IP Library Patent Application 13267849
Patent Application
App. No. 13/267,849

Authentication and authorization method for tasking in profile-based data collection

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/267,849
Abstract

An apparatus and a new method of authentication and authorization of tasking requests to data collection agents on wireless devices directly makes use of public key cryptography, rather than depending on domain-name-based authenticated using the standard HTTPS chain-of-trust: A set of digital credentials is stored in the device's secure credential store. These credentials include at least one “supertasking authority” credential, as well as one or more normal “tasking authority” credentials. Profiles are only accepted by the agent if they are signed by a trusted tasking authority credential. Supertasking authority credentials thus serve as credential authorities (CAs) for tasking authority credentials.

Claims (37)

1 . A method for operation of a data collection agent on a wireless device comprises:

receiving a signed data collection tasking profile;

reading a trusted tasking authority credential;

installing the signed data collection tasking profile after verifying the signature by the trusted tasking authority credential, and

executing the instructions contained within the verified signed data collection tasking profile.

2 . The method of claim 1 wherein the trusted tasking authority credential is a supertasking authority.

3 . The method of claim 1 wherein the trusted tasking authority credential is not issued by a supertasking authority but is signed by a supertasking authority.

4 . The method of claim 1 further comprises

reading a supertasking authority credential which was installed in the device's secure credential store at manufacture time or by a secure system software update.

5 . The method of claim 1 further comprises

discarding a data collection tasking profile which is not signed by a trusted tasking authority credential.

6 . The method of claim 1 further comprises

receiving a tasking authority credential, verifying it is signed by a supertasking authority and storing it into trusted tasking credential store.

7 . The method of claim 1 wherein a credential makes use of public key cryptography.

8 . The method of claim 2 wherein a supertasking credential is a noisy supertasking credential and the method further comprises:

displaying to the user information contained within the noisy supertasking credential, and

discarding the tasking profile when the user does not agree to the data collection, and

executing the tasking profile when the user explicitly agrees to the data collection.

9 . The method of claim 8 wherein information contained within the noisy supertasking credential is the identity of the company or entity requesting collection and transmittal of the data collection.

10 . The method of claim 9 further comprising displaying to the user the metrics the tasking profile proposes to collect if approved.

11 . The method of claim 2 wherein a supertasking credential is a silent supertasking credential and the method further comprises installing and executing a tasking profile without asking the user for permission.

12 . The method of claim 10 further comprising

keeping a list of explicitly authorized tasking authorities,

displaying on demand a selectable list of explicitly authorized tasking authorities enabling selected revocation, and

accepting any new profiles signed with a credential on the list of explicitly authorized tasking authorities without displaying information in the credential for approval.

13 . The method of claim 12 further comprising reading within a tasking authority credential a set of rules that defines what the credential permits profiles to do and validating any new profile with respect to those rules before accepting it, and/or enforce those rules at runtime.

14 . The method of claim 13 further comprising applying priorities within a credential to resolve conflicts for resources from a plurality of profiles.

15 . The method of claim 13 further comprising reporting on all the profiles which have been installed onto a wireless device.

16 . The method of claim 1 wherein a credential is a SSL certificate.

17 . The method of claim 16 wherein said SSL certificate is signed by a trusted Certificate Authority.

18 . The method of claim 1 wherein a credential may be revoked.

19 . An apparatus comprising:

a super-tasking credential store;

a profile store;

a processor configured to record, transform, and transmit metrics according to a profile read from the profile store; and

a cryptographic circuit to validate that a profile is signed by a credential read from the super-tasking credential store.

20 . The apparatus of claim 19 further comprising: a receiver circuit to receive a plurality of profiles, at least one credential, and determine priority among the plurality of profiles.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2016
From: CARRIER IQ, INC.
To: AT&T MOBILITY IP, LLC
Reel/Frame 037576/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2011
From: LACEY, BRUCE BLAINE
To: CARRIER IQ, INC.
Reel/Frame 027045/0546 →