Data Fading to Secure Data on Mobile Client Devices
Claim Score by NHIP
Abstract
Methods, systems, and computer program products to secure data stored on mobile client devices are provided. In an embodiment, the method operates by defining one or more security policies. Each security policy comprises a plurality of security policy parameters. The method stores the security policies in a data store, and selects a security policy from among the stored security policies for a mobile client device. The selected security policy is applied to the mobile client device. The mobile client device determines whether it is compliance with parameters of said selected security policy, and performs data fade actions if it is determined that it is out of compliance with said security policy parameters.

Term
Projected expiry 5 December 2027.
- Priority and filed
- Published
- Today
- Projected expiry
25 claims: 6 independent, 19 dependent
- 1A method for securing data stored on a mobile client device, comprising:defining one or more security policies, wherein each security policy comprises at least a plurality of security policy parameters;storing said security policies in a data store;selecting a security policy from among said stored security policies for a mobile client device;and applying said selected security policy to said mobile client device;wherein said mobile client device determines whether it is compliance with parameters of said selected security policy, and wherein data fade actions are performed on said mobile client device if it is determined that said mobile client device is out of compliance with said security policy parameters of said selected security policy.
- 2Broadest claimClaim Score 68, broad(NHIP)A method for securing data stored on a mobile client device, comprising:receiving, at said mobile client device, a security policy, wherein said security policy comprises at least a plurality of security policy parameters, and wherein said security policy is received from a server having stored therein a plurality of security policies;determining, on said mobile client device, if said mobile client device is in compliance with parameters of said received security policy;and executing data fade actions on said mobile client device if it is determined that said mobile client device is out of compliance with said security policy parameters.
- 14A system for securing data stored on a plurality of mobile client devices, comprising:a security policy definition module configured to define one or more security policies, wherein each of said security policies comprise at least a plurality of security policy parameters;a storage module configured to store said security policies in a data store;a policy selection module configured to select one of said security policies for each of said mobile client devices;a device update module configured to apply said selected security policy to said each of said mobile client devices during an update session for said each of said mobile client devices.
- 15A system for securing data stored on a mobile client device, comprising:a receiving module, configured to receive a security policy at said mobile client device, wherein said security policy comprises at least a plurality of security policy parameters, and wherein said security policy is received from a server having stored therein a plurality of security policies;a compliance module configured to determine, on said mobile client device, if said mobile client device is in compliance with said selected security policy parameters;and a data fade module configured to execute data fade actions on said mobile client device when said compliance module determines that said mobile client device is out of compliance with said security policy parameters.
- 22A computer program product comprising a computer usable medium having computer program logic recorded thereon for enabling a processor to secure data on a mobile client device, the computer program logic comprising:defining means for enabling a processor to define one or more security policies, wherein each of said one or more security policies comprises a plurality of security parameters;storing means for enabling a processor to store said one or more security policies in a data store;selecting means for enabling a processor to select one of said one or more security policies said mobile client device;and updating means for enabling a processor to apply said selected security policy to said mobile client device.
- 23A computer program comprising a computer usable medium having computer program logic recorded thereon for enabling a processor to secure data on a mobile client device, the computer program logic comprising:receiving means for enabling a processor to receive a security policy at said mobile client device, wherein said security policy comprises at least a plurality of security policy parameters, and wherein said security policy is received from a server having stored therein a plurality of security policies;encrypting means for enabling a processor to store a secure copy of said received security policy on said mobile client device;testing means for enabling a processor to test said plurality of security policy parameters on said mobile client device;determining means for enabling a processor to determine, on said mobile client device, if said mobile client device is in compliance with said security policy parameters;and securing means for enabling a processor to execute data fade actions on said mobile client device when said determining means determines that said mobile client device is not in compliance with said selected security policy parameters.
Independent claims6
91 paragraphs in 4 sections, as filed
BACKGROUND OF INVENTION
p-00021. Field of the Invention
p-0003The present invention relates generally to mobile communications technology and more particularly to securing data on mobile client devices. The invention further relates to securing compromised mobile client devices by deleting data and/or decryption keys from the mobile client devices that have been lost or stolen.
p-00042. Description of the Background Art
p-0005Mobile client devices are in common usage, many featuring powerful processors, larger and more colorful displays, and wireless networking capabilities. Despite these advances in mobile technology, mobile client devices typically have greater limitations regarding physical and data security than servers and workstation computers. Due to the mobile nature and small size of many mobile client devices, there is a risk that the devices can be misplaced, stolen, or otherwise compromised. As a result of this, data residing on these devices may not remain secure when devices are lost or stolen.
p-0006Mobile users face an extremely vulnerable computing environment where security gaps exist. Mobile client devices can include a broad range of hardware and software platforms such as mobile phones, personal digital assistants (PDAs), BlackBerry® devices, Palm® devices, Pocket PCs, Smartphones, hand held computers, palmtop computers, laptop computers, tablet PCs, ultra-mobile PCs, devices running the Symbian mobile operating system, and other wireless client machines. Due to their portability and mobility, mobile client devices can be misplaced, lost, or stolen. When mobile client devices are compromised through loss or theft, the risk of intrusion is high, and existing security controls are inconsistent at best and often unenforceable. On-device data encryption alone is often insufficient to protect data on compromised mobile client devices as regulations regarding data privacy and encryption are becoming stricter. On-device encryption is also less-effective to protect data on mobile client devices as thieves in possession of stolen mobile client devices have the time necessary to derive decryption keys or otherwise access physical data stores on the mobile client devices.
p-0007Existing methods to secure data on mobile client devices include allowing users to create a user name and a password associated with the device. When a user name and password have been established for a mobile client device, data stored on the device is available to any user that logs onto the device by furnishing the correct user name and password. Although this approach may restrict access to data, even when the data is encrypted, anyone who obtains the password or the physical module that stores data in a mobile client device may be able to view and copy the data stored therein.
p-0008Moreover, when a mobile client device is stolen, thieves may have sufficient time to access data on the device by circumventing on-device security measures such as power-on passwords and on-device data encryption.
p-0009Therefore, what is needed is a system, method, and computer program product to secure data stored on mobile client devices in a manner that prevents data access in the event that a mobile client device is stolen or misplaced.
