IP Library Granted Patent US 9,172,538
Granted Patent B2
US 9,172,538 · App. 13/842,116 · Granted Oct 27, 2015

Secure lock for mobile device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,172,538
App. No.
13/842,116
Granted
Oct 27, 2015
Kind
B2
Abstract

A secure lock procedure for mobile devices is disclosed. The secure lock process generally includes detecting a device access attempt at a telecommunication device during a security-enabled boot sequence. The device access attempt may include a cryptographic key, which when detected, initiates a cryptographic authentication operation. The cryptographic authentication operation results in access to one or more resource of the telecommunication device being enabled, when the cryptographic key is determined to be valid, or denied, when the cryptographic key is determined to be invalid. The device access attempt may be associated with a root-level device access attempt or software flash attempt, and the secure lock procedure can be implemented in conjunction with a boot loader stored within a memory of the telecommunication device.

Claims (36)

1. A telecommunication device comprising:

one or more processors; and

a memory coupled to the one or more processors, and having at least a device operating system (OS) and a secure lock component,

wherein the secure lock component is operable by the one or more processors to:

detect a device access attempt during a boot sequence of the telecommunication device, wherein each of multiple layers in a boot stack of the boot sequence employs a cryptographic lock that is configured to be unlocked with a first security key;

initiate a cryptographic validation operation when a second security key is encountered as a part of the device access attempt; and

enable access to at least one resource of the telecommunication device in response to utilizing the first security key to determine that the second security key is valid during the cryptographic validation operation, or

deny access to the at least one resource of the telecommunication device in response to utilizing the first security key to determine that the second security key is not valid during the cryptographic validation operation.

2. The telecommunication device of claim 1 , wherein the device access attempt is a root-level device access attempt.

3. The telecommunication device of claim 1 , wherein the secure lock component comprises a secure on chip (SoC) boot loader that is configured to control the boot sequence, and wherein the boot sequence includes at least one boot layer that is bootable by the SoC bootloader to initialize the device OS.

4. The telecommunication device of claim 1 , wherein the device access attempt is a flash attempt by software, and wherein the software of the flash attempt is an unauthorized device OS or third party application.

5. The telecommunication device of claim 4 , wherein the secure lock component is further operable by the one or more processors to deny access to the at least one resource stored in the memory, in response to detecting the flash attempt.

6. The telecommunication device of claim 1 , wherein the secure lock component is further operable by the one or more processors to detect a plurality of unauthorized user access attempts at the telecommunication device, and wherein at least one of the plurality of unauthorized user access attempts is associated with an invalid unlock code that is received at an interface of the telecommunication device.

7. The telecommunication device of claim 1 , wherein the secure lock component is further operable by the one or more processors to:

detect an unauthorized software image in, or being flashed to, the memory of the telecommunication device; and

brick access to the telecommunication device in response to detecting the unauthorized software image.

8. A method comprising:

receiving, at a telecommunication device, a cryptographic identifier as a part of a root-level access attempt, wherein the root-level access attempt is an attempt to access at least one resource of the telecommunication device requiring root-level access;

determining a validity of the cryptographic identifier; and

authenticating root-level access to the at least one resource of the telecommunication device in response to determining the validity of cryptographic identifier,

wherein the root-level access attempt occurs during a secure boot sequence of the telecommunication device, and wherein each of multiple layers in a boot stack of the secure boot sequence employs a cryptographic lock that is configured to be unlocked with the cryptographic identifier.

9. The method of claim 8 , wherein the cryptographic identifier of the root-level access attempt is associated with a security key that is one of:

i) a symmetric cryptographic key,

ii) an asymmetric cryptographic public/private key, and

iii) a cryptographic hash key.

10. The method of claim 8 , further comprising bricking access to the telecommunication device in response to detecting a predetermined number of failed user access attempts.

11. A non-transitory computer storage device with a stored computer-executable program, which, when executed by one or more processors of a telecommunication device, performs operations comprising:

initiating an authentication operation in response to identifying a first cryptographic key to be a part of a device access attempted during a boot sequence of the telecommunication device, wherein each of multiple layers in a boot stack of the boot sequence employs a cryptographic lock that is configured to be unlocked with a second cryptographic key; and

enabling access to at least one resource of the telecommunication device in response to utilizing the second cryptograph key to determinate that the first cryptographic key is valid during the authentication operation, or

denying access to the at least one resource of the telecommunication device in response to utilizing the second cryptograph key to determinate that the first cryptographic key is not valid during the authentication operation.

12. The non-transitory computer storage device of claim 11 , wherein the device access attempt is an unauthorized root-level device access attempt or software flash attempt.

13. The non-transitory computer storage device of claim 11 , wherein the operations further comprise detecting a plurality of unauthorized user access attempts at the telecommunication device, and wherein at least one of the plurality of unauthorized user access attempts is associated with an invalid unlock code that is received at the telecommunication device.

14. The non-transitory computer storage device of claim 11 , wherein the operations further comprise:

detecting an unauthorized software image in, or being flashed to, a memory of the telecommunication device; and

bricking access to the telecommunication device in response to detecting the unauthorized software image.

15. The non-transitory computer storage device of claim 14 , wherein the operations further comprise generating a notification indicating a bricked or a locked status of the telecommunication device, wherein the notification includes an option for curing the bricked or locked status of the telecommunication device.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE TELEKOM AG
To: T-MOBILE USA, INC.; IBSV LLC
Reel/Frame 052969/0381 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: T-MOBILE USA, INC.; IBSV LLC; METROPCS COMMUNICATIONS, INC.; METROPCS WIRELESS, INC.; T-MOBILE SUBSIDIARY IV CORPORATION; LAYER3 TV, INC.; PUSHSPRING, INC.
Reel/Frame 052969/0314 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 30, 2016
From: T-MOBILE USA, INC.
To: DEUTSCHE TELEKOM AG
Reel/Frame 041225/0910 →
SECURITY AGREEMENT Recorded Nov 17, 2015
From: T-MOBILE USA, INC.; METROPCS COMMUNICATIONS, INC.; T-MOBILE SUBSIDIARY IV CORPORATION
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS ADMINISTRATIVE AGENT
Reel/Frame 037125/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2013
From: OBAIDI, AHMAD ARASH
To: T-MOBILE USA, INC.
Reel/Frame 030022/0305 →