IP Library Granted Patent US 10,084,603
Granted Patent B2
US 10,084,603 · App. 14/297,524 · Granted Sep 25, 2018

Method and system for rendering a stolen mobile communications device inoperative

Inventors: Marc William Rogers (Moraga, CA); Brian James Buck (Livermore, CA)
Assignee: LOOKOUT, INC.
H04L9/3234G06F21/575G09C1/00H04L9/088H04W12/12H04L2209/127H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,603
App. No.
14/297,524
Granted
Sep 25, 2018
Kind
B2
Abstract

A method and system for rendering a stolen mobile communications device inoperative is presented. A determination that the mobile communications device is in a first state is made at a security component on the mobile communications device. A removal of a cryptographic key is affected at the security component on the mobile communications device.

Claims (34)

1. A method comprising:

determining, by an autonomous security component preloaded on a system partition of an internal memory of a mobile communications device where an operating system is stored, the autonomous security component configured to persist after a factory reset of the mobile communications device and the autonomous security component being separate from the operating system, that the mobile communications device is in a first state, the first state being an indication that the mobile communications device is not in possession of an authorized user;

in response to the determination that the mobile communications device is in the first state, initiating and causing, by the autonomous security component, a destruction of a cryptographic key of a bootloader from a key store on the mobile communications device;

upon initiating and causing the destruction of the cryptographic key of the bootloader, initiating, by the autonomous security component, a boot sequence at the mobile communications device; and

during the boot sequence at the mobile communications device after the destruction of the cryptographic key, booting the mobile communications device into a kernel that restricts operation of the mobile communications device so that the mobile communications device can only communicate with a single server (i) to report at least one selected from the group of: a mobile communications device location, and mobile communications device contextual information, and (ii) to receive a re-enablement cryptographic key from the single server.

2. The method of claim 1 , wherein booting the mobile communications device into a kernel that restricts operation of the mobile communications device includes booting into a specific mode.

3. The method of claim 2 , further comprising:

determining, at the autonomous security component on the mobile communications device when the mobile communications device is booted into the specific mode, that the mobile communications device is in a second state, the second state being an indication that the mobile communications device is in possession of an authorized user, and

when the mobile communications device is determined to be in the second state indicating that the mobile communications device is in possession of an authorized user, receiving, at the autonomous security component on the mobile communications device, the re-enablement cryptographic key from the single server to replace the destroyed cryptographic key from the key store.

4. The method of claim 3 , wherein the re-enablement cryptographic key received from the single server is stored in one of a Trusted Platform Module (TPM) or a separate hardware component that supports a command to cause the destruction of the cryptographic key.

5. The method of claim 1 , wherein the re-enablement cryptographic key received from the single server is stored in one of a Trusted Platform Module (TPM) or a separate hardware component that supports a command to cause the destruction of the cryptographic key.

6. The method of claim 1 , wherein the initiating, by the autonomous security component, a boot sequence at the mobile communications device includes initiating one of a reboot sequence or a power off sequence.

7. The method of claim 1 , wherein the cryptographic key of the bootloader on the mobile communications device comprises information unique to the mobile communications device.

8. The method of claim 7 , wherein the information unique to the mobile communications device is an International Mobile Station Equipment Identity (IMEI) number.

9. The method of claim 1 , wherein the cryptographic key on the mobile communications device is a cryptographic key used to decrypt encrypted device storage contents.

10. A method comprising:

determining, by an autonomous security component preloaded on a system partition of an internal memory of a mobile communications device where an operating system is stored, the autonomous security component configured to persist after a factory reset of the mobile communications device and the autonomous security component being separate from the operating system, that the mobile communications device is not in possession of an authorized user;

when the determination is that the mobile communications device is not in possession of an authorized user, receiving, from a single server and at the autonomous security component, a first cryptographic key;

encrypting, at the autonomous security component, device storage contents with the first cryptographic key;

after encrypting the device storage contents, initiating and causing, by the autonomous security component, a destruction of a second cryptographic key from a key store on the mobile communications device, the second cryptographic key being a cryptographic key of a bootloader;

upon initiating and causing the destruction of the second cryptographic key, initiating, by the autonomous security component, a boot sequence at the mobile communications device; and

during the boot sequence at the mobile communications device after the destruction of the second cryptographic key, booting the mobile communications device into a kernel that restricts operation of the mobile communications device so that the mobile communications device can only communicate with the single server (i) to report at least one selected from the group of: a mobile communications device location, and mobile communications device contextual information, and (ii) to receive a re-enablement second cryptographic key from the single server.