p-0010Interaction between mobile client devices and central servers often occurs in the context of periodic updates or exchanges of information stored in databases. Mobile client devices often retain a copy of some or all of the data found in the central database in a local database for local access. However, security gaps exist between the original data residing on corporate servers and local copies stored on mobile client devices due to the limitations of mobile client devices. Additionally, mobile client devices run a variety of operating systems, software suites, and programming frameworks which can limit what on-device security measures can be ‘pushed’ out to the devices.
p-0011Given the inherent security risks associated with mobile client devices, what is needed are methods, systems, and computer program product to secure data on these mobile client devices in the event the mobile client devices are lost, stolen, or compromised. Due to the occasionally-connected nature of wireless mobile client devices, what is further needed are data security methods, systems, and computer program products to for mobile client devices, wherein security policies are deployed and enforced within the context of potentially intermittent, unreliable, or unavailable networking capabilities.
p-0012Accordingly, what is desired is a means of efficiently securing data residing on compromised mobile client devices. What is further desired are methods and systems to lock (disable), wipe (delete data), or reset a mobile client device that has not communicated with the network or server after a predetermined period of time.
p-0013Further, what is needed are methods, systems, and computer program product to render a mobile client device unusable without requiring manual intervention by an organization's information technology (IT) department when a mobile client device is lost or stolen. What is further needed are methods, systems, and computer program product that enable organizations to manage and protect sensitive data, and enforce mobile client data security centrally, rather than placing the burden of security on mobile client end users.
SUMMARY OF INVENTION
p-0014The invention includes systems, methods, computer program products, and combinations and sub-combinations thereof for defining, deploying, changing, and executing a security policy for devices in a mobile environment, wherein the security policy determines when and if a mobile client device will automatically “fade” or delete data located on the device. According to an embodiment of the present invention, “data fading” events can be executed even if a mobile client device is no longer contactable by the central server so that control can be specifically exerted on mobile client devices that have left the IT administrator's control. In this way, data on mobile client devices that are lost, stolen, or compromised can still be protected. According to an embodiment, a lost or stolen mobile client device can be rendered unusable by executing, thus eliminating the need for manual IT intervention for compromised mobile client devices. In accordance with an embodiment of the invention, mobile client devices are “pre-secured” to take data fading actions at a point determined by an IT administrator.
p-0015The invention further includes an embodiment for securing email, contact information, and other data on mobile client devices. More particularly, this embodiment allows an information technology (IT) system administrator to define and deploy security policy that controls when a “data fade” will be executed on a mobile client. According to an embodiment of the invention, the mobile device can be locked (disabled), wiped (delete data and/or data decryption keys), or reset (restore mobile client device to original ‘factory’ setting via a hard reset). The embodiment further includes the step of setting type of actions to take (e.g., lock, wipe, or reset the mobile client device) and configuring the event(s) that will trigger the actions (i.e., no communication or connection with network or corporate server after a predetermined period of time and/or entry of a predetermined number of sequential invalid passwords). For example, a security policy may determine that a data fade will execute on a mobile client device when the device has not communicated with a network or security server after a predetermined period of time. An embodiment also includes the step of setting a mobile client to ‘vacation mode’ in order to avoid inadvertent deletion of mobile client data when the user anticipates that the client will be unable to connect to a server for a length of time (i.e., during a vacation out of the service area of the mobile client's wireless service provider).
p-0016Unless specifically stated differently, a user or IT administrator is interchangeably used herein to identify a human user, a software agent, or a group of users and/or software agents. Besides a human user who needs to access data on a mobile client device, a software application or agent sometimes needs to access data on mobile devices. Accordingly, unless specifically stated, the term “user” and “administrator” as used herein does not necessarily pertain to a human being. In general, a user and administrator who will access a data on a mobile client device or unlock a device are associated with respective user names and passwords.
p-0017The invention additionally includes an embodiment for defining, deploying, changing, and executing a security policy for mobile client devices, wherein the security policy determines when a mobile client device will automatically “fade” or delete data located on the device. According to an embodiment of the invention, the system secures email, contact information, and other data on a mobile client device by “pre-securing” the device to configure the device to perform actions when the device is lost, stolen, or compromised. The system includes a first module to define “data fade” security policies, wherein the policies comprise criterion for determining when a mobile client is “out of compliance”, and wherein the policies comprise actions to take when a mobile client is out of compliance; a second module to store data fade security policies in a data store on a server; a third module to apply a data fade security policy to a plurality of mobile client devices, wherein the updates occur during respective update sessions for the devices; a fourth module to store a data fade security policy securely on a plurality of mobile client devices; a fifth module to periodically test the data fade security policy on one of a plurality of mobile client devices; a sixth module executable on each of the plurality of mobile client devices to determine if the mobile client devices are out of compliance; and a seventh module to take a data fade action when a mobile client device is out of compliance, wherein the data fade action is determined by the data fade security policy stored on the mobile client device.
p-0018The invention also includes an embodiment to prevent inadvertent deletion or data fading of email, contact information, and other data on mobile client devices. The embodiment includes a module that avoids inadvertent deletion of data on mobile client devices by allowing a user to set a ‘vacation mode’ on a mobile client device when the user anticipates that the device will be unable to connect to a server for a length of time.
p-0019The invention furthermore includes an embodiment to define, deploy, change, and execute a security policy for mobile client devices, wherein the security policy determines when a mobile client device will automatically “fade” or delete data located on the device. The embodiment includes the step of defining “data fade” security policies, wherein the policies comprise criterion for determining when a mobile client is “out of compliance,” and wherein the policies comprise actions to take when a mobile client is out of compliance. The method further includes the steps of storing data fade security policies in a data store on a server; applying a data fade security policy to a plurality of mobile client devices, wherein the policy application occurs during the device's respective update sessions; storing a security policy securely on a plurality of mobile client devices; periodically testing the data fade security policy on the plurality of mobile client devices; determining, on each of the respective mobile client devices, if the mobile client devices are out of compliance; and taking a data fade action when a mobile client device is out of compliance, wherein the data fade action is determined by the security policy stored on the mobile client device.
