IP Library Granted Patent US 8,997,181
Granted Patent B2
US 8,997,181 · App. 14/034,320 · Granted Mar 31, 2015

Assessing the security state of a mobile communications device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,997,181
App. No.
14/034,320
Granted
Mar 31, 2015
Kind
B2
Abstract

Methods for assessing the current security state of a mobile communications device. A security component installed in either the server or the mobile communications device is configured to assess the current security state by processing security data generated by the mobile communications device. If the security data is not current, then security events on the mobile communications device are evaluated to determine a severity level for the security events, and this determination is used to assess the current security state of the mobile communications device.

Claims (74)

1. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

receiving, at a server security component, security data generated by an application running on a mobile communications device;

processing, at the server security component, the received security data to make an assessment of a current security state of the mobile communications device; and

in response to a request from the mobile communications device for access to a service provider received at the server security component, providing, by the server security component, the assessment of the current security state of the mobile communications device by the server security component to the service provider for enforcement of an application-level security policy that determines whether or not to grant access to the mobile communications device and at what level.

2. The computer-readable medium of claim 1 , further comprising:

storing the received security data in a database accessible to the server security component; and

comparing the received security data to other data stored in the database in order to make the assessment of the current security state of the mobile communications device.

3. The computer-readable medium of claim 1 , further comprising:

assessing, by the server security component, security events on the mobile communications device received as part of the security data from the mobile communications device to determine severity levels for the security events, and using the assessment of the security events as part of the assessment of the current security state of the mobile communications device.

4. The computer-readable medium of claim 1 , further comprising:

if the server security component determines that the security data received from the mobile communications device is not current, then assessing, by the server security component, security events on the mobile communications device received from the mobile communications device to determine severity levels for the security events and using this determination of severity levels to assess the current security state of the mobile communication device.

5. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

receiving, at a server security component, security data generated by an application running on a mobile communications device;

processing, at the server security component, the received security data to make an assessment of a current security state of the mobile communications device; and

in response to a request from a service provider for access to the mobile communications device, received at the server security component, providing, by the server security component, the assessment of the current security state of the mobile communications device from the server security component to the mobile communications device for enforcement of an application-level security policy that determines whether or not to grant access to the service provider and at what level.

6. The computer-readable medium of claim 5 , further comprising:

storing the received security data in a database accessible to the server security component; and

comparing the received security data to other data stored in the database in order to make the assessment of the current security state of the mobile communications device.

7. The computer-readable medium of claim 5 , further comprising:

assessing, by the server security component, security events on the mobile communications device received as part of the security data from the mobile communications device to determine severity levels for the security events, and using the assessment of the security events as part of the assessment of the current security state of the mobile communications device.

8. The computer-readable medium of claim 5 , further comprising:

if the server security component determines that the security data received from the mobile communications device is not current, then assessing, by the server security component, security events on the mobile communications device received from the mobile communications device to determine severity levels for the security events and using this determination of severity levels to assess the current security state of the mobile communication device.

9. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

providing a server security component in communication with a mobile communications device and a service provider;

receiving, at the server security component, security data generated by the mobile communications device;

storing the security data in a database accessible to the server security component;

processing, at the server security component, the received and stored security data to make an assessment of a current security state of the mobile communications device; and

in response to a request from the mobile communications device for access to a service provider, received at the server security component, providing, by the server security component, the assessment of the current security state of the mobile communications device from the server security component to the service provider for enforcement of an application-level security policy that determines whether or not to grant access to the mobile communications device and at what level.

10. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

providing a server security component in communication with a mobile communications device and a service provider;

receiving, at the server security component, security data generated by the mobile communications device;

storing the security data in a database accessible to the server security component;

processing, at the server security component, the received and stored security data to make an assessment of a current security state of the mobile communications device; and

in response to a request from a service provider for access to the mobile communications device, received at the server security component, providing, by the server security component, the assessment of the current security state of the mobile communications device from the server security component to the service provider for enforcement of an application-level security policy that determines whether or not to grant access to the mobile communications device and at what level.