11. The method of claim 10 , wherein the re-enablement second cryptographic key is retrievable from the single server by a security program operating on the mobile communications device, the re-enablement second cryptographic key being retrievable when the single server determines that the security program fulfills predetermined security privileges criteria.

12. The method of claim 10 , wherein the re-enablement second cryptographic key received from the single server is not stored on the mobile communications device.

13. A non-transitory computer-readable medium encoded with a plurality of instructions which, when executed by a processor, cause the processor to perform a method comprising:

receiving, at a server, an indication that a mobile communications device is not in possession of an authorized user;

sending, from the server, a first command for a security component preloaded on a system partition of an internal memory of the mobile communications device where an operating system is stored, the security component configured to persist after a factory reset and the security component being separate from the operating system, the first command directing the security component to encrypt data stored on the mobile communications device using a first cryptographic key from the server;

upon receiving from the security component of the mobile communications device confirmation that the data stored has been encrypted, sending, from the server, a second command for the security component of the mobile communications device to cause a destruction of a second cryptographic key from a key store on the mobile communications device, the second cryptographic key being a cryptographic key of a bootloader, wherein, upon causing the destruction of the second cryptographic key of the bootloader, the security component autonomously initiates a boot sequence at the mobile communications device; and

during the boot sequence at the mobile communications device after the destruction of the second cryptographic key, booting the mobile communications device into a kernel that restricts operation of the mobile communications device so that the mobile communications device can only communicate with the server (i) to report at least one selected from the group of: a mobile communications device location, and mobile communications device contextual information, and (ii) to receive a re-enablement second cryptographic key from the server.

14. The non-transitory computer-readable medium of claim 13 , wherein the security component autonomously initiating a boot sequence at the mobile communications device includes the security component of the mobile communications device initiating one of a reboot sequence or a power off sequence.

15. The non-transitory computer-readable medium of claim 14 , wherein booting the mobile communications device into a kernel that restricts operation of the mobile communications device includes booting into a specific mode.

16. The non-transitory computer-readable medium of claim 13 , further comprising instructions for:

receiving, at the server, an indication that the mobile communications device, after having been booted into the kernel that restricts operation of the mobile communications device, is in a second state indicating that the mobile communications device is in possession of an authorized user;

sending, upon receiving the indication that the mobile communications device is in the second state, the re-enablement second cryptographic key from the server to the mobile communications device.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2023
From: LOOKOUT, INC.
To: F-SECURE CORPORATION
Reel/Frame 065027/0342 →
RELEASE OF PATENT SECURITY INTEREST REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 064120/0985 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
RELEASE OF SECURITY INTEREST Recorded Nov 23, 2020
From: OBSIDIAN AGENCY SERVICES, INC.
To: LOOKOUT INC.
Reel/Frame 054716/0923 →
SECURITY INTEREST Recorded Jun 6, 2019
From: LOOKOUT, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 049408/0861 →
SECURITY INTEREST Recorded Oct 29, 2018
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 048208/0947 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2014
From: ROGERS, MARC WILLIAM; BUCK, BRIAN JAMES
To: LOOKOUT, INC.
Reel/Frame 033094/0232 →
Continuity (2)
Provisional Application 61834388 · Jun 12, 2013
Related Publication 20140372743A1 · Dec 18, 2014
Cited By (9)
US 12,277,234 US 12,282,567 US 12,306,998 US 12,321,467 US 12,346,463 US 12,376,069 US 12,481,502 US 12,581,269 US 12,658,018