p-0020Moreover, the invention includes a computer program product embodiment comprising a computer usable medium having computer program logic stored thereon for enabling a processor to define data fade security policies, wherein the policies comprise criterion for determining when a mobile client is out of compliance, and wherein the policies comprise actions to take when a mobile client is out of compliance. The computer program product further comprises computer program logic, which when executed, enables a processor to store security policies in a data store on a server; apply a security policy to a plurality of mobile client devices during the respective update sessions for each device update session; store security policies securely on a plurality of mobile client devices; periodically test compliance with the security policies on each of the plurality of mobile client devices; determine if a mobile client device is out of compliance; and execute a data fade action when a mobile client is out of compliance, wherein the data fade action is determined by the security policy stored on the mobile client device.
p-0021The invention also includes a computer program product embodiment comprising a computer usable medium having computer program logic recorded thereon for enabling a processor to prevent inadvertent deletion or data fading of email, contact information, and other data on mobile client devices. The computer program logic includes computer program logic that enables a processor to avoid inadvertent deletion of data on mobile client devices by allowing a user to set a ‘vacation mode’ on a mobile client device when the user anticipates that the device will be unable to connect to a server for a length of time.
p-0022Further features and advantages of the invention, as well as the structure and operation of various embodiments of the invention, are described in detail below with reference to the accompanying drawings. It is noted that the invention is not limited to the specific embodiments described herein. Such embodiments are presented herein for illustrative purposes only. Additional embodiments will be apparent to persons skilled in the relevant art(s) based on the teachings contained herein.
BRIEF DESCRIPTION OF THE DRAWINGS
p-0023The present invention is described with reference to the accompanying drawings. The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments of the present invention and, together with the description, further serve to explain the principles of the invention and to enable a person skilled in the relevant art to make and use the invention.
p-0024<figref idrefs="DRAWINGS">FIG. 1</figref> illustrates a mobile data system, in accordance with an embodiment of the present invention.
p-0025<figref idrefs="DRAWINGS">FIG. 2</figref> illustrates a mobile data system with two mobile client devices disconnected from the network, wherein one is compromised (i.e., lost or stolen) and a second is set to vacation mode, in accordance with an embodiment of the invention.
p-0026<figref idrefs="DRAWINGS">FIG. 3</figref> depicts the steps by which data residing on compromised mobile client devices is secured, in accordance with an embodiment of the present invention.
p-0027<figref idrefs="DRAWINGS">FIG. 4</figref> illustrates the definition, deployment, and execution of mobile data security policies, in accordance with an embodiment of the present invention.
p-0028<figref idrefs="DRAWINGS">FIG. 5</figref> is a flowchart illustrating steps by which mobile data security policies are defined, deployed, and executed on mobile client devices, in accordance with an embodiment of the present invention.
p-0029<figref idrefs="DRAWINGS">FIG. 6</figref> depicts an example computer system in which the present invention may be implemented.
p-0030The present invention will now be described with reference to the accompanying drawings. In the drawings, generally, like reference numbers indicate identical or functionally similar elements. Additionally, generally, the left-most digit(s) of a reference number identifies the drawing in which the reference number first appears.
DETAILED DESCRIPTION
I. Introduction
p-0031The present invention relates to systems, methods, and computer program products for securing data residing on mobile client devices that have been lost, stolen, or otherwise compromised. According to embodiments of the invention, data on mobile client devices is secured by defining, updating, deploying, and executing mobile security policies.
p-0032While the present invention is described herein with reference to illustrative embodiments for particular applications, it should be understood that the invention is not limited thereto. Those skilled in the art with access to the teachings provided herein will recognize additional modifications, applications, and embodiments within the scope thereof and additional fields in which the invention would be of significant utility.
p-0033The detailed description of embodiments of the present invention is divided into several sections. The first section describes a system for securing data on compromised mobile client devices.
II. Structural Embodiments
p-0034This section describes a system for securing data on mobile client devices according to embodiments of the invention as illustrated in <figref idrefs="DRAWINGS">FIGS. 1 and 2</figref>.
p-0035<figref idrefs="DRAWINGS">FIG. 1</figref> depicts a mobile data security system <b>100</b> which allows a mobile client devices <b>160</b><i>a</i>-<i>d </i>within wireless network <b>102</b> to access data on central server system <b>122</b> via network <b>172</b>, in accordance with an embodiment of the present invention. Network access servers <b>112</b><i>a </i>and <b>112</b><i>b </i>allow mobile client devices <b>160</b><i>a</i>-<i>d </i>to receive the most current data available on server system <b>122</b>, as well as download the most current data fade security policies from a data store on central server system <b>122</b>. For example, network access servers <b>112</b><i>a </i>and <b>112</b><i>b </i>can be wireless network access servers used by mobile client devices <b>160</b><i>a</i>-<i>d </i>to access central server system <b>122</b> via network <b>172</b>. Central server system <b>122</b> applies data fade security policies to mobile client devices <b>160</b><i>a </i>and <b>160</b><i>b</i>, and the policies are then securely stored on mobile client devices <b>160</b><i>a </i>and <b>160</b><i>b</i>, according to an embodiment of the present invention. In accordance with an additional embodiment of the present invention, an Information Technology (IT) administrator defines, selects, and updates data fade security policies on system <b>122</b> which are stored in a data store on central server system <b>122</b>. According to an embodiment, security policies are applied to mobile client devices <b>160</b><i>a</i>-<i>d </i>during update sessions when the devices connect to network <b>172</b> via network access severs <b>112</b><i>a </i>and <b>112</b><i>b. </i>
p-0036In accordance with an embodiment of the invention, mobile client devices <b>160</b><i>a</i>-<i>d </i>store security policies securely in their respective data stores. According to an embodiment, the data security policies are stored on mobile client devices <b>160</b><i>a</i>-<i>d </i>in a secure manner such that users of mobile client devices <b>160</b><i>a</i>-<i>d </i>cannot alter, disable, or delete the security policies. According to a further embodiment, the data fade security policies stored on devices <b>160</b><i>a</i>-<i>d </i>may be encrypted to prevent unauthorized alteration of the policies by end-users.
p-0037According to an embodiment of the present invention, mobile client devices <b>160</b><i>a</i>-<i>d </i>periodically test parameters of data fade security policies stored on devices <b>160</b><i>a</i>-<i>d </i>to determine if the client is out of compliance. For example, pursuant to a previously-applied security policy, device <b>160</b><i>a </i>will periodically check the elapsed time since the last network connection, number of sequential invalid password entries, and/or elapsed time since the last wireless network connection to determine if the device is out of compliance with the security policy stored on device <b>160</b><i>a</i>. According to an embodiment, device <b>160</b><i>a </i>may check for non-compliance at regular time intervals (i.e., hourly, daily, weekly, monthly, etc).
