particular embodiments, for example, the portion of the second set of personal information (eg, transmitted in action 955) includes a travel itinerary, for example. Thus a user is able to conveniently send his travel itinerary to another person. In Figure 9, in many modes, if the user does not instruct
- 132 IMPI
MEXICAN INSTITUTE
MUrnOHBMD
INDUIT1UAL
<img file="MX348109B_D0108.tif" />
of sending the particular information to a different third party, then the action of transmitting the information to a different third party (action 955) is omitted for at least that iteration of method 900.
Still referring to FIG. 9, in many embodiments of the invention and in the illustrated embodiment, method 900 further includes receiving a local signal (action 960), transmitting a local signal (action 965), or both. As used herein, a local signal is a signal that is transmitted and received without going through the main transmitter that the mobile phone uses to place phone calls and without going through the main receiver that the mobile phone uses to receive. phone calls, a local signal does not go through the mobile phone (eg, 40). For example, a local signal from mobile phone 42 may be transmitted by local transmitter or communications device 82 and received (ie, directly) by reader or communications device 88, or vice versa. Examples of local signals include near field communication (NFC) signals, for example using transmitters and receivers or both (eg, device 82) or the mobile phone that is separate from the transmitter and receiver that is used for telephone conversations.
In particular embodiments, method 900 further includes, for each of the plurality of users, use
- 133 -
<img file="MX348109B_D0109.tif" />
<img file="MX348109B_D0110.tif" />
IMPI
INSTITUTO MUUCANO oe hardware that receives signals (eg, device 82 shown in Figure 1) located on the user's mobile phone (eg,
42) and using the second software module (eg 72), under the control of the user (eg, user 22) that receives (eg, in action 260) a local signal from a transmitter (eg, device 88) within proximity to mobile phone (eg, 42). Furthermore, some embodiments of the invention include, for example, for each of the plurality of users, using hardware that transmits local signal (eg, device 82) located on the user's mobile phone (eg, 42), disabling the second software module. (eg, 72) under the control of the user (eg, 22), transmitting a local signal (eg, at action 965) that includes at least a portion of at least one of the first set of personal information (eg, received in action 905), and the second set of personal information (eg, received in action 915) for a reader (eg, device 88) within the proximity of the mobile phone (eg, 42). As used herein "proximity" in this context means within (10) feet, and "close proximity" means within (1) foot.
In the illustrated embodiment, method 900 further includes organizing certain information (action 970), eg, information that is handled by system 100. For example, in many embodiments of the invention, the second
- 134 -
<img file="MX348109B_D0111.tif" />
IMPI
MEXICAN INSTITUTE
OF THE FROHEDAD
INBUrnUAL software module 72 organizes (action 970) on the mobile phone (eg 41), the fraction (eg, portions 78, 79 or both) of the second set of personal information ((eg, selected in action 920 and transmitted in action 935), which can be included in several ways, when applicable, to decrypt the information, decompress the information, make the fraction of the second set of personal information accessible to the user (action 975), for example, to the user's mobile phone or a combination thereof. In some modalities, for each of the plurality of users, the second software module (eg, 72) organizes (action 970) the fraction of the second set of personal information based on the topic and makes the fraction of the second set of personal information (eg, portions 78, 79, or both) accessible (action 975) to the user (eg 21), for example, on the basis of the information topic (eg, in folder or folders 76).
In various embodiments of the invention, some or all of the actions of method 900 can be repeated. For example, in some embodiments (eg, for each of the plurality of users) the method 900 may include repeating, at least a plurality of times, the receipt (action 915), for example, of the second set of personal information, the selection of the fraction (share 920) and the transmission of the fraction share 935).
In many
- 135 -
<img file="MX348109B_D0112.tif" />
IMPI iwrnvTO mixjcano
FROM THE FWOWBOAP
INDUSTRIAL modalities, when applicable, encryption (action
925), compression (action 930) provision of an alarm (action 945) transmission of information to a different third party (action 955), reception or transmission, (or both) of local signals (actions 960, 965 or both), the organization of the information (action 970), the provision of the information to a user (action 975), or a combination thereof, may be repeated, as appropriate. Furthermore, in some embodiments, the receipt of information from the user (action 905) may be repeated but may be repeated less frequently than certain other actions, such as the receipt of information from third parties (action 915), for example.
In many modalities (.g. For each of the plurality of users), the repetition includes (eg, a part of action 970) that replaces at least a portion of the fraction of the second set of personal information that is stored in the mobile phone of the user, while maintaining the organization of the information, for example, based on the topic of the information. Furthermore, in various embodiments, for each of the plurality of users, the repetition includes (eg, as part of action 970) the synchronization of at least a portion of the fraction of the second set of personal information that is stored in the phone. user's mobile phone with corresponding personal information that has already been stored on the mobile phone,
- 136 -
<img file="MX348109B_D0113.tif" />
IMPI
MEXICAN INSTITUTE
MIA FMHBDAD
INDUSTRIAL while maintaining the organization of information based on the topic of information. As used herein, information synchronization includes both the replacement and annexation of information, while classifying or maintaining a stored organizational structure based on topic. Topics can include, for example, travel information, account information (which can be stored for different accounts), bank card information, loyalty information, insurance information, etc.
In some modalities, the mobile phone (eg, software module 72 or phone 41) can block the user (eg, 21 or another user who may not be authorized) from accessing the information if the software (eg, 72) or the phone (eg, 41) has not been used for a specified period of time, or if the user has repeatedly failed to provide the correct password for the software (eg 72). In other modalities, the software (eg software module 72 or phone 41) can provide the GPS coordinates of the phone (eg, to module 61 or server 15) at regular intervals, when accessing or exiting the software (eg, 72) when accessing the phone (eg, 41) , when turning off the phone, when turning on the phone (eg, 41) or when running out of battery or combination thereof, as examples.
