Computing device for enabling conformance to legislative requirements for mobile devices and a method for controlling the same
Abstract
Provided are a method and a mechanism for dynamically controlling the performance of communication-related operations of a mobile device in accordance with legislative requirements of the particular location of the mobile device and the location of the ccmputing device with which it is to communicate, and also in accordance with, communication requirements of application programs at either end of the communication link. A first use of the invention is for ensuring conformance of a mobile device's communications to the cryptographic requirements of different countries, even when the device crosses a country boundary during communication.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
21 claims: 21 independent, 0 dependent
- 1一種用以提供服務至第一計算裝置上應用程式之軟體元件,包含控制第一計算裝置之操作以執行諸程序,藉由得到法定要件資訊以回應至少第一計算裝置之國家位置識別,該資訊有關於上述國家或諸國家之第一計算裝置之至少一通訊操作;以及根據得到之資訊及根據第一計算裝置上至少一第一應用程式之通訊要件,而選擇或證實選擇一操作序列,用以執行至少一通訊操作。
- 2如申請專利範圍第1項之軟體元件,其中根據第二計算裝置上一第二應用程式之通訊要件,而在第一計算裝置上或是在與第一計算裝置通訊之第二計算裝置上執行選擇證實。
- 3如申請專利範圍第2項之軟體元件,其中滿足第一及第二應用程式通訊要件之操作序列選擇或證實選擇發處理時,通訊連線即中斷。
- 4如申請專利範圍第1至3項中任一項之軟體元件,其中根據第二計算裝置上國家位置之法定要件,而在第一計算裝置上或是在與第一計算裝置通訊之第二計算裝置上執行選擇證實。
- 5一種用以提供通訊服務至第一計算裝置上應用程式之軟體元件,包含控制第一計算裝置之操作以執行諸程序,藉由得到資訊以回應至少第一計算裝置之國家位置識別,用以識別上述國家或諸國家之允許密碼元件;以及根據得到之資訊及根據第一計算裝置上至少一第一應用程式之通訊要件,而選擇或證實選擇一密碼元件,用以加密及解密資料。
- 6如申請專利範圍第5項之軟體元件,其中根據第二計算裝置上一第二應用程式之通訊要件,而在第一計算裝置上或是在與第一計算裝置通訊之第二計算裝置上執行選擇證實。
- 7如申請專利範圍第6項之軟體元件,其中滿足第一及第二應用程式要件之密碼元件選擇或證實選擇發處理時,通訊連線即中斷。
- 8如申請專利範圍第5至7項中任一項之軟體元件,其中根據第二計算裝置上國家位置之法定要件,而在第一計算裝置上或是在與第一計算裝置通訊之第二計算裝置上執行選擇證實。
- 9如申請專利範圍第5至7項中任一項之軟體元件,當建立第一計算裝置上一應用程式與一遠地應用程式之通訊連線時,用以啟始第一計算裝置國家位置之識別。
- 10如申請專利範圍第9項之軟體元件,用以重覆國家位置識別之啟始,以回應通訊期間之諸事件。
- 11如申請專利範圍第10項之軟體元件,其中該等預設事件包含一指令處理以加密或解密資料。
- 12如申請專利範圍第10項之軟體元件,用以控制一行動電話之操作,其中該等預設事件包含從一行動網路存取節點接收一新細胞識別碼。
- 13如申請專利範圍第11項之軟體元件,用以控制一行動電話之操作,其中該等預設事件包含從一行動網路存取節點接收一新細胞識別碼。
- 14如申請專利範圍第10項之軟體元件,其中僅當國家位置改變時,才重覆得到資訊用以識別許之密碼元件,以及選擇或證實選擇一密碼元件該等步驟。
- 15如申請專利範圍第11項之軟體元件,其中僅當國家位置改變時,才重覆得到資訊用以識別許之密碼元件,以及選擇或證實選擇一密碼元件該等步驟。
- 16如申請專利範圍第12項之軟體元件,其中僅當國家位置改變時,才重覆得到資訊用以識別許之密碼元件,以及選擇或證實選擇一密碼元件該等步驟。
- 17如申請專利範圍第13項之軟體元件,其中僅當國家位置改變時,才重覆得到資訊用以識別許之密碼元件,以及選擇或證實選擇一密碼元件該等步驟。
- 18一種用以控制第一計算裝置操作之方法,包含:得到法定要件資訊以回應至少第一計算裝置之國家位置識別,該資訊有關於上述國家或諸國家之第一計算裝置之至少一通訊操作;以及根據得到之資訊及根據第一計算裝置上至少一第一應用程式之通訊要件,而選擇或證實選擇一操作序列,用以執行至少一通訊操作。
- 19一種用以控制第一計算裝置操作之方法,包含:得到資訊以回應至少第一計算裝置之國家位置識別,用以識別上述國家或諸國家之允許密碼元件;以及根據得到之資訊及根據第一計算裝置上至少一第一應用程式之通訊要件,而選擇或證實選擇一密碼元件,用以加密及解密資料。
- 20一種行動計算裝置,包含軟體用以控制裝置之操作,以確保符合裝置目前位置之法定要件,軟體控制裝置以執行諸程序;藉由得到法定要件資訊以回應至少第一計算裝置之國家位置識別,該資訊有關於上述國家或諸國家之行動計算裝置之至少一通訊操作;以及根據得到之資訊及根據行動計算裝置上第一應用程式之通訊要件,而選擇或證實選擇一操作序列,用以執行至少一通訊操作。
- 21一種計算裝置,用以與行動計算裝置交互操作,計算裝置包含軟體用以控制計算裝置之操作,以確保符合計算裝置位置及行動計算裝置目前位置之法定要件,軟體控制裝置以執行諸程序:藉由得到有關於上述計算裝置之國家位置之至少一通訊操作法定要件資訊,及有關於計算裝置之國家位置之至少一通訊操作法定要件,以回應行動計算裝置之國家位置識別;以及根據得到之資訊及根據行動計算裝置上第一應用程式之通訊要件,而選擇或證實選擇一操作序列,用以執行至少一通訊操作。