p-0038In accordance with an embodiment of the invention, mobile client devices <b>160</b><i>a</i>-<i>d </i>do not take data fade actions if it has been determined that each of the clients are in compliance with their respective security policies. For example, mobile client device <b>160</b><i>c </i>does not take any data fade actions when it determines that device <b>160</b><i>c </i>is in compliance with its security policy. According to an embodiment, while device <b>160</b><i>c </i>has not been disconnected from wireless network <b>102</b> or network <b>172</b> for a predetermined period of time, device <b>160</b><i>c </i>is in compliance with its security policy and no data fade actions are executed. According to another embodiment, when a predetermined number of sequential invalid password entries have not been made on device <b>160</b><i>c</i>, device <b>160</b><i>c </i>is in compliance with its security policy and no data fade actions are executed.
p-0039“Data” as used herein may be any object, including, but not limited to, information in any form (text, video, audio, etc.) and applications.
p-0040Wireless network <b>102</b> is commonly, but not limited to, a persistent network connection over a cellular provider network, and communications travel over the Internet. However, system <b>102</b> may be any communication means by which central server system <b>122</b> and mobile client devices <b>160</b><i>a</i>-<i>d </i>may interact, such as a docking cradle, Wide Area Network (WAN), Local Area Network (LAN), Wireless Local Area Network (WLAN), infrared, or Bluetooth. The degree of availability of access to the communication means employed may vary greatly, and a user of mobile client device <b>160</b><i>a</i>-<i>d </i>may only occasionally be connected to network <b>172</b> (i.e., by using a docking cradle), or may be constantly connectable to central server system <b>122</b> when connected to a WAN.
p-0041<figref idrefs="DRAWINGS">FIG. 2</figref> depicts a mobile data security system <b>200</b> in which mobile client devices <b>260</b><i>a </i>and <b>260</b><i>b </i>are capable of obtaining updated data fade security policies from central server system <b>122</b> over network <b>272</b> via network access server <b>212</b><i>a</i>, in accordance with an embodiment of the present invention. According to the example of <figref idrefs="DRAWINGS">FIG. 2</figref>, mobile client devices <b>260</b><i>c </i>and <b>260</b><i>d </i>are no longer capable of obtaining data fade security policies from central server system <b>222</b> over network <b>272</b> via network access server <b>212</b><i>b</i>, but instead retain previously-applied data fade security policies. In this example, client devices <b>260</b><i>c </i>and <b>260</b><i>d </i>are both disconnected from the network, <b>260</b><i>d </i>is compromised (i.e., lost or stolen) and <b>260</b><i>c </i>has been set to ‘vacation mode’, in accordance with an embodiment of the invention. Mobile client device <b>260</b><i>d </i>may have been lost, stolen, or otherwise compromised such that it can no longer connect to wireless network <b>202</b> and network <b>272</b>.
p-0042In accordance with an embodiment of the invention, mobile client devices <b>260</b><i>c </i>and <b>260</b><i>d </i>periodically test parameters of their respective, locally-stored data fade security policies to determine if they are out of compliance. For example, pursuant to a previously-applied security policy, device <b>260</b><i>c </i>will periodically check the elapsed time since the last network connection, number of sequential invalid password entries, and/or elapsed time since the last wireless network connection to determine if device <b>260</b><i>c </i>is out of compliance with its locally stored security policy. According to an embodiment, device <b>260</b><i>c </i>may check for non-compliance at regular time intervals (i.e., hourly, daily, weekly, monthly, etc).
p-0043Assume in the example of <figref idrefs="DRAWINGS">FIG. 2</figref> that mobile client device <b>260</b><i>c </i>was set to ‘vacation mode’ prior to becoming disconnected from wireless network <b>202</b> and network <b>272</b>. Assume also that device <b>260</b><i>d </i>has been lost or stolen. According to an embodiment, in this scenario, device <b>260</b><i>c </i>will not take data fade actions despite being disconnected from the network. In contrast, device <b>260</b><i>d </i>will test security policy parameters to determine if it is in compliance with its security policy as it was not set to vacation mode. For example, mobile client device <b>260</b><i>d </i>takes data fade actions pursuant to its security policy when it determines that it is not in compliance with its locally-stored security policy. According to an embodiment, device <b>260</b><i>d </i>will determine that it is not in compliance and will execute data fade actions after it has been disconnected from wireless network <b>202</b> and network <b>272</b> for a predetermined amount of time (i.e., a certain number of hours, days, weeks, etc.). According to another embodiment, device <b>260</b><i>d </i>is not in compliance and will take data fade actions when a threshold number of sequential invalid password entries has been exceeded on the device (i.e., more than n invalid passwords entered on device in a row).
p-0044In accordance with an embodiment of the present invention, data fade actions to be performed on mobile client device <b>260</b><i>d </i>can include one or more of deleting all data on device <b>260</b><i>d</i>, deleting only encrypted data on the device, deleting a subset of data on device <b>260</b><i>d </i>which was previously selected by an IT administrator on server system <b>222</b>, resetting device <b>260</b><i>d </i>back to its original factory settings (i.e., a hard reset which returns device <b>260</b><i>d </i>back to its original configuration), deleting decryption keys on device <b>260</b><i>d</i>, locking mobile client device (i.e., locking the keyboard, screen, and input devices of device <b>260</b><i>d</i>) until it is contacted by a server such as <b>222</b>, locking the device until the device's administrator logs in, or locking the device until a one-time challenge-response process has been completed.
p-0045According to a further embodiment, the data fade actions on device <b>260</b><i>d </i>cannot be interrupted or overridden by an end-user once device <b>260</b><i>d </i>has been determined to be out of compliance with its security policies. In accordance with a further embodiment, data fade actions on device <b>260</b><i>d </i>cannot be interrupted by attempting to power down, turn off, or reset device <b>260</b><i>d</i>. For example, if a thief in possession of device <b>260</b><i>d </i>attempts to circumvent data fade security measures on the device by turning off device <b>260</b><i>d</i>, the data fade actions will continue uninterrupted with only the display or screen of device <b>260</b><i>d </i>being powered down. Similarly, if a thief in possession of device <b>260</b><i>d </i>attempts a hardware reset of the device after recognizing that the data fade actions are executing on the device, data fade actions continue unabated with the screen of device <b>260</b><i>d </i>displaying a mock or simulated reset of the device.
p-0046In a typical system, mobile client devices <b>260</b><i>a</i>-<i>d </i>connect with a central server system <b>222</b>. Central server system <b>222</b> need not be a single physical computer, and may in fact comprise several computers distributed over a number of physical and network locations. For the purposes of illustrations, central servers <b>122</b> and <b>222</b> are depicted as a single point of access for mobile client devices <b>160</b><i>a</i>-<i>d </i>and <b>260</b><i>a</i>-<i>d</i>, respectively.