Furthermore, in some of these modalities, for even
- 137 -
<img file="MX348109B_D0114.tif" />
IMPI (MEXICAN NSIIIUTO
DELAKOrHOAD
INDUSTRIAL other examples, the first software module (eg, module
61) includes programming instructions to receive (eg, in action 905) instructions from the user identifying at least one alarm threshold (eg, used in action 940) for at least a portion of the particular information (eg, portions 78 ). In some of these embodiments, at least one of the first software module (eg, 61) and the second software module (eg, 72) include programming instructions for comparing (eg, at action 940) at least a portion of the particular information for the threshold. And in some such embodiments at least one of the first software module (eg, 61) and the second software module (eg, 72), includes programming instructions to provide an alarm ((eg, at action 945) for the user if the particular information passes the threshold (eg, in action 940).
In a number of embodiments, such examples of method 900 also include, for each of the plurality of users (eg, users 21 to 23 shown in Figure 1), sending (eg, at action 935) the particular information for the telephone. user's mobile phone (eg, user 21 phone 41) through a mobile phone network (eg, 40) to store on the user's mobile phone (eg, 41 and accessed by the user (eg, 21). In some modalities, the particular information that is sent may contain or be
138
IMPI fWTHVTO MDUCANO of momDAD
INDUTHUAL similar to. the slices (eg, 78 and 79 and can be stored, for example, within folder 76, by module 77, for example). In some embodiments, the software module 67 or server 15 can be a classification software module, and can perform or initiate the actions of receiving emails (eg, action 915), searching for passwords or identification numbers (or both). and extresr the particular information (eg, in action 920), and in some modalities, transmit or send (eg, action 935) the particular information.
In some embodiments, the particular information may be the same or similar to the fraction of the information described herein, for example with reference to actions 920 to 935.
In many embodiments, method 900 also includes repeat actions, for example multiple times, search (eg, part of action 920), extract (eg, part of action 920), and send (eg, action 935). Various modalities of such methods can be performed in various orders and may include additional actions. For example, in some embodiments, method 900 may include (eg, for each of the plurality of users 21 to 23), after extraction of the particular information (eg, in action 920) and before sending the particular information (eg, in action 935), for example, for the
<img file="MX348109B_D0115.tif" />
IMPI (
MEXICAN INSTITUTE
M LA momDAP
INDUSTRY!
a 43) shares of (share 925)
- 139 mobile phone of the user (eg, encrypt the particular information the particular information (action 930) or both.
In particular modalities, (eg, for each of the plurality of users), the method 900 may include actions to receive instructions (eg, in action 205) from a user (eg, one of users 21 to 23) and identify at least one threshold criterion for the alarm for at least a portion of the particular information. In some embodiments, after extraction of the particular information (eg, action 920), the method 9000 may include comparing (eg, in action 940) at least a portion of the particular information for the criterion or threshold for the alarm, and providing an alarm (eg, in action 945) for the user (eg, one of users 21 to 23) if the particular information meets the criteria or passes the threshold, as examples.
Still other modalities include (eg, for at least a plurality of users 21 to 23) after instruction by the user (eg, user 21), transmitting (eg, action 955) at least a portion of the particular information to a third party (eg, 22) mobile phone (eg 42), for example, through the mobile phone network 40, to be stored in the third party's mobile phone (eg, 42), to be accessed by the third party (eg, user 22 ). In some
140
IMPI
WJTTTUT »M1X1CANO 72 ^ 8268 ^^ 8
ΜΙΛΜΜΒΜΧΙ iNDurruAi modalities, the at least a portion of the particular information (eg, transmitted in action 955) does not include a complete email (eg, an email received by user 21 or by module 67, and addressed to user 22 ). As an example, in some embodiments, the (at least a portion of the) particular information includes a travel itinerary (eg, of user 21). Thus, user 21 can easily send his travel itinerary (or other particular information) to another person, to facilitate such communication.
Turning now to Figure 10, this flow chart illustrates, among other things, an exemplary method for authorizing an action and authenticating access. Most of the various actions of method 1000 can be performed in an automated process, for example, by server 15, module 61, or both shown in Figure 1. In various embodiments, method 1000 can be carried out by one company or company for example, as a service for other companies and companies, or the like.
In Figure 10, the method 1000 includes receiving (action 1003), for example, from a person having authority to authorize the action, an identification of a first mobile phone to obtain authorization for the action. Such a person who has the power to authorize the action may be, for example, one of users 21 to 23
141
IMPI ^^ ίΝΓΠΤΤΠΌ MEXICAN J *
DtiAnampAD On-AS /
INDÚrnUAL shown in Figure 1. In some modalities, the person who has the power to authorize the action can provide the telephone number (eg, received in action 1003) through his computer or mobile phone, for example. For example, if user 23 is the person who has authority to authorize the action, user 23 can provide the phone number (eg, received in action 1003) from phone 43 or through computer 13 and website 65 .
In some modalities, the person who has the power to authorize the action can enter or put a password in the telephone number directly, although in other modalities, the person (eg, user 23) can enter or select a name, for example, or another identifier or token, which can be used (eg, in action 1003 for example, via server 15 or module 61) to find the appropriate telephone number (eg, telephone 43). In some embodiments, the person with the authority to authorize the action can select the phone number, for example from a menu, or the number can be read automatically from the person's phone or from a Caller ID feature or service , when using the phone. As used herein, all such are examples of actions (eg, 1003) to receive from a person who has authority to authorize the action,
- 142 -
<img file="MX348109B_D0116.tif" />
IMPI
INSTITUTO MEXICANO DC LA MONEDAD INDUTTMAL an identification of a first telephone number to obtain authorization of the action.
Still referring to Figure 10, the method 1000 may also include an action (1009) to receive, for example, from a person seeking the action, a request for authorization of the action. In different embodiments, actions 1003 and 1009 can be presented in any order, including, for example, the order shown in Figure 10. In different modalities or different situations, the person seeking the action (eg, who requests authorization in action 1009) and the person who has the power to authorize the action (eg, who provides the number in action 1003) can be the same person or it can be a different person (eg, from users 21 to 23).