Independent claims21
72 paragraphs, as filed
Computing device and control method for mobile device to make it meet statutory requirements
<u>Friendship category</u>
The present invention relates to mobile computing, and in particular, to a mechanism that can modify the operation of a mobile device when it crosses a national border, so as to maintain compliance with legal requirements of different countries, such as password restrictions or other specific regional communication requirements.
<u>Background of the invention</u>
Different countries have different laws to regulate the allowed strength and/or password types, including differences between European countries. Some competent authorities require that legal signal interception is still technically feasible. For example, a country allows the use of RSA cryptographic algorithms with 512-bit keywords but cannot use 1024-bit keywords, or a country allows the use of DES but does not allow the use of 3DES or uses up to 128-bit keywords Length of any cryptographic algorithm. There are also some countries, for example, on the prohibited list, so it is not allowed to exchange cryptographic information with any company in that country.
Mobile devices such as mobile phones and personal digital assistants (PDAs) for communication can now execute applications in addition to exchanging voice data. Mobile phones are often used as portable computers to connect to the Internet to exchange data with other computers. When performing any sensitive transactions connecting credit card purchases or exchanging secret information, although encryption and decryption is a good idea, the encryption of data flow is particularly important in wireless communication, because wireless communication is easier to intercept than communication transmitted via a wired connection.
When any company or individual wants to exchange encrypted data in a mobile environment, and when any company sells mobile computing devices, they will immediately encounter the following problems, such as how to ensure that users of mobile computing devices and those who exchange data with them are at each end of the communication chain Meet the legal password requirements of these countries. This is a special problem, because mobile devices can move across countries, so fixed solutions are not enough. For example, a bank connected to an Internet computer may also encounter this problem. It allows applications running on mobile devices to communicate with applications running on the banks customer system, and mobile users also encounter this problem. If the banks international business needs to be approved by the statutory authorities of each country, the bank needs a mechanism to ensure compliance with the laws of each country.
