IP Library Granted Patent US 8,621,191
Granted Patent B2
US 8,621,191 · App. 11/964,440 · Granted Dec 31, 2013

Methods, apparatuses, and computer program products for providing a secure predefined boot sequence

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,621,191
App. No.
11/964,440
Granted
Dec 31, 2013
Kind
B2
Abstract

An apparatus for providing a secure predefined boot sequence may include a processor. The processor may be configured to verify a predefined boot sequence certificate that defines a boot sequence for a device, verify one or more software elements referenced by the predefined boot sequence certificate, and execute one or more software elements that have been verified in the sequence defined by the predefined boot sequence certificate. Corresponding methods, systems, and computer program products are also provided.

Claims (47)

1. A method comprising:

loading a predefined boot sequence certificate pre-stored on a memory associated with a mobile computing device to be booted,

verifying, by a processor, the predefined boot sequence certificate, wherein the predefined boot sequence certificate defines a boot sequence for the device, security settings and an intended final state of the device; and

in an instance in which the predefined boot sequence certificate is verified:

verifying one or more software elements referenced by the predefined boot sequence certificate; and

executing one or more software elements that have been verified in the sequence defined by the predefined boot sequence certificate.

2. A method according to claim 1 , further comprising:

following verifying each software element referenced by the predefined boot sequence certificate and executing the one or more software elements that have been verified, determining whether the boot sequence was successfully completed; and

in an instance in which it is determined that the boot sequence was successfully completed, booting the device to the intended final state defined by the predefined boot sequence certificate.

3. A method according to claim 1 , wherein verifying the predefined boot sequence certificate comprises a security subsystem of the device verifying the predefined boot sequence certificate.

4. A method according to claim 1 , wherein verifying one or more software elements referenced by the predefined boot sequence certificate comprises a security subsystem of the device verifying the one or more software elements.

5. A method according to claim 1 , further comprising determining whether the boot sequence was successfully completed, wherein if the boot sequence was successfully completed, the method further comprises enabling security services, and wherein if the boot sequence was not successfully completed, the method further comprises limiting services provided by the device.

6. A method according to claim 1 , further comprising causing the predefined boot sequence certificate to be loaded from the memory of the device to be booted.

7. A computer program product comprising at least one non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:

a program code portion configured to load a predefined boot sequence certificate pre-stored on a memory associated with a mobile computing device to be booted,

a program code portion configured to verify a predefined boot sequence certificate, wherein the predefined boot sequence certificate defines a boot sequence for the device, security settings and an intended final state of the device; and

a program code portion configured, in an instance in which the predefined boot sequence certificate is verified, to verify one or more software elements referenced by the predefined boot sequence certificate; and

a program code portion configured to execute one or more software elements that have been verified in the sequence defined by the predefined boot sequence certificate.

8. A computer program product according to claim 7 , further comprising:

a program code portion configured, following verification of each software element referenced by the predefined boot sequence certificate and execution of the one or more software elements that have been verified, to determine whether the boot sequence was successfully completed; and

a program code portion configured, in an instance in which it is determined that the boot sequence was successfully completed, to boot the device to the intended final state defined by the predefined boot sequence certificate.

9. A computer program product according to claim 7 , wherein the program code portion configured to verify the predefined boot sequence certificate includes instructions configured to verify the predefined boot sequence certificate by causing a security subsystem of the device to verify the predefined boot sequence certificate.

10. A computer program product according to claim 7 , wherein the program code portion configured to verify one or more software elements includes instructions configured to verify one or more software elements referenced by the predefined boot sequence certificate by causing a security subsystem of the device to verify the one or more software elements.

11. A computer program product according to claim 7 , further comprising:

a program code portion configured to determine whether the boot sequence was successfully completed; and

a program code portion configured to enable security services if the boot sequence was successfully completed and to limit services provided by the device if the boot sequence was not successfully completed.

12. An apparatus comprising at least one processor and at least one memory storing computer program code, wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to at least:

load a predefined boot sequence certificate pre-stored on a memory associated with a mobile computing device to be booted,

verify a predefined boot sequence certificate, wherein the predefined boot sequence certificate defines a boot sequence for the device, security settings and an intended final state of the device; and

in an instance in which the predefined boot sequence certificate is verified:

verify one or more software elements referenced by the predefined boot sequence certificate; and

execute one or more software elements that have been verified in the sequence defined by the predefined boot sequence certificate.

13. An apparatus according to claim 12 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to further cause the apparatus to:

following verification of each software element referenced by the predefined boot sequence certificate and execution of the one or more software elements that have been verified, determine whether the boot sequence was successfully completed; and

in an instance in which it is determined that the boot sequence was successfully completed, boot the device to the intended final state defined by the predefined boot sequence certificate.

14. An apparatus according to claim 12 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to verify the predefined boot sequence certificate by causing a security subsystem to verify the predefined boot sequence certificate.

15. An apparatus according to claim 12 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to cause the apparatus to verify the one or more software elements by causing a security subsystem to verify the one or more software elements referenced by the predefined boot sequence certificate.

16. An apparatus according to claim 12 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to further cause the apparatus to:

determine whether the boot sequence was successfully completed;

in an instance in which it is determined that the boot sequence was successfully completed, to enable security services; and

in an instance in which it is determined that the boot sequence was not successfully completed, to cause only a limited set of services to be provided by the device.

17. An apparatus according to claim 12 , wherein the at least one memory and stored computer program code are configured, with the at least one processor, to further cause the apparatus to load the predefined boot sequence certificate from the memory of the device to be booted.

18. An apparatus comprising:

means for loading and verifying a predefined boot sequence certificate pre-stored on a memory of a mobile computing device to be booted, wherein the predefined boot sequence certificate defines a boot sequence for a device, security settings and an intended final state of the device;

means for, in an instance in which the predefined boot sequence certificate is verified, verifying one or more software elements referenced by the predefined boot sequence certificate; and

means for executing one or more software elements that have been verified in the sequence defined by the predefined boot sequence certificate.

19. The apparatus of claim 12 , wherein the apparatus comprises, or is embodied on the device, and wherein the device comprises a mobile phone, the mobile phone comprising a user interface configured to facilitate user control of at least some functions of the mobile phone through use of a display, the display being configured to display at least a portion of a user interface of the mobile phone to facilitate user control of at least some functions of the mobile phone.

Assignments (6)
SECURITY INTEREST Recorded Jun 1, 2021
From: WSOU INVESTMENTS, LLC
To: OT WSOU TERRIER HOLDINGS, LLC
Reel/Frame 056990/0081 →
RELEASE OF SECURITY INTEREST Recorded May 21, 2019
From: OCO OPPORTUNITIES MASTER FUND, L.P. (F/K/A OMEGA CREDIT OPPORTUNITIES MASTER FUND LP
To: WSOU INVESTMENTS, LLC
Reel/Frame 049246/0405 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2017
From: NOKIA TECHNOLOGIES OY
To: WSOU INVESTMENTS, LLC
Reel/Frame 043953/0822 →
SECURITY INTEREST Recorded Sep 21, 2017
From: WSOU INVESTMENTS, LLC
To: OMEGA CREDIT OPPORTUNITIES MASTER FUND, LP
Reel/Frame 043966/0574 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035496/0763 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2008
From: KIIVERI, ANTTI
To: NOKIA CORPORATION
Reel/Frame 020499/0187 →