After receipt of the identification of the first telephone number (eg, in action 1003), and after receipt of the authorization request (eg, action 1009), in the illustrated embodiment, method 1000 also includes an action (1015 ) of sending a first message, for example, via a mobile phone network (eg, 40 shown in Figure 1) to a first mobile phone, for example, having the first phone number. In such embodiments, the first message (eg, from action 1015) may include a description of the action for which authorization is requested, for example. In some modalities, the first
<img file="MX348109B_D0117.tif" />
IMPI wsrrrvTO Mexican
DILAPM> WWA £)
INDUSTRIAL telephone message is sent (eg, in action 1015) automatically, which means herein that you make the request for authorization (eg, received in action 1009) and provide the number and any criteria (eg, received in one or both actions 1003 and 1009) does not include human interaction (ie, between actions 1009 and 1015.
Furthermore, in the illustrated embodiment, after sending the first message (eg after action 1015), method 1000 includes an action (1021) to receive, for example, from the first mobile phone, (eg, having the first number number) a second message, which can authorize the action. In various embodiments, the second message (eg, received at action 1021) may be the result of the person controlling the phone taking an affirmative action to indicate authorization of the action (action 1018). Action 1018 may be performed by one of the users 21 to 23 shown in Figure 1, for example.
In some embodiments, the first message, (eg, from action 1015) includes at least one menu and at least one prompt to authorize the action when making the menu selection. The person controlling the phone can take affirmative action to indicate authorization for the action (action 1018) by making a selection from the menu, for example.
In some modalities, authorization is indicated (action
- 144 -
<img file="MX348109B_D0118.tif" />
1018) and the second message authorizing the action is sent (eg, which is received in action 1021) by pressing, for example, a single button on the mobile phone, then the first message (eg, sent in action 1015) it is received by mobile phone. As used herein press
IMPI ΐΜτπυτυ MEXICAN DE LA ηΟΕΙΕΜΟ INDUniUAL a single button does not include such actions, such as opening the flap of a phone, scrolling to view a message, or pressing send. In other words, it does not include determining how buttons are pressed, opening the phone flap, scrolling to view a message, or pressing send.
In some embodiments, the first message (eg sent in action 1015), the second message (eg, received in action 1021), or both, are SMS messages. One or both (eg of the first and second messages sent in action 1015 and received in action 1021 respectively) can be transmitted (eg, sent and received) through the mobile phone network (eg, 40 shown in Figure 1 ). Furthermore, in some modalities, the first message, (eg, sent in action 1015), the second message (eg, received in action 1021) or both, are voice messages, as additional examples, which can be generated in a computer, interpreted using speech recognition software, or both, as examples. In some embodiments, the first message (eg, sent in action
145
INJTTTVTO MEXICANO DI LA «ORÍDAD Wl industrial
1015) can be a voice message, as long as the second message, (eg, received in action 1021) is an SMS message. Other modalities may have other combinations.
In the illustrated embodiments, method 1000 also includes an action (1027) to evaluate whether the second message (eg, received at action 1021) authorizes the action. If so, then (in action 1030) the action may be allowed, facilitated, or performed, as examples. Some modalities include an action to allow the action (action 1030) only if the second message is received (eg, at action 1021) and the second message authorizes the action (eg, as determined by action 1027). Some modalities also include repeating the receipt of the request for authorization of the action (eg, action 1009), the sending of the first message (eg, action 1015), and the receipt of the second message (eg, action 1021). These actions can be repeated, for example, for requests for different actions, requests for the same action for different people, for requests for the same action or the same person at different times, etc.
Still further, some of these modes further include an action (1012) to encrypt the first message, for example, before the first message is sent (eg, action 1015), for example, for the first mobile phone. Some modalities also (and instead) include
- 146 -
<img file="MX348109B_D0119.tif" />
IMPI
MEXICAN INSTITUTE
OF INDUSTRIAL KNOWLEDGE an action (1024) to decrypt the second message, for example, after receipt of the second message (eg,
1021), for example, for the first mobile phone. In such embodiments, the first mobile phone can decrypt the first message and encrypt the second message, as examples. In some modes, compression and decompression can also be used (or instead).
In some modalities, before receipt of the request for authorization of the action (eg, action 1009), the first telephone number (eg, in action 1003) is received through an Internet website (eg website 65 via the Internet 10 shown in Figure 1), the mobile phone network (eg 40), or both. In some embodiments, they also include an action (1006) to receive. For example, through an Internet website (eg website 65 via the Internet 10) or a mobile phone network (eg 40). Or both, for example, from each of at least the plurality of persons who have the power to authorize the action, an indication or a criterion to obtain the authorization for the action, for example, for that particular person. Such criteria may be typed or verbally entered by the person, or it may be selected by the person from one or more menus, for example. In some embodiments, action 1006 may be similar to action 205 shown in Figure 9 and described herein.
- 147 IMPI Mexican institute
OF THE morBDAP
INDUSTRIAL
<img file="MX348109B_D0120.tif" />
In addition, some are included within modalities. Action 1003 can take action 1006 or vice versa, or actions 1003 and 1006 can be performed in another order.
As an example, in some modalities of the method
1000, the action 1006 includes receiving, for example, from the person who has the power to authorize the action, through at least one of the Internet website 65 (eg, website 65 through the Internet 10, shown in the Figure 1) and the mobile phone network (eg, 40), a time limit identifier to send the first message (eg action 1015). In many such modes, the sending of the first message (eg, 1015) can be done only according to time limits. For example, in some modalities, the person may not want to be requested in certain types of authorization during certain hours of the night, and can enter criteria or make selections accordingly.
