IP Library Granted Patent US 9,426,661
Granted Patent B2
US 9,426,661 · App. 14/874,023 · Granted Aug 23, 2016

Secure lock for mobile device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,426,661
App. No.
14/874,023
Granted
Aug 23, 2016
Kind
B2
Abstract

A secure lock procedure for mobile devices is disclosed. The secure lock process generally includes detecting a device access attempt at a telecommunication device during a security-enabled boot sequence. The device access attempt may include a cryptographic key, which when detected, initiates a cryptographic authentication operation. The cryptographic authentication operation results in access to one or more resource of the telecommunication device being enabled, when the cryptographic key is determined to be valid, or denied, when the cryptographic key is determined to be invalid. The device access attempt may be associated with a root-level device access attempt or software flash attempt, and the secure lock procedure can be implemented in conjunction with a boot loader stored within a memory of the telecommunication device.

Claims (56)

1. A telecommunication device comprising:

one or more processors;

an access attempt counter; and

a memory coupled to the one or more processors, and having at least a secure lock component and a device operating system (OS),

wherein the secure lock component is operable by the one or more processors to:

initialize the access attempt counter to a default value n;

detect a device access attempt during a boot sequence of the telecommunication device, wherein each of multiple layers in a boot stack of the boot sequence employs a cryptographic lock that is configured to be unlocked with a first security key;

initiate a cryptographic validation operation when a second security key is encountered as a part of the device access attempt;

in response to utilizing the first security key to determine that the second security key is valid during the cryptographic validation operation, enable access to at least one resource of the telecommunication device; and

in response to utilizing the first security key to determine that the second security key is not valid during the cryptographic validation operation,

deny access to the at least one resource of the telecommunication device:

increment the access attempt counter value n to a value i, where i=n+1;

compare the incremented access attempt counter value i to an access attempt threshold value Th;

determine whether a counter equation i≧Th is satisfied based at least in part on the comparison; and

reboot the telecommunication device in response to determining that the incremented access attempt counter value i satisfies the counter equation.

2. The telecommunication device of claim 1 , wherein the secure lock component comprises a secure on chip (SoC) boot loader that is configured to control the boot sequence, and wherein the boot sequence includes at least one boot layer that is bootable by the SoC bootloader to initialize the device OS.

3. The telecommunication device of claim 1 , wherein the secure lock component is further operable by the one or more processors to reset the access attempt counter to the default value n, in response to determining that the incremented access attempt counter value i satisfies the counter equation.

4. The telecommunication device of claim 1 , wherein the secure lock component is further operable by the one or more processors to detect a plurality of unauthorized user access attempts at the telecommunication device, and wherein at least one of the plurality of unauthorized user access attempts is associated with an invalid unlock code that is received at an interface of the telecommunication device.

5. The telecommunication device of claim 1 , wherein the secure lock component is further operable by the one or more processors to:

detect an unauthorized software image in, or being flashed to, the memory of the telecommunication device; and

brick access to the telecommunication device in response to detecting the unauthorized software image.

6. A method comprising:

initializing, by a telecommunication device, a device access attempt counter to a default value n;

detecting a device access attempt during a boot sequence of the telecommunication device, wherein each of multiple layers in a boot stack of the boot sequence employs a cryptographic lock that is configured to be unlocked with a first security key;

initiating a cryptographic validation operation when a second security key is encountered as a part of the device access attempt; and

in response to utilizing the first security key to determine that the second security key is valid during the cryptographic validation operation, enabling access to at least one resource of the telecommunication device; or

in response to utilizing the first security key to determine that the second security key is not valid during the cryptographic validation operation,

denying access to the at least one resource of the telecommunication device;

incrementing the device access attempt counter value n to a value i, where i=n+1;

comparing the incremented device access attempt counter value i to an access attempt threshold value Th;

determining whether a counter equation i≧Th is satisfied based at least in part on the comparison; and

rebooting the telecommunication device in response to determining that the incremented device access attempt counter value i satisfies the counter equation.