11. A method comprising:

at a server security component in communication with a mobile communications device, receiving security data generated by at least one application running on the mobile communications device;

at the server security component, processing the received security data to assess a current security state of the mobile communications device;

at a server in communication with the server security component, receiving a request from the mobile communications device to access a service provider;

in response to the request for access received by the server, at the server security components, determining whether to grant the requested access to the service provider and at what access level depending upon the assessment of the current security state for the mobile communications device; and

communicating to the service provider the determination of whether to grant the requested access, and if so, the access level.

12. The method of claim 11 , further comprising:

storing the received security data in a database accessible to the server security component; and

comparing the received security data to other data stored in the database in order to make the assessment of the current security state of the mobile communications device.

13. The method of claim 11 , further comprising:

assessing, by the server security component, security events on the mobile communications device received as part of the security data from the mobile communications device to determine severity levels for the security events, and using the assessment of the security events to make the assessment of the current security state of the mobile communications device.

14. A method comprising:

at a server security component in communication with a mobile communications device, receiving security data generated by at least one application running on the mobile communications device;

at the server security component, processing the received security data to assess a cuurent security state of the mobile communications device;

at a server in communication with the server security component, receiving a request from a service provider to access the mobile communications device;

in response to the request for access received by the server, at the server security component, determining whether to grant the requested access to the mobile communications device and at what level depending upon the assessment of the current security state for the mobile communications device; and

communicating to the service provider the determination of whether to grant the requested access, and if so, the access level.

15. The method of claim 14 , further comprising:

storing the received security data in a database accessible to the server security component; and

comparing the received security data to other data stored in the database in order to make the assessment of the current security state of the mobile communications device.

16. The method of claim 14 , further comprising:

assessing, by the server security component, security events on the mobile communications device received as part of the security data from the mobile communications device to determine severity levels for the security events, and using the assessment of the security events to make the assessment of the current security state of the mobile communications device.

17. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

receiving, at a server security component, security data generated by an application running on a mobile communications device;

processing, at the server security component, the received security data to make an assessment of a current security state of the mobile communications device;

receiving, at the server security component, a request from the mobile communications device to access a service provider;

in response to the request for access received at the server security component, determining, at the server security component, whether to grant the requested access to the service provider and at what access level depending upon the assessment of the current security state for the mobile communications device; and

communicating to the service provider the determination of whether to grant the requested access, and if so, the access level.

18. The computer-readable medium of claim 17 , further comprising:

storing the received security data in a database accessible to the server security component; and

comparing the received security data to other data stored in the database in order to make the assessment of the current security state of the mobile communications device.

19. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

receiving, at a server security component, security data generated by an application running on a mobile communications device;

processing, at the server security component, the received security data to make an assessment of a current security state of the mobile communications device;

receiving, at the server security component, a request from a service provider to access the mobile communications device;

in response to the request for access received at the server security component, determining, at the server security component, whether to grant the requested access to the mobile communications device and at what access level depending upon the assessment of the current security state for the mobile communications device; and

communicating to the service provider the determination of whether to grant the requested access, and if so, the access level.

20. The computer-readable medium of claim 19 , further comprising:

storing the received security data in a database accessible to the server security component; and

comparing the received security data to other data stored in the database in order to make the assessment of the current security state of the mobile communications device.

Assignments (11)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2020
From: OBSIDIAN AGENCY SERVICES, INC.
To: LOOKOUT INC.
Reel/Frame 054716/0923 →
SECURITY INTEREST Recorded Jun 6, 2019
From: LOOKOUT, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 049408/0861 →
SECURITY INTEREST Recorded Oct 29, 2018
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 048208/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2013
From: MAHAFFEY, KEVIN; HERING, JOHN G.; BURGESS, JAMES
To: FLEXILIS, INC.
Reel/Frame 031261/0507 →
CHANGE OF NAME Recorded Sep 23, 2013
From: FLEXILIS, INC.
To: LOOKOUT, INC.
Reel/Frame 031263/0941 →