III. Operational Embodiments
p-0047<figref idrefs="DRAWINGS">FIG. 3</figref> depicts the steps of method <b>300</b> by which data residing on mobile client devices is secured, in accordance with an embodiment of the present invention. The functionality of mobile data security method <b>300</b> is described in greater detail in the following sections.
p-0048According to an embodiment of the present invention, data fade security policies are defined in step <b>323</b>, and stored in central system data store <b>322</b> in step <b>324</b>. Security policies are applied to mobile client devices <b>360</b><i>a</i>-<i>d </i>in step <b>325</b> via network <b>372</b> during update sessions for devices <b>360</b><i>a</i>-<i>d </i>in step <b>332</b>. In the example scenario of <figref idrefs="DRAWINGS">FIG. 3</figref>, devices <b>360</b><i>a </i>and <b>360</b><i>b </i>remain connected to network <b>372</b>. Device <b>360</b><i>c </i>was set to vacation mode prior to being disconnected from network <b>372</b>. Device <b>360</b><i>d </i>has been lost or stolen and disconnected from network <b>372</b>.
p-0049When mobile client device <b>360</b><i>d </i>has been determined to be “out of compliance” with the data fade security policy in step <b>336</b>, data fade operations (previously stored on the device in step <b>324</b>) are executed in step <b>338</b>, in accordance with an embodiment of the present invention.
p-0050According to an embodiment, out of compliance criterion for device <b>360</b><i>d </i>can include one or more of: passage of a predetermined amount of time (i.e., a number of hours, days, or weeks) since the device <b>360</b><i>d </i>was last connected to network <b>372</b> or server <b>322</b>; passage of a predetermined amount of time since device <b>360</b><i>d </i>was last updated or “refreshed” with a new security policy; and/or exceeding a predetermined number of invalid login attempts by a user on device <b>360</b><i>d. </i>
p-0051According to an embodiment of the present invention, once mobile client device <b>360</b><i>d </i>has been determined to be out of compliance, data fade actions are taken in step <b>338</b>. The data fade actions can include, but are not limited to one or more of: deletion of all data on device <b>360</b><i>d</i>; deletion of only encrypted data on device <b>360</b><i>d</i>; deletion of a subset of data previously selected by an IT administrator in step <b>323</b>; performing a “hard reset” of device <b>360</b><i>d</i>, wherein the hard reset returns device <b>360</b><i>d </i>to its factory settings by deleting all data and setting all configuration information back to original factory defaults; deleting decryption keys on device <b>360</b><i>d</i>; locking device <b>360</b><i>d </i>until device <b>360</b><i>d </i>is contacted by server <b>322</b>, wherein device <b>360</b><i>d </i>is locked by disabling the device's keyboard, screen, and input devices; locking device <b>360</b><i>d </i>until the device's “administrator” logs in, wherein the device administrator username and password was determined in step <b>323</b>; or locking device <b>360</b><i>d </i>until a one-time challenge-response process has been completed, wherein the challenge-response questions and answers were determined in step <b>323</b>.
p-0052According to an embodiment, the data security policies stored on mobile client devices <b>360</b><i>a</i>-<i>d </i>in step <b>332</b> are stored in a secure manner such that users of devices <b>360</b><i>a</i>-<i>d </i>cannot alter, disable, or delete the security policies. According to a further embodiment, the data fade security policies stored on devices <b>360</b><i>a</i>-<i>d </i>in step <b>332</b> may be encrypted to prevent unauthorized alteration of the policies by end-users.
p-0053According to a further embodiment, the data fade actions on device <b>360</b><i>d </i>performed in step <b>338</b> cannot be interrupted or overridden by a user once device <b>360</b><i>d </i>has been determined to be out of compliance with security policies applied in step <b>325</b> and stored in step <b>332</b>. In accordance with a further embodiment, data fade actions being executed in step <b>338</b> on device <b>360</b><i>d </i>cannot be interrupted by attempting to power down, turn off, or reset the device. For example, if a thief in possession of device <b>360</b><i>d </i>attempts to circumvent data fade security measures on the device by turning off device <b>360</b><i>d</i>, the data fade actions will continue uninterrupted with only the display or screen of device <b>360</b><i>d </i>being powered down. According to another embodiment of the invention, if a thief in possession of device <b>360</b><i>d </i>attempts a hardware reset of the device after recognizing that the data fade actions are executing on the device in step <b>338</b>, data fade actions continue unabated with the screen of device <b>360</b><i>d </i>displaying a mock or simulated reset of device <b>360</b><i>d. </i>
p-0054<figref idrefs="DRAWINGS">FIG. 4</figref> further illustrates the steps of method <b>300</b> by which data residing on mobile client devices is secured, in accordance with an embodiment of the present invention. In step <b>423</b>, an Information Technology (IT) administrator defines new data fade security policies or updates existing policies.
p-0055In step <b>424</b>, the policies defined and updated in step <b>423</b> are stored in a central server data store.
p-0056In step <b>425</b>, a data fade security policy is selected for mobile client device <b>460</b>, and in step <b>426</b> the selected policy is applied during an update session for device <b>460</b>.
p-0057In step <b>432</b>, the data fade security policy for mobile client device <b>460</b> is securely stored in a data store on device <b>460</b>. According to an embodiment, the data security policy stored on device <b>460</b> in step <b>432</b> is stored in a secure manner such that users of device <b>460</b> cannot alter, disable, or delete the security policy. According to a further embodiment, the security policy stored on device <b>460</b> in step <b>432</b> may be encrypted to prevent unauthorized alteration of the policies by a user.
