IP Library Patent Application 10515759
Patent Application
App. No. 10/515,759

Mobile wireless device with protected file system

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/515,759
Abstract

A mobile wireless device programmed with a file system which is partitioned into multiple root directories. The partitioning of the file system ‘cages’ processes as it prevents them from seeing any files they should not have access to. A Trusted Computing Base verifies whether or not a process has the required privileges or capabilities to access root sub-trees. The particular directory a file is placed into automatically determines its accessibility to different processes—i.e. a process can only access files in certain root directories. This is a light weight approach since there is no need for a process to interrogate an access control list associated with a file to determine its access rights over the file—the location of the file taken in conjunction with the access capabilities of a process intrinsically define the accessibility of the file to the process. Another aspect of this invention is that each process can have its own private area of the file system guaranteeing confidentiality and integrity to its data.

Claims (23)

1 . A single-user mobile wireless device programmed with a file system which is partitioned into multiple root directories; in which the location of a file is enough to fully identify its access policy to a process running on the device.

2 . The device of claim 1 in which access rights of the file are modified by moving its location in the file system.

3 . The device of claim 1 in which one of the root directories is reserved to components forming a Trusted Computing Base.

4 . The device of claim 1 in which one or more trusted components verify whether or not a process has the required privileges or capabilities to access a file system sub-tree.

5 . The device of claim 1 in which a process is restricted to accessing only its own private area of the file system.

6 . The device of claim 5 in which the private area is accessible only to a process with a correct secure identifier.

7 . The device of claim 1 in which the root directories are each functionally equivalent to the following:

(a) a root directory with sub-trees accessible to any process that has been granted operating system privileges over all files;

(b) a root directory with sub-trees accessible only to a process with a correct secure identifier;

(c) a root directory with sub-trees that are public read-only,

(d) a root directory with sub-trees that are available to any process for file read and write operations, file creation and deletion.

8 . A single user operating system for a mobile wireless device, the operating system comprising a file insulation mechanism that maintains the integrity of an exiting file system by controlling where files are installed, the file system being portioned into multiple root directories; in which the location of a file is enough to fully identify its access policy to a process running on the device.

9 . The operating system of claim 8 in which access rights of the file are modified by moving it location in the file system.

10 . The operating system of claim 8 in which one of the root directories is reserved to components forming a Trusted Computing Base.

11 . The operating system of claim 8 in which one or more trusted components verify whether or not a process has the required privileges or capabilities to access a file system sub-tree.

12 . The operating system of claim 8 in which a process is restricted to accessing only its own private area of the file system.

13 . The operating system of claim 12 in which the private area is accessible only to a process with a correct secure identifier.

14 . The operating system of claim 8 in which the file installation mechanism allows program to contribute to another program's private are without compromising it.

15 . The operating system of claim 8 in which the root directories are each functionally equivalent to the following.

(a) a root directory with sub-trees accessible to any process that has been granted operating system privileges over all files;

(b) a root directory with sub-trees accessible only to a process with a correct secure identifier;

(c) a root directory with sub-trees that are public read-only;

(d) a root directory with sub-trees that are available to any process for file read and write operations, file creation and deletion.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2009
From: SYMBIAN LIMITED; SYMBIAN SOFTWARE LIMITED
To: NOKIA CORPORATION
Reel/Frame 022240/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2004
From: DIVE-RECLUS, CORINNE; THOELKE, ANDREW; DOWMAN, MARK
To: SYMBIAN LIMITED
Reel/Frame 016529/0330 →