IP Library Granted Patent US 7,353,533
Granted Patent B2
US 7,353,533 · App. 10/413,443 · Granted Apr 1, 2008

Administration of protection of data accessible by a mobile device

Assignee: Novell, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,353,533
App. No.
10/413,443
Granted
Apr 1, 2008
Kind
B2
Abstract

The administration of protection of data on a client mobile computing device by a server computer system such as within an enterprise network or on a separate mobile computing device is described. Security tools are described that provide different security policies to be enforced based on a location associated with a network environment in which a mobile device is operating. Methods for detecting the location of the mobile device are described. Additionally, the security tools may also provide for enforcing different policies based on security features. Examples of security features include the type of connection, wired or wireless, over which data is being transferred, the operation of anti-virus software, or the type of network adapter card. The different security policies provide enforcement mechanisms that may be tailored based upon the detected location and/or active security features associated with the mobile device. Examples of enforcement mechanisms are adaptive port blocking, file hiding and file encryption.

Claims (34)

1. A computer-implemented method for administering protection of data accessible by a mobile computing device, comprising:

pre-defining one or more security policies by a server computer system for the mobile computing device based upon a plurality of pre-configured locations associated with a network environment in which the mobile computing device may be operating;

upon the mobile computing device detecting a location in which it is operating during use, the server computer system configured for receiving a query from the mobile computing device to verify whether the detected location corresponds to one of the plurality of pre-configured locations;

comparing the detected location to the plurality of pre-configured locations; and

if the detected location corresponds to one of the plurality of pre-configured locations, sending over a network the one or more security policies to the mobile computing device as a function of the detected location, wherein the server computer system sends the one or more security policies and responds to the received query using a cryptographic authentication protocol.

2. The method of claim 1 further comprising:

determining a current security policy by the mobile device from the one or more security policies received over the network from the server computer system based upon criteria, with; and

enforcing the current security policy.

3. The method of claim 2 further comprising decrypting the one or more received security policies and authenticating that each received security policy is from an authorized server computer system.

4. The method of claim 1 further comprising:

monitoring diagnostic data received over the network from one or more mobile computer devices;

analyzing the diagnostic data; and

transmitting support information to the one or more mobile computing devices.

5. A computer-implemented method for providing protection of data accessible by a mobile computing device comprising:

pre-defining one or more security policies by a server computer system for the mobile computing device based upon a plurality of pre-configured security features associated with a network environment in which the mobile device may be operating;

monitoring whether security features of the mobile computing device have been activated or deactivated as the mobile computing device operates in one or more locations to-be-detected during use by the mobile computing device relative to a plurality of pre-configured locations corresponding to the plurality of pre-configured security features, the server computer system configured for receiving and verifying a query from the mobile computing device regarding Pie one or more locations to-be-detected and a corresponding activated or deactivated security feature; and

if the corresponding activated or deactivated security feature does not comply with Pie plurality of pre-configured security features associated with a network environment in which the mobile device may be operating, sending over a network the one or more security policies to the mobile device to force compliance.

6. The method of claim 5 further comprising:

enforcing a current security policy on the mobile computing device by sending commands according to a cryptographic protocol over the network to the client device.

7. A computer-implemented system for providing protection of data accessible by a client mobile computing device comprising:

a policy management module for managing one or more security policies for execution on the client mobile device, the security policies being pre-defined based upon criteria, the criteria including a plurality of pre-configured locations associated with a network environment in which the mobile device may be operating;

an authorization module for communicating with a location detection module of the client mobile device such that upon the location detection module detecting a location in which the client mobile device is operating during use, the authorization module configured for receiving and responding to a query from the mobile computing device verifying whether the detected location corresponds to one of the plurality of pre-configured locations; and

if the detected location corresponds to one of the plurality of pre-configured locations, a policy distribution module for sending over the network the one or more security policies to the client mobile device, the policy distribution module having a communication interface with the policy management module for receiving information regarding policies.

8. The system of claim 7 , wherein the authorization module is further configured to authorize a communication exchange with the client mobile device based upon information received from the mobile device over the network in accordance with a cryptographic authentication protocol.

9. The system of claim 7 wherein the one or more security policies are defined as XML documents.

10. The system of claim 7 wherein the one or more security policies are encrypted.

11. The system of claim 7 wherein, responsive to an update request from a client, the distribution module transmits over a network to the mobile client device, security information.

12. The system of claim 7 further comprising a remote diagnostics module comprising:

a monitoring module for monitoring diagnostic data received over a network from one or more remotely located mobile client devices;

a diagnosis module for analyzing die diagnostic data; and

a diagnosis distribution module for transmitting support information to the one or more mobile client devices.

13. The system of claim 7 further comprising: a policy setting module for determining a current security policy for the client mobile device from die one or more security policies received from the policy management module based upon criteria including the detected location.

14. The system of claim 13 further comprising a policy enforcement control module being communicatively coupled with the policy setting module for communication of the current security policy to be enforced, the enforcement control module comprising one or more enforcement mechanism modules for enforcing the current security policy on die client mobile device by sending commands over the network to the client device.

15. The system of claim 7 wherein the criteria further comprises an activity status of a security feature.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 6, 2026
From: COLDVEST PATENT LLC
To: COLDVENTURES LLC
Reel/Frame 075550/0035 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2012
From: CPTN HOLDINGS LLC
To: APPLE INC.
Reel/Frame 028856/0230 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2012
From: NOVELL, INC.
To: CPTN HOLDINGS LLC
Reel/Frame 028841/0047 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2007
From: SENFORCE TECHNOLOGIES, INC.
To: NOVELL, INC.
Reel/Frame 020010/0387 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2003
From: WRIGHT, MICHAEL; BOUCHER, PETER; NAULT, GABE; SMITH, MERRILL; JACOBSON, STERLING K.; WOOD, JONATHAN; MIMS, ROBERT
To: SENFORCE TECHNOLOGIES, INC.
Reel/Frame 013869/0206 →
Continuity (4)
Continuation In Part 1037726500 · Feb 28, 2003
Provisional Application 6043855600 · Jan 6, 2003
Provisional Application 6043448500 · Dec 18, 2002
Related Publication 20040123153A1 · Jun 24, 2004