US Patent No. 5781628 discloses selectively restricting communication encryption in telecommunication networks based on encryption restrictions in special countries. U.S. Patent No. 5781628 only discloses that encryption is not allowed when necessary, and it has not considered the more clever password requirements currently required by many countries. For example, as described above, if the keyword bit length is not greater than the preset maximum value, the use of cryptographic algorithms is allowed, or only certain types of cryptographic algorithms are not allowed.
In addition, US Patent No. 5781628 does not disclose any mechanism that can make the selected cryptographic components achieve high performance after referring to the specific requirements of the communication application program executed on the communication device. In fact, U.S. Patent No. 5781628 does not include any mechanism for disclosing whether encryption is required for realization. Although this is not important for the simple determination of US Patent No. 5781628 in deciding whether to (according to the strict statutory requirements of certain countries) to suspend all password functions of voice calls, it does not provide sufficient support for communication with applications. The application requires a minimum level of security. US Patent No. 5781628 also does not consider related password restrictions and application requirements, and whether to use a limited device level to terminate the communication connection or continue communication.
The password requirement is one of many examples of differences between the laws of different countries, and therefore also an example of legal requirements, which benefits from a method and mechanism that can ensure compliance with different laws of mobile devices. In another case, the legislation prohibits computing device users from using certain technologies in a prohibited country (for example, if the technology is related to national defense). In another case, the statutory language must be used by financial institutions for electronic transactions.
<u>Invention summary</u>
The present invention provides a method and mechanism to dynamically control the operating performance of the mobile device according to the legal requirements of the special location of the mobile device and the requirements of the application program at any end of the communication chain. Control operations are preferably communication-related operations such as encryption and decryption or digital signature applications.
In the first concept, the present invention provides a method and mechanism that can be used to automatically exchange password strength and/or type when a mobile computing device crosses a national border, or to terminate the connection of the mobile device in a controlled manner, which is conducive to the use of The communication of mobile devices meets the password requirements of different countries.
Determine the location of a mobile computing device in a country, and then obtain information to identify the strength or type of the allowed device in the country in the location. For example, a specific allowed or forbidden algorithm name or keyword bit length can be used to indicate the allowed password strength or type. The information provided can also identify specific communication prohibitions or restrictions in other countries.
Then select a cryptographic component that can implement an algorithm to encrypt the chain according to the requirements of the application at either end of the communication and the information on the password restriction, or to interrupt the communication connection or enable the device or its encryption function stop.
In the first embodiment, the present invention is implemented in the application service component of the first computing device. The application service component responds to the identification of at least one country location of the first computing device to provide information that can be used to identify the cryptographic component. Use in the above-mentioned countries without violating legal restrictions. The application service component can select or verify the selection of a cryptographic component based on the obtained information and the first application program located on the first computing device to encrypt and decrypt the chain.
If the first computing device initiates communication, it then preferably initiates the selected authentication based on the communication requirements of the second application located on the second computing device in order to exchange links. The initial confirmation referring to the second application requirement only needs to send a request to the second computing device to generate a communication channel, or use an explicit confirmation request.
The step of obtaining information to identify permitted cryptographic components, or the step of selecting or verifying the selection of a cryptographic component, or the subsequent verification step performed on the first or second computing device before the encryption chain is exchanged, will also consider the second The password requirements for the country location of the device to ensure compliance with the country requirements for the location of the first and second devices.
The invention dynamically selects the password function and refers to the application requirements when considering whether to disconnect the connection, and has significant advantages compared with the mechanism that only relies on the basic communication stack to determine whether to start or stop the password algorithm. The present invention according to the preferred embodiment implements the selection mechanism in the application layer of the layered model of the communication system function (such as the OSI model), and enables the application to coordinate the cryptographic function by referring to the dynamic elements. However, the implementation in the communication layer The selection mechanism cannot.
