WO2004028070A1

Server, computer memory, and method to support security policy maintenance and distribution

Abstract

In a particular embodiment, a server module deployed on a server (102) is disclosed. The server module is connected to a wireless network access node (104). The server modules includes a database (108) containing user information for multiple wireless devices (106). Each element in the database (108) is attributable to at least one authorized wireless device (106) and contains at least one type of data file from the following group: (i) wireless connectivity permissions, (ii) authorized wireless device identification, and (iii) authorized network access node information.In another embodiment, a method of enforcing security policies at a mobile computing device (106) is provided. The method includes receiving a policy at the mobile computing device (106) and enforcing the policy at the mobile computing device (106) by disallowing a user of the mobile computing device (106) from engaging in the use precluded by the use limitation. The policy includes at least one device use limitation.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 15 independent, 0 dependent

  1. 1
    WHAT IS CLAIMED IS 1. A server module deployed on a server that is connected to a wireless network access node, comprising:a database containing user information for multiple wireless devices, each element in the database attributable to at least one authorized wireless device and containing at least one type of data file from the group consisting of: (i) wireless connectivity permissions, (ii) authorized wireless device identification, and (iii) authorized network access node information.
  2. 2
    A computer memory comprising:a plurality of operating keys for use in connection with security features of a mobile computing device;and a root key, the root key to encrypt the plurality of operating keys.
  3. 3
    A method of enforcing security policies at a mobile computing device, the method comprising:receiving a policy at the mobile computing device, the policy including at least one device use limitation;enforcing the policy at the mobile computing device by disallowing a user of the mobile computing device from engaging in the use precluded by the use limitation.
  4. 4
    A security method comprising:receiving a password from a user of a mobile computing device;deriving a security code from the password by applying a non-linear function;and encrypting the security code using the password as an encryption key.
  5. 5
    A method of selectively providing a mobile computing device with access to a software application on a server, the method comprising:receiving a request to access the software application from the mobile computing device;determining whether to grant access to the software application by checking whether the mobile computing device has an installed security program.
  6. 6
    A method of updating policies and key materials, the method comprising:providing a shared encryption key that is shared by a server and a client module;encrypting data on the client using the shared encryption key;authenticating a user of a mobile computing device by receiving a password, the client resident at the mobile computing device;decrypting the shared key using the password;using the shared key to decrypt updated policies and key materials;and replacing policies and key materials at the mobile computing device with the updated and decrypted policies and key materials.
  7. 7
    A wireless security system, comprising:a client module deployed on a wireless device;a network module selectively coupled to the client module during synchronization;and a server module coupled to the network module, wherein the client module is adapted to authenticate use of a wireless computing device independent of the network module and the server module.
  8. 8
    A method of installing a security software application from a network module to a mobile computing device, the method comprising:providing a network module, the network module including security policies and key material, the security policies and key material communicated to the network module from a server;when the mobile device is synchronizing with the network module, initiating installation of a security software program onto the mobile security device;requesting a one-time password;receiving the one-time password at the mobile computing device;and using the one-time password to decrypt a root key associated with the key materials.
  9. 9
    A method of distributing security policy information from a server to a mobile computing device, the method comprising:authenticating a connection between the server and a gatekeeper;sending a policy package to the gatekeeper;initiating data synchronization between the mobile computing device and the gatekeeper;authenticating the mobile computing device;and sending the policy package from the gatekeeper to the mobile computing device.
  10. 10
    A client module deployed on a wireless device, comprising:a policy database including a list of authorized devices to which the wireless device may communicate.
  11. 11
    A client module deployed on a wireless device, comprising:a policy database containing at least two user profiles on the wireless device.
  12. 12
    A client module deployed on a wireless device, comprising:a policy database including rules related to wireless connectivity permissions;and an intelligent agent for enforcing the policy database rules.
  13. 13
    A client module deployed on a wireless device, comprising:a policy database;and an agent responsive to the policy database, the agent configured to monitor unauthorized use of the wireless device.
  14. 14
    A client module deployed on a wireless device, comprising:a policy database including at least one type of data file from the group consisting of: (i) multiple profile data, (ii) connectivity permissions, (iii) authorized wireless device identification, and (iv) authorized network access node information;an intelligent agent for enforcing rules of the policy database;and an activity log containing wireless connectivity history information.
  15. 15
    A network module deployed at a wireless network access node, comprising:a policy database including a list of authorized wireless mobile devices;and an agent for enforcing rules of the policy database.