p-0058In step <b>434</b>, the vacation mode setting is checked on device <b>460</b>. According to an embodiment, if device <b>460</b> was not set to vacation mode, security policy parameters will be tested (in step <b>436</b>) to determine if device <b>460</b> is in compliance with its security policy. Otherwise, if device <b>460</b> was set to vacation mode, security policy parameters pertaining to network connectivity are not tested and, in an embodiment, step <b>426</b> is repeated to apply any updates to device <b>460</b>'s security policy during the next update session for device <b>460</b>. According to an embodiment, even when mobile client device <b>460</b> is set to vacation mode, security policy parameters pertaining to the number of invalid sequential password entries will be checked.
p-0059In step <b>436</b>, the security policy parameters are tested by device <b>460</b>. In accordance with an embodiment of the invention, the frequency of testing or checking of policy parameters is pursuant to the security policy applied in step <b>426</b>.
p-0060According to an embodiment, device <b>460</b> will periodically check the elapsed time since the last network connection and/or elapsed time since the last wireless network connection to determine if device <b>460</b> is out of compliance with the security policy stored therein. According to an embodiment, device <b>460</b> tests for non-compliance at regular time intervals (i.e., hourly, daily, weekly, monthly, etc). In accordance with an embodiment, the number of sequential invalid password entries will be checked to determine if device <b>460</b> is out of compliance with the security policy stored therein.
p-0061According to an embodiment, device <b>460</b> is not considered to be in compliance with its security policy after it has been disconnected from either a wireless network or the network for a predetermined amount of time (i.e., a certain number of hours, days, weeks, etc.). According to another embodiment, device <b>460</b> is out of compliance when a threshold number of sequential invalid password entries has been exceeded on the device (i.e., more than n in a row invalid passwords entered on device, wherein n is the maximum allowed number of sequential invalid passwords).
p-0062Step <b>442</b> is performed if device <b>460</b> was determined to be out of compliance. In step <b>442</b>, data fade actions are taken on device <b>460</b>. In accordance with an embodiment of the invention the data fade actions in step <b>438</b> can include one or more of deleting all data on device <b>460</b>, deleting only encrypted data on the device, deleting a subset of data previously selected by an IT administrator in step <b>423</b>, performing a hard reset of device <b>460</b> by deleting all data and setting all configuration information back to original factory defaults, deleting decryption keys on device <b>460</b>, locking device <b>460</b> until it is contacted by a corporate server by disabling the device's keyboard, screen, and input devices, locking device <b>460</b> until the device's administrator logs in, wherein the device administrator username and password was determined in step <b>423</b>, or locking device <b>460</b> until a one-time challenge-response process has been completed, wherein the challenge-response questions and answers were determined in step <b>423</b>.
p-0063<figref idrefs="DRAWINGS">FIG. 5</figref> is a flowchart <b>500</b> which illustrates the steps by which the method depicted in <figref idrefs="DRAWINGS">FIGS. 3 and 4</figref> secures data on mobile client devices.
p-0064The method starts at step <b>502</b> and proceeds to step <b>523</b>. In step <b>523</b>, an Information Technology (IT) defines new data fade security policies or updates existing policies.
p-0065In step <b>524</b>, the policies defined and updated in step <b>523</b> are stored in a central server data store.
p-0066In step <b>525</b>, a data fade security policy is selected for a given mobile client device prior to an update session for the device. According to an embodiment of the present invention, the data fade security policy is selected by an IT administrator before the mobile client device connects as part of the update session.
p-0067In step <b>526</b> the data fade security policy selected in step <b>525</b> is applied to a given mobile client device during an update session for the device. According to an embodiment, the server will apply whatever policy an IT administrator previously specified in step <b>525</b> during the update session.
p-0068In step <b>532</b>, the data fade security policy for the mobile client device is securely stored in a data store on the device. According to an embodiment, the data security policy stored on the device in step <b>532</b> is stored in a secure manner such that users of the device cannot alter, disable, or delete the policy. According to a further embodiment, the security policy stored on the device in step <b>532</b> is encrypted to prevent unauthorized alteration of the policies by an end-user.
p-0069In step <b>534</b>, it is determined if the device is in vacation mode. According to an embodiment, if the device is not in vacation mode, security policy parameters will be tested in step <b>536</b> as described below, but if the device is in vacation mode, security policy parameters pertaining to network connectivity are not tested and control returns to step <b>526</b>. When step <b>526</b> is repeated, any updates to the device's security policy will be applied during the device's next update session. In accordance with an embodiment of the present invention, the fact that a mobile client devices has been set to vacation mode does not affect the check for invalid password attempts. For example, if the device's security policy is to lock the device after a number of sequential invalid password entries, the mobile client device will be locked even if the device is in vacation mode.
p-0070In step <b>536</b>, the security policy parameters are tested on the device. In accordance with an embodiment of the invention, the timing and frequency of testing for compliance with security policy parameters is pursuant to the security policy applied in step <b>525</b>. According to an embodiment, the device will periodically calculate the elapsed time since the last network connection and/or elapsed time since the last wireless network connection to determine if the device is out of compliance with the security policy stored on the device. According to an embodiment, the mobile client device tests for non-compliance at regular time intervals (i.e., hourly, daily, weekly, monthly, etc) pursuant to its security policy.
p-0071In accordance with an embodiment of the invention, the check for the number of sequential invalid password attempts is not periodical or based on time interval. For example, the check for the number of invalid password attempts it is done anytime an invalid password is entered on the mobile client device. According to an embodiment, it is number of sequential invalid passwords entered on the mobile client device that triggers a data fade action. For example, a mobile client device will execute data fade actions after n sequential invalid passwords are entered where n is greater than or equal to one.
p-0072In step <b>538</b>, a decision is made as to whether the mobile client device is out of compliance with its security policy parameters or not. According to an embodiment, the mobile client device is not in compliance after it has exceeded a predetermined amount of disconnect time from either a wireless network or a network (i.e., the device has been off of the network for a certain number of hours, days, weeks, etc.). According to another embodiment, the mobile client device is determined to be out of compliance in step <b>538</b> when a certain number of sequential invalid password entries have been entered on the device (i.e., more than n consecutive invalid passwords entered on device, wherein n is the maximum allowed number of sequential invalid passwords).