Therefore, considering the application requirements and making the application rate help coordinate those cryptographic algorithms that can be used or disconnected, in order to achieve a coordinated address that is acceptable for special applications. When the communication device crosses the national border, some applications can use different encryption algorithms or no encryption to continue communication and application execution. However, if the specific requirements of the communication channel cannot be maintained, other applications will request disconnection. Other rules require that a device be stopped, and in all of these cases, the appropriate action can be taken by referring to the application requirements.
The mechanism implemented in the communication layer must also be specified by the special communication support (for example, TCP or GSM specified). However, the service provided by the present invention can be used more widely because it is not limited to the special communication support layer.
The application service component according to the present invention can be provided as a computer program product, including computer readable program code recorded in a computer readable recording medium, or integrated with a computing device.
In the second concept of the present invention, a method for controlling the operation of a first computing device is provided, which includes: responding to at least the country location identification of the first computing device to obtain legal requirement information, which is at least the same as that of the first computing device in the above-mentioned country A communication operation is related; and based on the obtained information and the communication requirements of at least the first application program located on the first computing device, an operation sequence is selected or confirmed to perform at least one communication operation.
In the third concept, the present invention provides a mobile computing device, including: software for controlling the operation of the device to ensure compliance with the legal requirements of the current location of the device; At least one statutory element information related to the communication operation in response to at least the national location identification of the mobile computing device, and based on the obtained information and the communication element of at least the first application located on the mobile computing device, select or confirm the choice of one The operation sequence is used to perform at least one communication operation.
In the fourth concept, the present invention provides a computing device for interoperating with a mobile computing device. The computing device includes software for controlling the operation of the computing device to ensure compliance with the legal requirements of the location of the computing device and the current location of the mobile computing device. Software control The device executes various procedures and responds to the country of the mobile computing device by obtaining the legal requirement information related to at least one communication operation of the above-mentioned national mobile device location and at least one communication operation related legal requirement of the country location of the computing device Location identification, and based on the obtained information and based on the communication requirements of at least the first application program located on the mobile computing device, selecting or confirming the selection of an operation sequence to perform at least one communication operation.
In the preferred embodiment of the present invention, the generation of the communication channel requires the first selection of cryptographic components to encrypt and decrypt the data transmitted on the channel. Then there is a follow-up check for the correctness of the password function, which is executed as a passive operation triggered by some preset event. This event can be a determination to identify a location that crosses a national border, which then causes the mobile device to generate an interrupt to prompt the application to check the correctness of the cryptographic components merged in the new country.
In another embodiment, an action program is used to perform a country location determination, and then a permitted password function table (or a password restriction table identifying permitted password components) is obtained, and the data is checked whenever the data is to be encrypted and transmitted .
There are many mechanisms that can be used to identify the location of a mobile device. In the mobile phone embodiment of the present invention, the phone sends a country query to the mobile network operating system in response to receiving a new broadcast cell identification code (which informs that the phone has moved ), either periodically, or whenever you want to exchange data. The mobile network operating system then manages a database retrieval operation to map the cell identification code to a specific country. In another embodiment, the Global Positioning System (GPS) is used and each time encrypted data is to be exchanged, the satellite is searched for identification The location of a device.
<u>Detailed description of the invention</u>
The present invention according to a preferred embodiment provides application services running on mobile computing devices, such as communication personal digital assistants (PDAs), laptop and palmtop computers, computing devices installed in cars, and the latest Application-oriented mobile phones and applications running on computing devices that communicate with these mobile devices.
The invention can meet the legal requirements of different countries on the strength and the type of cryptographic algorithm, it can be used to encrypt/decrypt data, and it can maintain compliance with local laws even when the mobile device crosses the national border. The present invention provides a mechanism to dynamically exchange the strength and password type used, and to interrupt the connection in a controlled manner. The purpose of referring to the country in this article is to refer to any geographic or political area that has specific password requirements or other legal requirements for communication.