In various modalities, the person who controls the phone (eg, who is in a position to indicate authorization in action 1018) is in fact, or intends to be, the person who has the authority to authorize the action (eg, from whom the number was received in action 1003, the criteria were received in action 1006 or both). In other modalities, the person who controls the phone is, in fact, or intends to be, a person who
- 148 -
<img file="MX348109B_D0121.tif" />
IMPI
INSTITUTO MEXICANO r * LA MOHEDA * INDVSTUAL is authorized by the person who has the power to authorize the action (eg, from whom the number was received in action 1003, the criteria were received in action 1006, or both). In addition, some modalities provide certain guarantees that the person who controls the phone is the correct person.
For example, in some embodiments, the second message (eg, received in action 1021) includes a password or authorization code that has been memorized by the person who has the authority to authorize the action and encrypt the first mobile phone (eg, in action 1018) after receiving the first message (eg, sent in action 1015) and before sending the second message (eg, received in action 1021). As another example, certain modalities include, for example, in the first message (eg, in action 1015) an action of asking a personal question about the person who has authority to authorize the action who is expected to be in control of the mobile phone. . Such modalities may also include, in the second message (eg, at action 1021), an action of receiving a present reply to the personal question. Such modalities may further include (eg, in action 1006), for example, by the person who has powers to authorize the action.
In various embodiments, the first message (eg, <sup>149</sup> IMPI »to
MEXICAN INSTITUTE
OF THE NNOHEDAD Q-li ΖΓΊ-ΛΞγ
INDUSTRY!
sent in action 1015) identifies the person attempting the action. and in some embodiments, the first message (eg, sent in action 1015) also (or instead of) identifies the action being requested (eg, in action 1009). Such information may be valuable, for example, in modalities or situations where the person requesting the authorization (eg, in action 1009) is different from the person whom the person who has the powers to authorize the action (eg, providing the number received in action 1003, in which the first message was sent in action 1015, which indicates authorization in action 1018, etc.). In some modalities, on the other hand, the first mobile phone is controlled by the person attempting the action (eg, who requests the authorization received in action 1009), and in some modalities, the person attempting the action (eg, who requests the authorization received in action 1009) is the same person who has the authority to authorize the action (eg, in action 1003, action 1008, or both).
In addition, some modalities also include an action (e.g., within action 1006) to receive, from the person who has the power to authorize the action, for example, through the Internet website (eg, the website 65 via the Internet 10 shown in Figure 1) or the mobile phone network (eg, 40), or both,
MEXICAN INSTITUTE
DtLAPMMUMD
IHDVSTTUAL an identification of a second phone number to notify a third person of the action (eg, the action for which a request is received in action 1009, which was authorized in action 1030, or both). Some such modalities include an action (eg, 1033), for example, after receiving the authorization request (eg, in action 1009), to automatically send the first message, the second message, a third message, or a combination of the same (eg, in action 1033), to the second phone number. The action (1033), to notify the third person, can include, for example (eg, in action 10098), or both, as or examples.
In the illustrated embodiment, method 1000 further includes action 1036 to track the authorization granted for the action over time, which may include reporting the results of the trace.For example, a report may be issued that may indicate which authorizations were requested ( eg, in action 1009), when authorizations were requested, who requested such authorizations, if and when authorizations were granted (eg, in action 1018), and if or when the actions were allowed (eg, on action 1030). In some embodiments, such a report or data (eg, in action 1036) may be provided to or through the (eg, first or second) mobile phone, for example, as SMS messages or portions of
151
<img file="MX348109B_D0122.tif" />
IMPI Muican trnrmiro oeuproredad
INDVSTMAL information described herein, as an example.
In some embodiments, the information can be provided through a local signal (received at action 1007). Action 1007 may be similar to action 260 shown in Figure 9 and described herein with reference to it. A local signal may be received (eg, at action 10078), for example, through local communication devices 88 and 82 shown in Figure 1 and described herein with reference thereto, wherein the device 88 is is receiving and device 82 is transmitting. A local signal may be received (eg, at action 1007), via NFC, for example, and can be received (eg, at action 10078) when the mobile phone is passed through a reader (eg, device 88).
In different modalities, different types of actions are requested (eg, in action 1009), authorized (eg, in action 1018) and allowed (eg, in action 1030). Some modalities are limited to particular types of actions. For example, some actions involve providing access, physical or otherwise, and some modes involve transferring funds or money from one entity or account to another, for example. As a specific example, in some modalities, the action is the granting of access to a computer to the information
<img file="MX348109B_D0123.tif" />
IMPI iNjrmrro mjuucano
OF ENOHETY
IMDUSTMAL is electronically stored, and the person attempting the action (eg, requesting authorization in action 1009) is attempting computer access to the electronically stored information. Method 1000 modes can be used to provide access to the computer, for example, in place of a password, if the password has been forgotten, or in addition to the password, for example, to provide and add a level of security in case of an unauthorized user has obtained the password. In some such modalities, the first message (eg, in action 10158) may include the description of the access to the computer or the electronically stored information for which authorization is requested.
In another example, the action is to grant physical access to a controlled space and the person attempting the action (eg, requesting authorization in action 1009) is attempting physical access to the controlled space. Physical access can be controlled, for example, to a building, part of a building, a floor of a building, a room, an enclosure, a reserved area, a storage area, a parking area, a path, furniture such as a desk or filing cabinet, a safe, etc. In such modalities physical access may be allowed {eg, in action 1030), for example, by electronically unlocking or opening a door, access port, or
- 153 -
<img file="MX348109B_D0124.tif" />
IMPI
MEXICAN INSTITUTE
Dt LA ntORIMD
INDUSTRIAL compartment, by allowing an elevator to reach a particular floor, etc. In such embodiments, the first message (eg, in action 10158) may include a description of the room, floor, building, space, etc., for which access authorization is requested.
