IP Library Granted Patent US 8,561,144
Granted Patent B2
US 8,561,144 · App. 13/742,110 · Granted Oct 15, 2013

Enforcing security based on a security state assessment of a mobile device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,561,144
App. No.
13/742,110
Granted
Oct 15, 2013
Kind
B2
Abstract

Security data generated by an application running on a mobile communications device is stored in a database. The security data is processed to assess a current security state of the device. In response to a request from the device for access to a service provider or a request from a service provider to access the device, the current security state assessment can be provided for enforcement of a security policy.

Claims (72)

1. A system comprising:

a server for assessing the security state of a mobile communications device, the server having a server security component in communication with the mobile communications device, the server security component further accessing a database available to store security data generated by the mobile communications device;

the server security component receiving from the mobile communications device security data generated by at least one application running on the mobile communications device, and causing the received mobile communications device security data to be stored in the database accessible to the server security component;

the server security component processing the received mobile communications device security data to assess a current security state of the mobile communications device; and

in response to a request from the mobile communications device for access to a service provider or to a request from a service provider to access the mobile communications device, the server security component providing current security state assessment data to the mobile communication device for enforcement of an application-level security policy on the mobile device that determines whether to grant access to a service provider and at what level depending on the current security state assessment of the mobile communications device.

2. The system of claim 1 , wherein the server security component communicates with the database containing received mobile communications device security data and the server security component compares the received mobile communications data to other data stored in the database to assess the security state of the mobile communications device.

3. The system of claim 1 , wherein the server security component receives a request to access the service provider from the mobile communications device.

4. The system of claim 1 , wherein the server security component assesses received security events on the mobile communications device to determine severity levels for the security events, and uses this data as part of the current security state assessment.

5. A system comprising:

a server having a security component for communicating with a mobile communications device and with a service provider, the server security component further accessing a database available to store security data about the mobile communications device;

the server security component receiving from the mobile communications device security data generated by the mobile communications device and causing the received mobile communications device security data to be stored in the database accessible to the server security component;

the server security component processing the received mobile communications device security data to assess a current security state of the mobile communications device; and

in response to a request from the mobile communications device for access to the service provider, the server security component providing current security state assessment data to the requested mobile communications device for enforcement of an application-level security policy on the mobile communication device that determines whether access to the service provider is to be granted to the mobile communication device and at what level.

6. A system comprising:

a server having a security component for communicating with a mobile communications device and with a service provider, the server security component further accessing a database available to store security data generated by the mobile communications device;

the server security component receiving from the mobile communications device security data generated by the mobile communications device and causing the received mobile communications device security data to be stored in the database accessible to the server security component;

the server security component processing the received mobile communications device security data to assess a current security state of the mobile communications device; and

in response to a request from a service provider for access to the mobile communications device, the server security component providing current security state assessment data to the requested mobile communications device for enforcement of an application-level security policy on the mobile communications device that determines whether access to the mobile communications device is to be granted to the mobile communications device and at what level.

7. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

at a server security component in communication with a mobile communications device, receiving security event data generated by at least one application running on the mobile communications device;

at the server security component, processing the received event security data to determine severity levels for the security events and using this determination to assess a current security state of the mobile communications device;

at the service security component, receiving a request from the mobile communications device to access a service provider; and,

in response to request for access, at the server security component, determining whether to grant the requested access to the service provider and at what level depending upon the current security state assessment for the mobile communications device.

8. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

on a mobile communications device, receiving a request for access to the mobile communications device from a service provider;

at the mobile communications device, assessing by a mobile communication device security component a current security state of the mobile communications device based upon processing of security event data generated by the mobile communications device to determine severity levels for the security events and using this determination as part of assessing the current security state of the mobile communication device; and

at the mobile communication device security component, granting the requesting service provider access to the mobile communications device at an access level determined by the mobile communications device security component depending upon the current security state assessment of the mobile communications device.

9. The non-transitory computer readable storage medium containing computer readable instructions of claim 8 wherein the assessing a current security state of the mobile communications device includes, at the device security component, processing the security data to assess a severity of any security events on the mobile communications device to determine severity levels for the security events.

10. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

providing a server security component in communication with a mobile communications device and with a service provider;

at the server security component, receiving a request for access to the service provider from the mobile communications device;

at the server security component, in response to the request for access, assessing the current security state of the mobile communications device by

(i) processing security data generated by at least one application running on the mobile communications device;

(ii) at the server security component, providing access to a database containing mobile communications device security event information; and

at the server security component, comparing the security data generated by at least one application running on the mobile communications device received by the server security component and stored in the database against mobile communications device security event data stored in the database to assess a current security state of the mobile communications device and

(iii) at the server security component, processing the mobile communications device data received by the server security component to assess a severity of security events on the mobile communications device to determine severity levels for the security events, and using this data as part of the current security state assessment

determining whether to grant access to the service provider and at what level depending upon the current security state assessment of the mobile communications device.

11. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

providing a server security component in communication with a mobile communications device and a service provider;

at the server security component, receiving a request from the service provider for the current security state assessment of the mobile communications device;

at the server security component, assessing the current security state of the mobile communications device by

(i) processing security data generated by the mobile communications device; and

(ii) at the server security component, providing access to a database containing mobile communications device security event information; and

at the server security component, comparing the security data generated by at least one application running on the mobile communications device received by the server security component and stored in the database against mobile communications device security event data stored in the database to assess a current security state of the mobile communications device and

(iii) at the server security component, processing the mobile communications device data received by the server security component to assess a severity of security events on the mobile communications device to determine severity levels for the security events, and using this data as part of the current security state assessment

providing the security state assessment of the mobile communications device to the service provider.

12. The non-transitory computer-readable storage medium of claim 11 wherein the request for the mobile communications device's security state is received by a web API.

13. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

at a server in communication with a mobile communication device and with a service provider, receiving a request from the mobile communications device for access to the service provider;

in response to the request for access to the service provider, requesting by a server security component current security state assessment data concerning the mobile communications device requesting access to the service provider;

if the server security component determines that the mobile communications device security state assessment data is not current, assessing the current security state of the mobile communications device by the server security component obtaining from the mobile communications device event security data generated by the mobile communications device to determine severity levels for the security events and using this determination as part of assessing the current security state of the mobile communication device; and,

at the server security component, granting access to the requested service provider by the mobile communications device at an access level depending upon the current security state assessment of the mobile communications device.

14. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

at a server security component in communication with a mobile communications device, receiving security event data generated by at least one application running on the mobile communications device;

at the server security component, processing the received event security data to determine severity levels for the security events and using this determination to assess a current security state of the mobile communications device;

at the service security component, receiving a request from the mobile communications device to access a service provider; and,

in response to request for access, at the server security component, determining whether to grant the requested access to the service provider and at what level depending upon the current security state assessment for the mobile communications device.

15. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

at a server security component in communication with a mobile communications device, receiving security event data generated by at least one application running on the mobile communications device;

at the server security component, processing the received security event data to determine severity levels for the security events and using this determination to assess a current security state of the mobile communications device;

at the server security component, receiving a request from a service provider to access the mobile communications device; and,

in response to request for access, at the server security component, determining whether to grant the requested access to the mobile communications device and at what level depending upon the current security state assessment for the mobile communications device.

16. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

at a server security component in communication with a mobile communications device, receiving security event data generated by at least one application running on the mobile communications device;

at the server security component, processing the received security data to determine severity levels for the security events and using this determination to assess a current security state of the mobile communications device;

at the service security component, receiving a request from the mobile communications device to access a service provider; and,

in response to request for access, at the server security component, determining whether to grant the requested access to the service provider and at what level depending upon the current security state assessment for the mobile communications device.

17. A non-transitory computer-readable storage medium having stored thereon a plurality of instructions which, when executed by a processor, cause the processor to perform the steps of a method comprising:

at a server security component in communication with a mobile communications device, receiving security event data generated by at least one application running on the mobile communications device;

at the server security component, processing the received security event data to determine severity levels for the security events and using this determination to assess a current security state of the mobile communications device;

at the server security component, receiving a request from a service provider to access the mobile communications device; and,

in response to request for access, at the server security component, determining whether to grant the requested access to the mobile communications device and at what level depending upon the current security state assessment for the mobile communications device.

Assignments (13)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2020
From: OBSIDIAN AGENCY SERVICES, INC.
To: LOOKOUT INC.
Reel/Frame 054716/0923 →
SECURITY INTEREST Recorded Jun 6, 2019
From: LOOKOUT, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 049408/0861 →
SECURITY INTEREST Recorded Oct 29, 2018
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 048208/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2013
From: MAHAFFEY, KEVIN
To: FLEXILIS, INC.
Reel/Frame 029633/0562 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2013
From: HERING, JOHN G.
To: FLEXILIS, INC.
Reel/Frame 029633/0630 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2013
From: BURGESS, JAMES
To: FLEXILIS, INC.
Reel/Frame 029633/0693 →
CHANGE OF NAME Recorded Jan 15, 2013
From: FLEXILIS, INC.
To: LOOKOUT, INC.
Reel/Frame 029635/0256 →