FIG. 1 shows a mobile computing device 10 such as a mobile phone, which can execute many installed application programs 20. The software component installed on the mobile device includes the application service component 30, which is located in the application layer of the layered structure of the communication function (this layered structure (its specific interface can support data flow between different layers) is the standard for communication devices)). The application layer is the top layer of the seven-layer standard open system connectivity (OSI) model and other equivalent functional layer models, so it can directly provide communication management to the application. The application layer generally refers to a layer that can identify the communication direction, the transfer rate and error rate (quality of service parameters) of the application program, and any restrictions on the data syntax.
The application service component 30 may be a Java (TM) software component, which is executed in a Java Virtual Machine (JVM) environment, so as to provide peer-to-peer services of the application program at execution time. The application service component 30 may be one of several application service components provided by the application layer, but the discussion of this additional support service is not within the scope of the present invention. FIG. 1 schematically shows the layered functional structure, including the JVM 40, the operating system 50 of the device, and the basic communication support layer 60.
The mobile computing device 10 communicates with a remote computing device 90 via a cellular communication area network access point (base station) 70 and a network 80, for example. The remote system is any communication device, whether it is a mobile device or not, but in the first example, we assume that the remote system includes a wired computer system and has a fixed location in the computer network. In particular, we can imagine that the program 20 running in the mobile phone communicates with the program 20' running in the bank computer system 90. The holder of the mobile device gives instructions to transfer money from one account to another. Banks and mobile devices generally encrypt the data stream to ensure that it will not be destroyed.
When the application program 20 running on the mobile computing device 10 wants to start exchanging data with the application program 20' running on the remote system 90, a communication channel is established, which is called an object type channel. The creation of this channel includes the following steps: Specify a set of parameters for the 100 channel, including specifying the target address, assigning the channel ID, time stamp, and identifying the elements of the password, the compression program and the authentication program intended to be used in communication. The type channel is interfaced with the type compression program and authentication program and the encryptor. The application program generally specifies a set of service quality requirements of the communication channel, and the channel is created only after the application service component 30 determines that the application requirements can be met.
Now we will explain in detail the selection of the cryptographic object, the implementation type of the encryptor, under the control of the application service component, and according to the requirements of the application.
First, the mobile device determines 110 its current location. Several mechanisms can be used to determine the location. As for the mobile phone, its best to be executed by the application service component on the mobile device to start sending queries to the database, which can be accessed via a cellular network. Access, and it contains information about country location information mapping network cell identification code (cell ID). The cell ID of the local area network cell is included in the telephone query. This cell ID has been previously broadcast by the local network access point or base station. The cell ID broadcast of the base station is conventional, but the application service component on the mobile device has not yet been able to use the information. The cellular network sends the country location identification code back to the mobile device as the address for database query.
Then the application service component 30 checks 120 that the cell ID broadcast is received by the network access point to recognize when the cell ID has changed, because this will indicate that the location of the mobile device has changed. These follow-up checks will be described later.
The application service component on the mobile device then checks the 140 password requirements of the above-mentioned countries. The password restriction table for different countries should preferably be stored in the non-volatile memory table of the mobile device (such as the ROM of the mobile phone), so that the country location identification code can be used. Perform table query operations locally (the identification code is returned from the database query as a search key), and the statutory requirements table can be maintained without relying on any third party. In a special embodiment of the present invention implemented in Java, the information retrieved on the above national password restriction forms an example of Java type Locale objects.
The application server component then performs a correct check 150 of the available cryptographic algorithms while considering 160 application-specific security requirements.
For example, the application has specified a minimum security level or expected security level, such as specifying a password algorithm with special requirements (such as 3DES) or an acceptable password keyword bit length range (such as 128 bits or higher). The application service component compares the specific application requirements with the password restriction table for the location of the special device, and the password structure and type of the available password components. This set of available cryptographic components meets all the requirements of the application and recognizes that the legal requirements are valid, and 170 a special one is selected.