p-0073If the device is found to be in compliance in step <b>538</b>, steps <b>526</b>-<b>538</b> are repeated as needed to apply policy updates to the device during subsequent update sessions. The repeated policy selections, applications, and compliance tested are accomplished by repeating steps <b>526</b>-<b>538</b>. According to an embodiment of the invention, data fade security policies can be updated and stored by repeating steps <b>523</b> and <b>524</b>.
p-0074After a compliance decision has been made in step <b>538</b>, and the device is found to be out of compliance, data fade actions are performed on the device in step <b>542</b>. In accordance with an embodiment of the invention the data fade actions in step <b>542</b> can include one or more of deleting all data on the mobile client device, deleting only encrypted data on the device, deleting a subset of data previously selected by an IT administrator in step <b>523</b>, performing a hard reset of the device by deleting all data and setting all configuration information back to original factory defaults, deleting decryption keys on the device, locking the device until it is contacted by a corporate server by disabling the device's keyboard, screen, and input devices, locking the device until the device's administrator logs in, wherein the device administrator username and password was determined in step <b>523</b>, or locking the device until a one-time challenge-response process has been completed, wherein the challenge-response questions and answers were determined in step <b>523</b>.
p-0075After the data fade actions have been performed in step <b>542</b>, the method ends at step <b>544</b>.
IV. Example Computer System Implementation
p-0076Various aspects of the present invention can be implemented by software, firmware, hardware, or a combination thereof. <figref idrefs="DRAWINGS">FIG. 6</figref> illustrates an example computer system <b>600</b> in which the present invention, or portions thereof, can be implemented as computer-readable code. For example, the method illustrated by flowchart <b>500</b> of <figref idrefs="DRAWINGS">FIG. 5</figref> can be implemented in system <b>600</b>. Various embodiments of the invention are described in terms of this example computer system <b>600</b>. After reading this description, it will become apparent to a person skilled in the relevant art how to implement the invention using other computer systems and/or computer architectures.
p-0077Computer system <b>600</b> includes one or more processors, such as processor <b>604</b>. Processor <b>604</b> can be a special purpose or a general purpose processor. Processor <b>604</b> is connected to a communications infrastructure <b>606</b> (for example, a bus, or network).
p-0078In alternative implementations, secondary memory <b>610</b> may include other similar means for allowing computer programs or other instructions to be loaded into computer system <b>600</b>. Such means may include, for example, a removable storage drive <b>622</b> and an interface <b>620</b>. Examples of such means may include a program cartridge and cartridge interface (such as that found in video game devices), a removable memory chip (such as an EPROM, or PROM) and associated socket, and other removable storage drives <b>618</b> and <b>622</b> and interfaces <b>620</b> which allow software and data to be transferred from the removable storage drive <b>622</b> to computer system <b>600</b>.
p-0079Computer system <b>600</b> may also include a communications interface <b>624</b>. Communications interface <b>624</b> allows software and data to be transferred between computer system <b>600</b> and external devices. Communications interface <b>624</b> may include a modem, a network interface (such as an Ethernet card), a communications port, a PCMCIA slot and card, or the like. Software and data transferred via communications interface <b>624</b> are in the form of signals which may be electronic, electromagnetic, optical, or other signals capable of being received by communications interface <b>624</b>. These signals are provided to communications interface <b>624</b> via a communications path <b>626</b>. Communications path <b>626</b> carries signals and may be implemented using wire or cable, fiber optics, a phone line, a cellular phone link, an RF link or other communications channels.
p-0080In this document, the terms “computer program medium” and “computer usable medium” are used to generally refer to media such as removable storage unit <b>614</b>, removable storage drives <b>618</b> and <b>622</b>, and a hard disk installed in hard disk drive <b>612</b>. Signals carried over communications path <b>626</b> can also embody the logic described herein. Computer program medium and computer usable medium can also refer to memories, such as main memory <b>608</b> and secondary memory <b>610</b>, which can be memory semiconductors (e.g. DRAMs, etc.). These computer program products are means for providing software to computer system <b>600</b>.
p-0081Computer programs (also called computer control logic) are stored in main memory <b>608</b> and/or secondary memory <b>610</b>. Computer programs may also be received via communications interface <b>624</b>. Such computer programs, when executed, enable computer system <b>600</b> to implement the present invention as discussed herein. In particular, the computer programs, when executed, enable processor <b>604</b> to implement the processes of the present invention, such as the steps in the methods illustrated by <figref idrefs="DRAWINGS">FIG. 3</figref>, <figref idrefs="DRAWINGS">FIG. 4</figref>, and flowchart <b>500</b> of <figref idrefs="DRAWINGS">FIG. 5</figref> discussed above. Accordingly, such computer programs represent controllers of the computer system <b>600</b>. Where the invention is implemented using software, the software may be stored in a computer program product and loaded into computer system <b>600</b> using removable storage unit <b>614</b>, interface <b>620</b>, hard drive <b>612</b> or communications interface <b>624</b>.
p-0082The invention is also directed to computer program products comprising software stored on any computer useable medium. Such software, when executed in one or more data processing device, causes a data processing device(s) to operate as described herein. Embodiments of the invention employ any computer useable or readable medium, known now or in the future. Examples of computer useable mediums include, but are not limited to, primary storage devices (e.g., any type of random access memory), secondary storage devices (e.g., hard drives, floppy disks, CD ROMS, ZIP disks, tapes, magnetic storage devices, optical storage devices, MEMS, nanotechnological storage device, etc.), and communication mediums (e.g., wired and wireless communications networks, local area networks, wide area networks, intranets, etc.).
p-0083The invention can work with software, hardware, and/or operating system implementations other than those described herein. Any software, hardware, and operating system implementations suitable for performing the functions described herein can be used.
V. Conclusion
p-0084It is to be appreciated that the Detailed Description section, and not the Summary and Abstract sections, is intended to be used to interpret the claims. The Summary and Abstract sections may set forth one or more but not all exemplary embodiments of the present invention as contemplated by the inventor(s), and thus, are not intended to limit the present invention and the appended claims in any way.
p-0085The present invention has been described above with the aid of functional building blocks illustrating the implementation of specified functions and relationships thereof. The boundaries of these functional building blocks have been arbitrarily defined herein for the convenience of the description. Alternate boundaries can be defined so long as the specified functions and relationships thereof are appropriately performed.
p-0086The foregoing description of the specific embodiments will so fully reveal the general nature of the invention that others can, by applying knowledge within the skill of the art, readily modify and/or adapt for various applications such specific embodiments, without undue experimentation, without departing from the general concept of the present invention. Therefore, such adaptations and modifications are intended to be within the meaning and range of equivalents of the disclosed embodiments, based on the teaching and guidance presented herein. It is to be understood that the phraseology or terminology herein is for the purpose of description and not of limitation, such that the terminology or phraseology of the present specification is to be interpreted by the skilled artisan in light of the teachings and guidance.
p-0087The breadth and scope of the present invention should not be limited by any of the above-described exemplary embodiments, but should be defined only in accordance with the following claims and their equivalents.