In another specific example, in particular modalities, the action (eg, requested in action 1009, authorized in action 1030, or a combination thereof) is (or includes) a financial transaction, the first message (eg, sent in action 1015) includes the amount of the transaction, and the second message (eg, received in action 1021) includes an authorization (eg, from action 1018) of the transaction. Some such modalities include (eg, in action 1006), receiving from the person who has the authority to authorize the action, for example, through the Internet website (eg, website 65 through the Internet). Internet 10 shown in Figure 1) or a mobile phone network (eg, 40), or both, an identification of a threshold monetary value of the transactions. In some modalities, the first message is sent (eg, in action 1015) for transactions that exceed the threshold, and transactions below the threshold are approved or authorized without sending the first message (eg, without actions 1012 to 1027) .
Also in some modalities, the transaction is (or
<img file="MX348109B_D0125.tif" />
IMPI
INSTITUTO MEXICANO M LA noniDIAD a bank account and the authorization of the action is a
- 154 includes) the withdrawal or debit of the person who has the authority to be an authorized user of the account. Thus, in some modalities, the user {eg, 21 to 23 shown in Figure 1) can choose {eg, by selecting or indicating the criteria received in action 1006) to be notified through his telephone {eg, 41 a 43) of large withdrawals or debits {eg, in action 1015), but not to be disturbed {eg, by a first message sent in action 1015) with smaller withdrawals or debits {eg, routine). Furthermore, in various modalities, the user must authorize {eg, in action 1018) the largest transactions, thus protecting the user, the bank (or other financial institution), or both, from losses that result from unauthorized withdrawals or debits.
Returning now to Figure 4A, this flow chart illustrates an exemplary method for providing positional awareness of, for example, a particular individual using mobile phones. In the illustrated embodiment, the method 400 includes actions to obtain (action 416) and store (action 420) the location information. Particular modalities include (at least) the action of obtaining (action 416) or storing (action 420) (or both) at least one location coordinate defining at least one region of interest, for example. Such location coordinates can be (or include) system coordinates
<img file="MX348109B_D0126.tif" />
IMPI
INSTHVTO MIXJCANO PC LA FROMIDAP INDUSTRIAL e.g. latitude and elevation, coordinates o
- 155 global positioning (GPS), longitude, grid coordinates, distances to one or more known points, Cartesian coordinates, polar coordinates, or the like, as examples.
A region of interest can be defined by one of such coordinates and the distance from it, by more than one coordinate and a distance from it (eg, by two coordinates that define a line segment and a distance from it), or by three, four, or more coordinates, which can define a perimeter or parcel of land (eg, four coordinates that define corners of squares or rectangles), as examples. In other modalities, street addresses can be used. Information or location coordinates that define regions of interest can be obtained, for example, from a third party (eg, 31 to 33 shown in Figure 1), from an Internet website, via the Internet 10 , of a user (eg, from 21 to 23), or the like. In some embodiments, there may be multiple locations, regions of interest, coordinates, or the like, which may correspond to different regions of interest, which may be of interest for different reasons, in certain embodiments.
In the illustrated embodiment, the method 400 also includes monitoring the location of a first mobile phone.
- 156 IMPI
ΙΝΠΤΤυΤΟ AUUUCANO
OF THE nOPIBMD
INDUSTRIAL
<img file="MX348109B_D0127.tif" />
(action 424), which can be owned by a particular individual, for example. Such monitoring can be - for example, continuous, at regular time intervals, during certain hours of the day, or the like, which can be selected by the user in some modalities. In some modalities, the frequency of monitoring can be increased if the particular individual is near a region of interest. In the illustrated embodiment, method 400 also includes evaluating whether the first phone is near or within a region (action 428), for example, of interest, and providing an alarm (action 432), for example, through a second mobile phone, when the first mobile phone passes into a region of interest, or within a predetermined distance of a region of interest. Such predetermined distance may be, for example, 25 feet, 50 feet, 75 feet, 100 feet, 200 feet, 300 feet, 500 feet or the like, and may be user selectable, in some embodiments. In addition, or instead of alarming the second phone, in some embodiments, an alarm may be provided (eg, at action 432) at the first mobile phone, which may be the same or a different alarm, in different modes.
An alarm may be provided (eg, at action 432) in a similar manner to other alarms described herein, for example, at action 254 shown in Figure.
- 157 -
<img file="MX348109B_D0128.tif" />
IMPI Mexican institute
DtUnOfWMD
IHDUmUAl
9, or it may be similar to the third party notification (action 333) or the first message (eg, sent in action 315) shown in Figure 10, or a combination thereof. An alarm (provided in action 432) can include a typical phone ringing sound, making a particular ringing tone, a text or SMS message, a vibration, a synthetic voice message, one or more lights, or a combination themselves, as examples. The nature of the alarm (eg, provided in action 432) may be user selectable, in many modes, for example, in an action similar to action 205, action 306, or both. In some embodiments, the alarm (eg, provided in action 432) can identify the first telephone, the person to whom the first telephone is assigned, the telephone number of the first telephone, the name of the region of interest, the reason why the region is of interest, how far from the region of interest the first phone is located, the uncertainty associated with such information, etc.
In some such modalities, for example, the location coordinates (eg, obtained in action 416, stored in action 420, or both) is for a reported residence or a reported sex offender. In some details, the first phone (eg, whose location is monitored in action 424) can be assigned or
158
IMS IIIUIO MEXICAN
<img file="MX348109B_D0129.tif" />
<img file="MX348109B_D0130.tif" />
IMPI used by a child, and the second phone (eg, which receives the alarm in action 432) can be assigned to a parent or guardian of the child. Thus, the child's parent or guardian can be alerted (eg, automatically) if the child enters or approaches the residence of a registered sex offender. In some modalities, the alarm (eg, provided in action 432) may indicate that the region of interest is the residence of a registered sex offender, in some modalities, details of the offender are included, crimes for which he has been convicted or accused , a description of him, a photograph of him, etc.