In some mobile devices such as PDAs, memory resources are limited, so it is best not to store the password restriction table of each country on the mobile device itself. Therefore, or in order to allow different users to use the same mobile device without reducing security, the current legal requirements can be maintained without the need to update the mobile device itself. The restriction table and other communication rules can be set in the security of the smart card. In the file, the card is inserted into the mobile device. The smart card can also store the public and secure password keywords of the mobile device user, as well as the public keywords of the previously designated communication target.
Another best method for smart cards is to request a password restriction table from the remote database by the mobile device to be used only for the country where the device is located, and then use this table to check the correctness of the password components.
After the first one of the available cryptographic components has been selected (that is, the regional legal requirements and regional application requirements can be met), the application service component sends a 180 channel request to the target application on the remote computing device 70. This request contains the specific parameters of the channel, including the identification code of the marginal person of the set of valid cryptographic components, the compression program and the authentication program, and the public password key of the sender. Public keywords are usually digitally signed in exchanges to allow subsequent authentication.
In this example, the remote target device is a large-scale network computer system, and the target application is a banking application. In this special case, if it is only because the rules may be implemented on financial institutions that support connection transaction requests, then the target system can be expected to perform greater checks than equivalent communications between applications installed on mobile phones. That is, it can be expected that the banking system will perform effective selection of cryptographic components after referring to the region restriction, which is applicable to mobile communication devices and the cryptographic restrictions on the country of its own location.
Therefore, within the scope of the present invention, a policy of only checking regional requirements is implemented, which is applicable to the current device location and current application requirements, or a policy that implements one or both of the communication device check requirements, which is applicable to the second part of the communication chain. end.
The application service component on the banks computer system determines the location of the 190 mobile communication device and responds to requests to establish a communication channel, such as capturing the displayed country location identification code, which is included in the request from the mobile phone, or Use the cell ID included in the request to generate a database query. If the location information is included in the request, the receiving application service component does not accept the call.
After obtaining the location information of the mobile device, the application service component on the target computer system retrieves 190 its own country location information (regional storage), and enters these location identification codes into a program to perform a 200-table query to identify this Legal password restrictions for 2 locations. Then perform 200 and 210 checks to ensure that they are consistent with password restrictions, application requirements on the target computer system, and the above-mentioned mobile devices.
Note that as long as the location information of the mobile device is provided to the target computer system, another possible embodiment of the present invention is that the mobile computing device relies on the application service component of the target computer system, and it can communicate to perform the password restriction check of the two types of locations. If the channel standard of the application on the mobile device is transmitted to the target computer system, the application service component on the target system also executes the selection or verification of the cryptographic component. In this case, the selection and verification functions cannot be copied on the mobile device.
The application service components on the mobile device and the target computer system then provide all the necessary information to coordinate the channel parameters, including those compression programs and authentication programs to be used, and select a cryptographic component that meets the legal requirements of the application and location, or If the security level requirements of the application cannot be met, but the relevant password restrictions are met, the application service component determines whether a connection should be established.
That is, the application service components at either end of the communication channel jointly decide whether to dynamically change the password or keyword characteristics, disconnect, or stop the device.
If the cipher component selected at the beginning meets the requirements of the mobile device (location specific legal and application requirements), it cannot be used as the target system, and then try 220 to identify an available cipher component that meets the requirements of the second end of the channel. Usually the target system responds with alternative cryptographic components to meet its requirements. If this substitution is not accepted by the mobile device, the application service component of the mobile device should preferably send the identification of the set of cryptographic components to the target system to meet the requirements of the mobile device, so that the target system can then make the final choice or determine whether it can continue to communicate . Or you can continue to propose the exchange of the identification code of the cryptographic component until one of the device tables of the valid cryptographic component is exhausted, or if it does not generate a positive address within the preset time or in the preset number of communication streams, then give up Coordination of channel parameters.
This coordination process is executed simultaneously with other aspects of the handshake coordination, including selecting compression programs, selecting authentication programs, coordinating transmission speed and communication protocols, and so on. Then according to the coordination function, before transmitting the data, perform 230 encryption, compression and authentication on the data.
