SYSTEM AND METHOD OF HANDLING ENCRYPTED BACKUP DATA
By using a symmetric key to encrypt mobile device data before transmitting the data to a backup location in a backup operation, access to the data, at the backup location, may be restricted. To facilitate later decryption of the backed up mobile device data, the mobile device may also transmit the symmetric key to the off-device location. However, to limit use of the symmetric key, the mobile device may encrypt the symmetric key using authentication data, before transmitting the encrypted symmetric key to the backup location.
1 . At a mobile communication device, a method of facilitating secure backing up of data in a backup location, said method comprising:
encrypting a symmetric key to form an encrypted symmetric key;
transmitting said encrypted symmetric key to said backup location; and
encrypting said data with said symmetric key, thereby forming encrypted data.
2 . The method of claim 1 further comprising transmitting said encrypted data to said backup location.
3 . The method of claim 1 further comprising receiving authentication data and wherein said encrypting involves using said authentication data.
4 . The method of claim 3 further comprising generating said symmetric key.
5 . The method of claim 4 wherein said generating said symmetric key involves using said authentication data.
6 . The method of claim 4 wherein said authentication data comprises an alphanumeric password.
7 . The method of claim 6 further comprising:
receiving an indication of a new password;
encrypting said symmetric key using said new password, to form a new encrypted symmetric key; and
transmitting said new encrypted symmetric key to said backup location.
8 . The method of claim 1 wherein said data comprises application-specific data.
9 . The method of claim 1 further comprising storing, in a non-volatile portion of a memory at said mobile communication device, said symmetric key.
10 . The method of claim 9 further comprising:
transmitting a request, to said backup location, for said encrypted data;
receiving said encrypted data;
retrieving, from said memory, said symmetric key; and
using said symmetric key to decrypt said encrypted data.
11 . A mobile communication device comprising:
a processor adapted to:
encrypt a symmetric key to form an encrypted symmetric key; and
encrypt said data with said symmetric key, thereby forming encrypted data; and
a transmitter adapted to, responsive to commands from said processor:
transmit said encrypted symmetric key to a backup location.
12 . A computer-readable medium containing computer-executable instructions that, when performed by a processor for facilitating secure backing up of data in backup location, cause said processor to:
encrypt a symmetric key to form an encrypted symmetric key;
transmit said encrypted symmetric key to a backup location; and
encrypt said data with said symmetric key, thereby forming encrypted data.
13 . At a mobile communication device, a method of restoring previously backed up data, said method comprising:
transmitting a request for said previously backed up data;
receiving said previously backed up data;
transmitting a request for a key used to encrypt said previously backed up data;
receiving said key;
using authentication data to decrypt said key, thereby producing a decrypted key; and
using said decrypted key to decrypt said previously backed up data.
14 . The method of claim 13 further comprising displaying a prompt for said authentication data.
15 . The method of claim 13 further comprising, responsive to said receiving said previously backed up data, notifying applications of said receiving.
16 . A mobile communication device comprising:
a transmitter adapted to:
transmit a request for previously backed up data; and
transmit a request for a key used to encrypt said previously backed up data;
a receiver adapted to:
receive said previously backed up data; and
receive said key; and
a processor adapted to:
use authentication data to decrypt said key, thereby producing a decrypted key; and
use said decrypted key to decrypt said previously backed up data.
17 . A computer-readable medium containing computer-executable instructions that, when performed by a processor for restoring previously backed up data, cause said processor to:
transmit a request for said previously backed up data;
receive said previously backed up data;
transmit a request for a key used to encrypt said previously backed up data;
receive said key;
use authentication data to decrypt said key, thereby producing a decrypted key; and
use said decrypted key to decrypt said previously backed up data.
18 . At a mobile communication device, a method of facilitating access to encrypted data restored from a backup location, said method comprising:
receiving an encrypted version of a key, where said key has been used to encrypt said encrypted data;
determining that authentication data has been received; and
using said authentication data to decrypt said encrypted version of said key.
19 . The method of claim 18 further comprising, before said determining:
determining that said authentication data has not been received; and
waiting a predetermined duration.
20 . The method of claim 18 further comprising:
receiving, from said backup location, said encrypted data; and
using said key to decrypt said encrypted data.
21 . At a mobile communication device, a method of facilitating access to encrypted data restored from a backup location, said method comprising:
receiving an encrypted version of a key, where said key has been used to encrypt said encrypted data;
employing a user interface of said mobile communication device to display a prompt requesting authentication data;
determining that said authentication data has been provided; and
using said authentication data to decrypt said encrypted version of said key.