In some such modalities, the registered residence of a number of registered sex offenders (eg, in action 416) can be obtained, for example, through the Internet 10, for example, from one or more government websites, which they can be converted into coordinates, for example, the demarcation of the property boundaries, the center of the property or the like. The location information can be stored (eg, in action 420), for example, or server 15, in store 64, by software module 61 or the like, which can be temporarily stored, for example, for the area in which is located the first mobile phone. Other information included in the alarms (eg, provided in action 432) can also be obtained from the website (s), in action 416,
<img file="MX348109B_D0131.tif" />
interest ions of the or both.
In other modalities, they can be for other threats, such as traffic hazards, pollution or toxic waste sites, areas of high radioactivity, industrial areas, neighborhoods with high crime rates, areas controlled by criminals, quarantined areas, areas with infestations. of insects, areas with high drug use or trafficking, bars, adult establishments, houses of prostitution, gambling establishments, areas under construction, areas with severe weather, war threat combat areas, prohibited areas, foreign territory, private lands, high tide areas, rough water areas, shallow water areas, coastlines, or other marine navigation hazards, etc. In addition to protecting children, modalities can notify (eg, in action 432), protect, or both, of individuals with substance abuse, alcohol or gambling problems, police officers, firefighters, test officers, officials parolees, census workers, soldiers, supply personnel, vendors, missionaries, sailors, etc. In some embodiments, the alarm (eg, provided in action 432) closes may be provided on the first telephone, in addition to or in place of the second telephone.
In some modes, special software can
160
<img file="MX348109B_D0132.tif" />
IMPI Mexican institute
OF THE FROfraDAJD
INDUSTRIAL be provided on one or more mobile phones to perform certain method actions (eg, method 400). For example, a number of embodiments of the method 400 further include, for example, the acts of providing a first software module for mobile phone for installation on the first mobile phone (action 404), providing a second software module for Telefo not mobile for installation on the second mobile phone (action 408), or both. In some such embodiments, the first mobile phone software module (eg, provided in action 404) includes programming instructions for mini-monitoring (eg, in action 424) of the location of the first mobile phone, eg, in possession. of the particular individual. And in some embodiments, the second mobile phone software module (eg, provided in action 408) includes programming instructions for the provision of the alarm (eg, in action 432, for example, via a second mobile phone when the first mobile phone passes a region of interest or within the predetermined distance of the region of the region of interest. In some embodiments, the first mobile phone software module (eg, provided in action 404), the second mobile phone software module (eg, provided in action 408), or both, may be similar in at least some respects. , or part of the second software module 72, described
161
<img file="MX348109B_D0133.tif" />
IMPI
INSTITUTO MEXICANO DC LA PROPERTY INDUSTRIAL in the present, for example.
In a number of such embodiments, the third software module (eg, obtained or provided in action 412) further contains instructions for downloading (eg, in action 404), for example, via mobile phone network 40, for example, for the first mobile phone, the first mobile phone software module. In many such embodiments, the first mobile phone software module (eg, provided or downloaded in action 404), the third software module (eg, obtained or provided in action 412), or both, include programming instructions for monitoring (eg, at action 424) of the location of the first mobile phone, eg, in the possession of the particular individual. Furthermore, in some such embodiments, the third software module (eg, obtained or provided in action 412) further contains instructions for downloading (eg, in action 408) for example, via mobile phone network 40, for example, for the second mobile phone, the second mobile phone software module.
In many such embodiments, the second mobile phone software module (eg, obtained or provided in action 408) includes programming instructions for the provision of the alarm (eg, in action 432) for example, through the second mobile phone
- 162 -
<img file="MX348109B_D0134.tif" />
IMPI
INSTITUTO MEXICANO MLAMOniDAD INDUSTRIAL when the first mobile phone passes the region of interest or within the predetermined distance of the region of interest, AND in particular modalities, the first software module for mobile phone, (eg, obtained or provided in action 404 ) also or instead includes programming instructions for the provision of the alarm (eg, in action 432), or instead via the first mobile phone when the first mobile phone passes into the region of interest or within the predetermined distance of the region of interest.
Furthermore, in many modalities, at least a plurality of users (eg, 21 to 23) enter (eg, in action 416), for example, through the Internet website (eg, 65) in at least one coordinate of A location that defines at least one region of interest. Thus, in different embodiments, some or all of the regions of interest may be of specific interest to the particular user. On the other hand, in some modalities the third software module (eg, obtained or provided in action 412), also contains instructions to obtain from a third party website (eg, from one or more third parties 31 to 33) data with the which determine at least the location coordinates that define at least one region of interest. An example of such data includes street address, which can be used to determine longitude and latitude or GPS coordinates, for
- 163 -
<img file="MX348109B_D0135.tif" />
IMPI Mexican institute DSLAHOntDAD IMDVSTUAL example. In some modalities, for example, the third party's website contains the domicile or residence location reported for a plurality of registered sex offenders, there is at least a plurality of regions of interest (eg, monitored in action 424), and at the least a plurality of the regions of interest surround at least one reported residence of the registered sex offender, for example.
Some of all the actions of method 400, or other methods described herein, may be repeated.For example, in many embodiments, location information (eg, action 416) may be retrieved and stored (eg, action 420) periodically, when the first phone moves to another area, when new information becomes available, or the like. Also, in some embodiments, the location information that is stored (eg, in action 420) can be time consuming (eg, in actions 424 and 428 and if appropriate, in action 432) between instances when obtaining the location information (eg, in action 416). In a number of different embodiments, the illustrated or described actions may be combined in various combinations or are other actions or features (or both) herein.
Referring now to Figures 3 and 4, in a particular embodiment as an example, the MANAGEMENT OF
- 164 -
<img file="MX348109B_D0136.tif" />
IMPI
MKUCANO INSTITUTE Di LA MtaniDAD
INDUSTRIAL
SECURE INFORMATION (SMIM) includes a platform for System 100 that allows mobile phone users (eg, 21 to 23) to access certain personal information through their mobile phone (eg, 41 to 43), even when they are not there is a signal or Internet connection for the cell phone (eg, from the cell phone network 40). In this mode, SMIM includes one or more code blocks that provide the structure and basis of the system 100 and comprise the functionality of definition standards under which definition security takes place, for communication between components and various application cores. of software.