7. The method of claim 6 , further comprising detecting a plurality of unauthorized access attempts at the telecommunication device, wherein at least one of the plurality of unauthorized access attempts is associated with receiving an invalid unlock code at an interface of the telecommunication device.

8. The method of claim 6 , further comprising resetting the device access attempt counter to the default value n, in response to determining that the incremented device access attempt counter value i satisfies the counter equation.

9. The method of claim 6 , further comprising generating a notification indicating a bricked or a locked status of the telecommunication device, wherein the notification includes an option for curing the bricked or locked status of the telecommunication device.

10. The telecommunication device of claim 1 , wherein the secure lock component is further operable by the one or more processors to generate a notification indicating a bricked or a locked status of the telecommunication device, wherein the notification includes an option for curing the bricked or locked status of the telecommunication device.

11. The method of claim 6 , further comprising:

detect an unauthorized software image in, or being flashed to, memory of the telecommunication device; and

brick access to the telecommunication device in response to detecting the unauthorized software image.

12. A non-transitory computer storage device with a stored computer-executable program, which, when executed by one or more processors of a telecommunication device, performs operations comprising:

initializing a device access attempt counter to a default value n;

detecting a device access attempt during a boot sequence of the telecommunication device, wherein each of multiple layers in a boot stack of the boot sequence employs a cryptographic lock that is configured to be unlocked with a first security key;

initiating a cryptographic validation operation when a second security key is encountered as a part of the device access attempt;

in response to utilizing the first security key to determine that the second security key is valid during the cryptographic validation operation, enabling access to at least one resource of the telecommunication device; and

in response to utilizing the first security key to determine that the second security key is not valid during the cryptographic validation operation,

denying access to the at least one resource of the telecommunication device;

incrementing the device access attempt counter value n to a value i, where i=n+1;

comparing the incremented device access attempt counter value i to an access attempt threshold value Th;

determining whether a counter equation i≧Th is satisfied based at least in part on the comparison; and

rebooting the telecommunication device in response to determining that the incremented device access attempt counter value i satisfies the counter equation.

13. The non-transitory computer storage device of claim 12 , wherein the operations further comprise detecting a plurality of unauthorized access attempts at the telecommunication device, wherein at least one of the plurality of unauthorized access attempts is associated with receiving an invalid unlock code at an interface of the telecommunication device.

14. The non-transitory computer storage device of claim 12 , wherein the operations further comprise resetting the device access attempt counter to the default value n, in response to determining that the incremented device access attempt counter value i satisfies the counter equation.

15. The non-transitory computer storage device of claim 12 , wherein the operations further comprise generating a notification indicating a bricked or a locked status of the telecommunication device, wherein the notification includes an option for curing the bricked or locked status of the telecommunication device.

16. The non-transitory computer storage device of claim 12 , wherein the operations further comprise:

detect an unauthorized software image in, or being flashed to, memory of the telecommunication device; and

brick access to the telecommunication device in response to detecting the unauthorized software image.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT INTERNATIONAL INCORPORATED; IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE TELEKOM AG
To: T-MOBILE USA, INC.; IBSV LLC
Reel/Frame 052969/0381 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: T-MOBILE USA, INC.; IBSV LLC; METROPCS COMMUNICATIONS, INC.; METROPCS WIRELESS, INC.; T-MOBILE SUBSIDIARY IV CORPORATION; LAYER3 TV, INC.; PUSHSPRING, INC.
Reel/Frame 052969/0314 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 30, 2016
From: T-MOBILE USA, INC.
To: DEUTSCHE TELEKOM AG
Reel/Frame 041225/0910 →
SECURITY AGREEMENT Recorded Nov 17, 2015
From: T-MOBILE USA, INC.; METROPCS COMMUNICATIONS, INC.; T-MOBILE SUBSIDIARY IV CORPORATION
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS ADMINISTRATIVE AGENT
Reel/Frame 037125/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2015
From: OBAIDI, AHMAD ARASH
To: T-MOBILE USA, INC.
Reel/Frame 036719/0901 →