In addition to performing the selection and verification procedures when establishing a channel, additional verification is also required to deal with the possibility of mobile devices crossing national borders during communication. Possible methods for performing verification after the channel is established include:
1. The first effective method is to check the location of the mobile device (and the verification of the cryptographic component when the country location changes), and repeat 1120 the establishment of the above-mentioned channel whenever encrypted data is sent or received. Before encrypting or decrypting any data, execute a rule transmission to transmit a password type, the data to be encrypted, and any related password keywords. The rule is sent to query the location, use location information to access the location communication requirements table, update the parameters of the type Locale, and verify that the password type and keyword length are acceptable at this location.
This method leads to an increase in network communication, because each location check and possibly access to the password restriction table requires network communication. When GPS is used, it is followed by an effective method of location determination, because GPS requires effective satellite polling.
2. The second passive method is to perform the location check 120 and verify when a predetermined event starts, such as a communication device crossing a national border. In the above mobile phone example, it can be implemented by controlling the application service component 30 to check the cell ID received from the base station to identify the cell change, and start location determination only when the change is known.
Generally, if the location recognition operation 130 determines that the mobile device has not crossed the border, then the mobile device in the embodiment of the present invention only checks the end of the communication itself, no further action is required for area verification, and the communication with the remote computing device is continued. However, whenever this information is obtained, the mobile computing device transmits its own location information to the remote computing device, so that the remote computing device maintains updated information about the device location throughout the session, including the remote computing device.
If the location recognition operation determines that the national border has been crossed, the mobile device is caused to generate an interrupt and then starts to retrieve 140 country-specific password restriction tables and update the country-specific parameters of the type Locale. Then perform a comparison 150, 160 between this table and the application requirements to identify a set of possible cryptographic components, or verify the correctness of the above-mentioned marginal cryptographic components.
Then dynamically coordinate the password level and/or encryption key length with the other end of the communication chain. Depending on the requirements of the application and special legal requirements, the connection can be disconnected, the application can be terminated or erased, or the device can be locked. In the case of encryption, the location information is appended to the sent data, and in the case of decryption, the location of the decryption device and the preset location information in the incoming data must be considered.
Then implement real-variation encryption or decryption, and the rule procedure preferably considers the source of the data and where it is received.
The above description indicates that it is expected to execute the application service component on the mobile device to perform at least the check of the location of its own device, and to select or verify the selection of the cryptographic component according to the legal restrictions of the region. When a mobile device is transmitting data to a remote target device, if it can rely on the target device to perform its own assessment of its regional legal restrictions, it is sufficient to consider its own location, but a complete password compliance check is still required. And other communication restrictions, so that the mobile device can determine the location of the remote communication device and its own location by sending a location query to the remote device. This query address can then be compared with a country-specific password restriction table, as with the location information of the device itself. This requires each communication device to send its location information to the communication counterpart, or requires each device to identify the location of these two devices in some other way.
Similarly, when the mobile device is the recipient of encrypted data, the application service component on the mobile device preferably checks the correctness of the cryptographic component based on its own location and the location of the device sending the data.
There are several alternative ways to determine the location of the mobile phone. For example, if the cost of satellite communication is not very high, the Global Positioning System (GPS) can be used. Whenever you want to send data, you will inquire whether you can use satellites, and GPS provides location coordinates using the national border database to map to a special country. A polygon with sufficient accuracy can be used to illustrate the country's borders, and then the mapping of the country's coordinates is relatively simple. For example, reference may be made to US Patent No. 5,781,628, which is hereby incorporated by reference.
Other mechanisms for location determination can also be used without violating the scope of the present invention. In the mobile phone network example, country location information can be periodically transmitted to the mobile device so that the device does not have to start inquiring before sending or receiving data. The network access station also contains country location information with broadcast cell ID.
From the implementation of the above example, it can be seen that the location information of two devices can be used to perform the location determination operation by only one communication device, or the determination can be made at the two ends of the communication or the selection-verification type.