In certain modalities, the SMIM includes MICRO AGENT and WEB SERVICES. In this example of a modality, the MICRO AGENT operates on mobile phones, and is an example of the second software module 72, or a portion thereof, and WEB SERVICES is an example of the first software module 61, or a portion of the In this example, the WEB SERVICES is a block of codes or software that operates on the server 15 and that communicates with or exchanges data with the MICRO AGENT on the phones, the websites 65 and the secure store 64, for example , WEB SERVICES can provide or allow authentication, communication, protocol definition, data integrity audit, prevention of unauthorized access, and so on, and can allow access to the website 65 from the Internet
165
<img file="MX348109B_D0137.tif" />
IMPI
INtrnUTOMUlCANO M LA mjouwap INDUrnilAL
10.
In some embodiments, local storage (eg, folder 76 or mobile phone 41) allows the application (eg, second software module 72) to store information (eg, portions 78 and 79 of information) or the phone (eg, 41) which can provide fast access, reduces dependence on the network (eg, mobile phone network 40, the Internet 10, or both) and can reduce the total cost of ownership by limiting the amount of data communication over the mobile phone network 40 that takes place (eg, at the expense of the user 21). In some embodiments, the data (eg, portions 78 and 79) on the phone (eg, 41) is synchronized with the data on the server 15 to ensure that the user (eg, 21) has access to up-to-date information on both their telephone (eg, 41) and the web (ie, Internet 10, which can be accessed, at least by user 23, through computer 13, for example.
Still another embodiment implements a method of eliminating the need to carry a card. This example method includes replacing an old mobile phone component with a new component. In some embodiments, the new component includes at least one of a backrest, a battery cover, a battery, and a case for the mobile phone, as examples. In some modes, the new component includes a code area
166
IMPI
INSTITUTO MEXICANA DE LA MONUMXAD INDUSTRIAL magnetic configured to produce a magnetic code to be read by the card reader (eg, device 88) when the phone is passed in proximity to the card reader. Another modality can use a barcode, as another example.
The benefits, other advantages and solutions to the problems have been described herein with reference to the specific embodiments. However, the benefits, advantages, solutions to the problems and element (s) that may cause the benefits, advantages or solutions to be presented or become more pronounced, should not be interpreted as critical, required or essential characteristics or elements of the claims. . Reference to an element in the singular is not intended to mean one and only one unless explicitly defined so, but rather one or more. As used herein, the terms comprises, comprising, or a variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus comprising a list of items, does not include only those elements, but may include other elements not expressly listed or inherent in such process, method, article or apparatus. Furthermore, none of the items described herein are required for practice unless expressly described as essential or critical. In addition,
167
<img file="MX348109B_D0138.tif" />
IMPI
ΜΤΠνΤΟ MEXICAN
OF THE MbAnUAD
INDVJTUAL skilled in the art will recognize that changes and modifications can be made to exemplary embodiments without departing from the scope of the present invention. Thus, the different embodiments may include different combinations, arrangements and / or orders of the elements or of the processing steps described herein, or as shown in the drawing figures. For example, the various components, elements or process steps can be configured in alternative ways depending on the particular application or in consideration of cost. These and other changes or modifications are intended to be included within the scope of the present invention, as set forth in the following claims.
168
<img file="MX348109B_D0139.tif" />
IMPI and Mexican wrmrro
M LA BROMBDAD INDUSTRIA!
Contents159
165 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84 Sheet 85 Sheet 86 Sheet 87 Sheet 88 Sheet 89 Sheet 90 Sheet 91 Sheet 92 Sheet 93 Sheet 94 Sheet 95 Sheet 96 Sheet 97 Sheet 98 Sheet 99 Sheet 100 Sheet 101 Sheet 102 Sheet 103 Sheet 104 Sheet 105 Sheet 106 Sheet 107 Sheet 108 Sheet 109 Sheet 110 Sheet 111 Sheet 112 Sheet 113 Sheet 114 Sheet 115 Sheet 116 Sheet 117 Sheet 118 Sheet 119 Sheet 120 Sheet 121 Sheet 122 Sheet 123 Sheet 124 Sheet 125 Sheet 126 Sheet 127 Sheet 128 Sheet 129 Sheet 130 Sheet 131 Sheet 132 Sheet 133 Sheet 134 Sheet 135 Sheet 136 Sheet 137 Sheet 138 Sheet 139 Sheet 140 Sheet 141 Sheet 142 Sheet 143 Sheet 144 Sheet 145 Sheet 146 Sheet 147 Sheet 148 Sheet 149 Sheet 150 Sheet 151 Sheet 152 Sheet 153 Sheet 154 Sheet 155 Sheet 156 Sheet 157 Sheet 158 Sheet 159 Sheet 160 Sheet 161 Sheet 162 Sheet 163 Sheet 164 Sheet 165
105 members in 15 offices
Priority claims11
| Document | Office | Kind | Date |
|---|---|---|---|
| 201261602072 | United States of America | P | |
| 61602072 | United States of America | – | |
| 13531177 | United States of America | – | |
| 201213531177 | United States of America | A | |
| 2013027500 | United States of America | W | |
| 13531177 | – | – | – |
| 61602072 | – | – | – |
| PCTUS2013027500 | – | – | – |
| US201213531177 | – | – | – |
| US201261602072P | – | – | – |
