IP Library Granted Patent US 8,863,252
Granted Patent B1
US 8,863,252 · App. 13/557,213 · Granted Oct 14, 2014

Trusted access to third party applications systems and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,863,252
App. No.
13/557,213
Granted
Oct 14, 2014
Kind
B1
Abstract

A method of downloading trusted content. The method comprises sending by a mobile device a request for a trusted content to a server, wherein the mobile device comprises a first mobile device trusted security zone and builds the request while executing in the first mobile device trusted security zone and wherein the server comprises a server trusted security zone and wherein the server handles the request for the trusted content at least partly in the server trusted security zone. The method comprises receiving the trusted content by the first mobile device trusted security zone, storing the trusted content in a second mobile device trusted security zone of the mobile device, inspecting the trusted content in the second mobile device trusted security zone, and when the trusted content passes inspection, at least one of executing or presenting a portion of the trusted content by the first mobile device trusted security zone.

Claims (39)

1. A method of downloading trusted content, comprising:

building a request for a trusted content while executing in a secure partition of a first mobile device trusted security zone of a mobile device;

responsive to executing in the secure partition of the first mobile device trusted security zone, stopping execution of a normal partition of the mobile device;

sending, by the mobile device, the request for the trusted content to a server, wherein the server comprises a server trusted security zone that at least partly handles the request for the trusted content;

receiving, by the first mobile device trusted security zone, the trusted content, wherein the trusted content comprises a trust token that contains information about the server trusted security zone and about the transmission of the trusted content;

storing the trusted content in a second mobile device trusted security zone of the mobile device;

inspecting the trusted content in the second mobile device trusted security zone, wherein inspecting the trusted content in the second mobile device trusted security zone comprises analyzing the trust token and comparing the trust token to a predefined trust criterion; and

responsive to the trusted content passing inspection, at least one of executing at least a portion of the trusted content by the first mobile device trusted security zone or presenting at least a portion of the trusted content by the first mobile device trusted security zone on a display of the mobile device.

2. The method of claim 1 , further comprising creating the second mobile device trusted security zone in response to receiving the trusted content by the first mobile device trusted security zone, wherein the second mobile device trusted security zone is provided in a virtual processor of the mobile device.

3. The method of claim 1 , wherein inspecting the trusted content in the second mobile device trusted security zone comprises decrypting the trusted content in the second mobile device trusted security zone.

4. The method of claim 1 , wherein inspecting the trusted content in the second mobile device trusted security zone comprises at least one of scanning at least part of the trusted content with a virus scanning tool, performing a cyclic redundancy check on at least part of the trusted content, performing a checksum on at least a part of the trusted content, and executing instructions contained in the trusted content and comparing the execution behavior of the executed instructions to a manifest provided in the trusted content.

5. The method of claim 1 , further comprising responsive to the trusted content passing inspection, storing at least a portion of the trusted content in a trusted memory partition of the mobile device.

6. The method of claim 5 , wherein one of a cyclic redundancy check data provided in the trusted content or a checksum data provided in the trusted content is stored in the trusted memory partition of the mobile device.

7. The method of claim 5 , wherein a data segment portion of the trusted content is stored in the trusted memory partition of the mobile device.

8. The method of claim 1 , further comprising:

receiving a second trusted content, wherein the second trusted content designates trusted execution;

based on the designation for trusted execution of the second trusted content, executing a browser plug-in in a trusted security zone of the mobile device, wherein responsive to the browser plug-in executing in the trusted security zone of the mobile device, applications are prevented from executing in the normal partition;

translating, by the browser plug-in, a form content of the second trusted content to a trusted form content;

presenting, by the browser plug-in, the trusted form content on a display of the mobile device;

receiving, by the browser plug-in, user input directed to the trusted form content from a user interface; and

transmitting the user input to complete a confidential transaction.

9. The method of claim 8 , wherein the browser plug-in is configured for use with a plurality of different browser applications.

10. The method of claim 8 , wherein the form content is received as part of one of a hypertext markup language (HTML) document or an extensible markup language (XML) document.

11. The method of claim 8 , further comprising:

encrypting, by the browser plug-in, the user input; and

providing, by the browser plug-in, the encrypted user input to a browser executing in the normal partition, wherein the browser transmits the encrypted user input to complete the confidential transaction.

12. The method of claim 8 , further comprising encrypting, by the browser plug-in, the user input, wherein the browser plug-in transmits the encrypted user input to complete the confidential transaction.

13. The method of claim 8 , further comprising presenting, by the browser plug-in, at least a portion of the content on a display of the mobile device, wherein the portion of the content comprises at least one of a medical record, medical diagnostic information, or medical treatment information.

14. The method of claim 1 , further comprising:

receiving, by the server, the trusted content and trust credentials associated with the trusted content;

validating, by the server, the trust credentials associated with the trusted content;

when the trust credentials associated with the trusted content are deemed valid, storing the trusted content;

receiving, by the server, the request for the trusted content and trust credentials associated with the request;

validating, by the server, the trust credentials associated with the request; and

when the trust credentials associated with the request are deemed valid, sending, by the server, the trusted content to the mobile device.

15. The method of claim 14 , wherein the trust credentials associated with the trusted content comprise a trust token that contains information about a trusted end-to-end communication link by which the trusted content was received by the server.

16. The method of claim 14 , wherein the trust credentials associated with the trusted content further comprises information that promotes validating the integrity of the trusted content.

17. The method of claim 14 , wherein the server sends the trusted content to the mobile device via a trusted end-to-end communication link.

18. The method of claim 14 , wherein the server stores the trusted content and the trust credentials associated with the trusted content.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: T-MOBILE INNOVATIONS LLC
Reel/Frame 055604/0001 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2012
From: KATZER, ROBIN D.; PACZKOWSKI, LYLE W.; PARSEL, WILLIAM M.; PERSSON, CARL J.; SCHLESENER, MATTHEW C.
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 028629/0610 →