The embodiments of the present invention have been described with reference to the application service component, so as to achieve that the mobile device communication complies with different cryptographic laws. The present invention can also periodically control the performance of operations other than encryption and decryption of the mobile device based on legal requirements (which are related to the current location of the mobile device) and based on application requirements at either end of the communication chain.
Examples of other applications of the present invention can ensure compliance with laws prohibiting the use of certain technologies in specific countries (if the technology is related to national defense), and laws requiring language must use or comply with the technical standards of digital signatures. The digital signature Used for electronic transactions in financial institutions. In the previous example, after checking whether the current location of a mobile device is a prohibited location for using the device, the location is determined. In this example, the device is stopped. In the example of language requirements, you can choose to translate software components to ensure that the transmitted data meets the language requirements.
In the digital signature example, information about the required technical standards can be obtained, and then used in the selection of a fixed-shift algorithm for a specific signal. In addition to the implementation of the country's location determination of the mobile device, financial transaction instructions are also required for self-identification, so that when the instruction recognizes itself as part of a financial transaction, it can initiate the inspection process of national statutory requirements. The application service component can implement this logic in response to these topic identifiers or other triggers.
The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, in which:
FIG. 1 is a schematic diagram of a mobile computing device communicating with a second computing device crossing a communication network through a device, each computing device includes an application service component according to an embodiment of the present invention; and
Figure 2 shows the selection and verification steps of a cryptographic component according to an embodiment of the present invention.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
23 members in 16 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 9907307 | United Kingdom | A | |
| 9907307 | United Kingdom | A | |
| 19990007307 | – | – | – |
| GB19990007307 | – | – | – |
Members23
| Document | Office | Kind | |
|---|---|---|---|
| GB2348568A | United Kingdom | A | |
| CA2361938A1 | Canada | A1 | |
| WO0059253A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3444100A | Australia | A | |
| TW449988BThis record | Taiwan Province of China | B | |
| KR20010114230A | Republic of Korea | A | |
| EP1166582A1 | European Patent Office (EPO) | A1 | |
| CN1345521A | China | A | |
| HU0200571A2 | Hungary | A2 | |
| HUP0200571A2 | Hungary | A2 | |
| IL144731A0 | Israel | A0 | |
| SG90112A1 | Singapore | A1 | |
| HK1042623A | Hong Kong, China | A | |
| HK1042623A1 | Hong Kong, China | A1 | |
| US6470447B1 | United States of America | B1 | |
| JP2002540748A | Japan | A | |
| CZ20013479A3 | Czechia | A3 | |
| PL356672A1 | Poland | A1 | |
| KR100447292B1 | Republic of Korea | B1 | |
| CN1176564C | China | C | |
| CA2361938C | Canada | C | |
| HK1042623B | Hong Kong, China | B | |
| IL144731A | Israel | A |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A | |
| Issue of patent certificate for granted invention patentGrantedGD4A | GD4A |
Numbers
- Publication
- 449988
- Publication, DOCDB
- 449988
- Publication, EPODOC
- TW449988B
- Application
- 88111084
- Application, DOCDB
- 88111084
- Application, EPODOC
- TW199988111084
Titles5
- Chinese
- 用於行動裝置致使其符合法定要件之計算裝置及其控制方法
- English
- COMPUTING DEVICE FOR ENABLING CONFORMANCE TO LEGISLATIVE REQUIREMENTS FOR MOBILE DEVICES AND A METHOD FOR CONTROLLING THE SAME
- English
- Computing device and control method for mobile device to make it meet statutory requirements
- Unlabeled
- 用於行動裝置致使其符合法定要件之計算裝置及其控制方法
- Unlabeled
- Computing device and control method for mobile device to make it meet statutory requirements
Classification
- CPC, 7
- H04W12/02
- H04L9/14
- H04W12/67
- H04W12/033
- H04W12/30
- H04W12/64
- H04W12/00
- IPC, 3
- H04B7 26
- H04L9 14
- H04W12 00