| WO2013US27500 | – | – | – |
Members105
| Document | Office | Kind | |
|---|---|---|---|
| AU2007267898A1 | Australia | A1 | |
| CA2650852A1 | Canada | A1 | |
| WO2007139909A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2007293202A1 | United States of America | A1 | |
| US2008081601A1 | United States of America | A1 | |
| US2008108324A1 | United States of America | A1 | |
| US2008109370A1 | United States of America | A1 | |
| WO2007139909A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2008133930A1 | United States of America | A1 | |
| US2008167060A1 | United States of America | A1 | |
| US2008214111A1 | United States of America | A1 | |
| WO2008109436A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2021960A2 | European Patent Office (EPO) | A2 | |
| AU2009228017A1 | Australia | A1 | |
| CA2719794A1 | Canada | A1 | |
| WO2009121046A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2009265552A1 | United States of America | A1 | |
| KR20100126850A | Republic of Korea | A | |
| MX2010010620A | Mexico | A | |
| IL208375D0 | Israel | D0 | |
| EP2286566A1 | European Patent Office (EPO) | A1 | |
| US7920851B2 | United States of America | B2 | |
| CN102037708A | China | A | |
| US2011145564A1 | United States of America | A1 | |
| US2011151903A1 | United States of America | A1 | |
| ZA201007633B | South Africa | B | |
| EP2021960A4 | European Patent Office (EPO) | A4 | |
| AU2007267898B2 | Australia | B2 | |
| US8225380B2 | United States of America | B2 | |
| US8260274B2 | United States of America | B2 | |
| US8280359B2 | United States of America | B2 | |
| US2012270560A1 | United States of America | A1 | |
| SG189710A1 | Singapore | A1 | |
| CA2864030A1 | Canada | A1 | |
| WO2013126832A1 | World Intellectual Property Organization (WIPO) | A1 | |
| UA103021C2 | Ukraine | C2 | |
| US2013252585A1 | United States of America | A1 | |
| CA2650852C | Canada | C | |
| AU2013222127A1 | Australia | A1 | |
| US8862129B2 | United States of America | B2 | |
| SG11201404627VA | Singapore | A | |
| PH12014501888A1 | Philippines | A1 | |
| PH12014501888B1 | Philippines | B1 | |
| CA2909613A1 | Canada | A1 | |
| KR20140135997A | Republic of Korea | A | |
| WO2014189882A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2817984A1 | European Patent Office (EPO) | A1 | |
| US8965416B2 | United States of America | B2 | |
| US2015072654A1 | United States of America | A1 | |
| US9154612B2 | United States of America | B2 | |
| AU2014268732A1 | Australia | A1 | |
| EP2021960B1 | European Patent Office (EPO) | B1 | |
| SG11201506971RA | Singapore | A | |
| EP2817984A4 | European Patent Office (EPO) | A4 | |
| KR20160009569A | Republic of Korea | A | |
| US2016044473A1 | United States of America | A1 | |
| EP2984863A1 | European Patent Office (EPO) | A1 | |
| PH12015502384A1 | Philippines | A1 | |
| PH12015502384B1 | Philippines | B1 | |
| MX2014010093A | Mexico | A | |
| US2016135020A1 | United States of America | A1 | |
| EP3023894A1 | European Patent Office (EPO) | A1 | |
| AU2013222127B2 | Australia | B2 | |
| IL208375A | Israel | A | |
| ZA201405967B | South Africa | B | |
| CA2987667A1 | Canada | A1 | |
| CA3187885A1 | Canada | A1 | |
| WO2016197143A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2984863A4 | European Patent Office (EPO) | A4 | |
| KR101690850B1 | Republic of Korea | B1 | |
| US9572033B2 | United States of America | B2 | |
| CA2864030C | Canada | C | |
| HK1220855A1 | Hong Kong, China | A1 | |
| MX348109BThis record | Mexico | B | |
| US9680803B2 | United States of America | B2 | |
| US9686660B2 | United States of America | B2 | |
| MY163154A | Malaysia | A | |
| US9775012B2 | United States of America | B2 | |
| EP3023894B1 | European Patent Office (EPO) | B1 | |
| AU2016271535A1 | Australia | A1 | |
| US9848081B2 | United States of America | B2 | |
| EP3304842A1 | European Patent Office (EPO) | A1 | |
| US2018124240A1 | United States of America | A1 | |
| US2018146088A1 | United States of America | A1 | |
| PH12017502211A1 | Philippines | A1 | |
| AU2014268732B2 | Australia | B2 | |
| MY166473A | Malaysia | A | |
| EP2984863B1 | European Patent Office (EPO) | B1 | |
| EP3304842A4 | European Patent Office (EPO) | A4 | |
| HK1253669A1 | Hong Kong, China | A1 | |
| US10412215B2 | United States of America | B2 | |
| US2019281465A1 | United States of America | A1 | |
| MY172205A | Malaysia | A | |
| US2019373107A1 | United States of America | A1 | |
| US10778837B2 | United States of America | B2 | |
| CA2719794C | Canada | C | |
| US2020412867A1 | United States of America | A1 | |
| CA2909613C | Canada | C | |
| US10992802B2 | United States of America | B2 | |
| US11089478B2 | United States of America | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 348109
- Publication, DOCDB
- 348109
- Publication, EPODOC
- MX348109
- Application
- 2014010093
- Application, DOCDB
- 2014010093
- Application, EPODOC
- MX20140010093
Titles3
- Spanish
- SISTEMAS Y MÉTODOS PARA LAS COMUNICACIONES MÓVILES DE VOZ ENCRIPTADAS.
- English
- SYSTEMS AND METHODS FOR ENCRYPTED MOBILE VOICE COMMUNICATIONS.
- English
- SYSTEMS AND METHODS FOR MOBILE ENCRYPTED VOICE COMMUNICATIONS.
Classification
- CPC, 21
- H04W4/14
- H04W12/08
- G06F21/33
- G06F21/35
- G06F21/43
- G06F21/6272
- G06F2221/2107
- G06F2221/2117
- H04L63/0428
- H04L63/0846
- H04L63/101
- H04M3/42382
- H04M7/0078
- H04M2203/609
- H04W88/16
- H04M1/72403
- H04M1/72436
- H04W12/068
- H04W4/12
- H04W12/06
- H04W12/0608
- IPC, 1
- H04W4 14