Contents4
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2011056700A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10425402B2 | Cited by | United States of America | Applicant |
| US9558370B2 | Cited by | United States of America | Applicant |
| US9386096B2 | Cited by | United States of America | Applicant |
| US9167037B2 | Cited by | United States of America | Search report |
| US8891772B2 | Cited by | United States of America | Applicant |
| US2017308713A1 | Cited by | United States of America | Search report |
| US7966001B2 | Cited by | United States of America | Search report |
| US2012046807A1 | Cited by | United States of America | Pre-grant |
| US10528748B2 | Cited by | United States of America | Search report |
| US10097587B2 | Cited by | United States of America | Applicant |
| US8640226B2 | Cited by | United States of America | Search report |
| US2014007222A1 | Cited by | United States of America | Pre-grant |
| US9900288B2 | Cited by | United States of America | Applicant |
| US9058503B2 | Cited by | United States of America | Applicant |
| US2012163603A1 | Cited by | United States of America | Pre-grant |
| US9667599B2 | Cited by | United States of America | Applicant |
| KR20140123522A | Cited by | Republic of Korea | Search report |
| US9811682B2 | Cited by | United States of America | Applicant |
| US8566961B2 | Cited by | United States of America | Applicant |
| WO2011056700A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8745383B2 | Cited by | United States of America | Applicant |
| EP2362322A1 | Cited by | European Patent Office (EPO) | Search report |
| US9449157B2 | Cited by | United States of America | Applicant |
| US10171503B1 | Cited by | United States of America | Search report |
| US8627508B2 | Cited by | United States of America | Applicant |
| US2010050244A1 | Cited by | United States of America | Pre-grant |
| WO2021046637A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9992191B2 | Cited by | United States of America | Applicant |
| JP2015508257A | Cited by | Japan | Examiner |
| WO2020159550A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US10140463B2 | Cited by | United States of America | Applicant |
| US9753746B2 | Cited by | United States of America | Applicant |
| US2010178899A1 | Cited by | United States of America | Pre-grant |
| US10348696B2 | Cited by | United States of America | Applicant |
| US9117092B2 | Cited by | United States of America | Applicant |
| US2010037323A1 | Cited by | United States of America | Pre-grant |
| US2013129094A1 | Cited by | United States of America | Pre-grant |
| US2009254995A1 | Cited by | United States of America | Pre-grant |
| US8560722B2 | Cited by | United States of America | Applicant |
| US9239707B2 | Cited by | United States of America | Applicant |
| WO2012129002A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| CN104094275A | Cited by | China | Search report |
| US2007162731A1 | Cited by | United States of America | Pre-grant |
| US2015186675A1 | Cited by | United States of America | Pre-grant |
| JP2015508257A | Cited by | Japan | Search report |
| US8935810B2 | Cited by | United States of America | Applicant |
| US9137659B2 | Cited by | United States of America | Applicant |
| JP2015508257A | Cited by | Japan | Search report |
| US9224005B2 | Cited by | United States of America | Applicant |
| US8556991B2 | Cited by | United States of America | Applicant |
| US10476947B1 | Cited by | United States of America | Applicant |
| US10943198B2 | Cited by | United States of America | Applicant |
| US8332953B2 | Cited by | United States of America | Applicant |
| US2010037291A1 | Cited by | United States of America | Pre-grant |
| US9836616B2 | Cited by | United States of America | Applicant |
| US9183380B2 | Cited by | United States of America | Search report |
| US9245143B2 | Cited by | United States of America | Applicant |
| US9633492B2 | Cited by | United States of America | Applicant |
| US10044763B2 | Cited by | United States of America | Applicant |
| US8713173B2 | Cited by | United States of America | Applicant |
| US9418244B2 | Cited by | United States of America | Search report |
| KR101531781B1 | Cited by | Republic of Korea | Search report |
| US2010037312A1 | Cited by | United States of America | Pre-grant |
| US9756080B2 | Cited by | United States of America | Applicant |
| US7689205B2 | Cited by | United States of America | Search report |
| US8984653B2 | Cited by | United States of America | Search report |
| EP2812842A4 | Cited by | European Patent Office (EPO) | Search report |
| US8510825B2 | Cited by | United States of America | Applicant |
| US2009328131A1 | Cited by | United States of America | Pre-grant |
| US9665577B2 | Cited by | United States of America | Applicant |
| CN103430518A | Cited by | China | Search report |
| US10410154B2 | Cited by | United States of America | Applicant |
| US9537868B2 | Cited by | United States of America | Search report |
| US2010266132A1 | Cited by | United States of America | Pre-grant |
| US9665576B2 | Cited by | United States of America | Applicant |
| US2006021007A1 | Cites | United States of America | Pre-grant |
| US2006161628A1 | Cites | United States of America | Pre-grant |
| US2006242685A1 | Cites | United States of America | Pre-grant |
| US2008005561A1 | Cites | United States of America | Pre-grant |
| US2008137593A1 | Cites | United States of America | Pre-grant |
| US2009019293A1 | Cites | United States of America | Pre-grant |
6 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 95086107 | United States of America | A | |
| US20070950861 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| US2009150970A1 | United States of America | A1 | |
| WO2009075807A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2223550A1 | European Patent Office (EPO) | A1 | |
| CN101933349A | China | A | |
| EP2223550A4 | European Patent Office (EPO) | A4 | |
| CN101933349B | China | B |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2009150970
- Publication, EPODOC
- US2009150970
- Application
- 11950861
- Application, DOCDB
- 95086107
- Application, EPODOC
- US20070950861
Titles
- English
- Data Fading to Secure Data on Mobile Client Devices
Classification
- CPC, 2
- G06F21/88
- G06F2221/2143
- IPC, 1
- G06F21 00
- USPC, 1
- 726001000