IP Library Granted Patent US 9,813,897
Granted Patent B2
US 9,813,897 · App. 15/173,433 · Granted Nov 7, 2017

Systems and methods for vehicle policy enforcement

Inventor: Michael Manente (Sudbury, MA)
Assignee: Intertrust Technologies Corporation
H04W8/22H04M1/72577H04W4/008H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,813,897
App. No.
15/173,433
Granted
Nov 7, 2017
Kind
B2
Abstract

This disclosure relates to systems and methods for vehicle policy management and enforcement. In certain embodiments, a method for enforcing a policy may include receiving policy information at a device including one or more conditions relating to a policy-managed location in a vehicle. A determination may be made whether the device is within the policy-managed location based on signals received by a short-range communication system included in the device and/or the vehicle. The received policy information may be evaluated to determine and implement one or more device actions associated with the one or more conditions.

Claims (41)

1. A method for securely managing the use of an electronic device in a policy managed location, the steps comprising:

receiving a first policy at a first electronic device from a first party, said first policy specifying one or more actions to be performed by the first device in response to detecting that it is located in a policy-managed location, said policy further including a secure policy validation code to authenticate a message associated with said policy managed location;

wirelessly receiving short range communication signals from an apparatus in proximity to the first device, said signals being operable to determine the location of the first device relative to a policy managed location within or near the apparatus;

determining if the first device is located in a policy managed location at least in part based on said signals;

receiving a message from the apparatus;

authenticating said message at least in part using the secure policy validation code; and

initiating said one or more actions if it is determined that the first device is in a policy managed location and the message authentication is successful.

2. The method of claim 1 , wherein said one or more actions comprises at least temporarily disabling a feature of the first device.

3. The method of claim 1 , wherein said secure policy validation code is a shared secret value.

4. The method of claim 2 , further comprising the step of enabling said temporarily disabled feature after a time-out period has elapsed and no additional signals are received from said apparatus.

5. The method of claim 2 , further comprising the step of enabling said temporarily disabled feature after a time-out period has elapsed and additional signals are received from said apparatus and a second said determining step using said additional signals indicates that the first device is no longer located in a policy managed location.

6. The method of claim 2 , further comprising the step of enabling said temporarily disabled feature after a time-out period has elapsed and a second message is received from the apparatus that cannot be successfully authenticated using said validation code.

7. The method of claim 2 , further comprising the steps of:

receiving a second policy at the apparatus, said second policy specifying one or more actions to be performed by the apparatus in response to detecting that a second device is located in a policy-managed location, said second policy further including a secure policy validation code to be used to authenticate one or more messages exchanged between said apparatus and a second device in proximity to the apparatus.

8. The method of claim 7 , wherein the second policy is received from said first party.

9. The method of claim 7 , wherein the first device is the same as the second device.

10. A method for securely managing the use of an electronic device in a policy managed location, the steps comprising:

receiving a first policy at a first electronic device from a first party, said first policy specifying at least temporarily disabling a feature of the first device in response to (1) determining that the first device is located in a policy-managed location and (2) authenticating a message associated with the policy managed location, said policy further including a secure policy validation code to authenticate the message associated with said policy managed location;

determining the first device is located in a policy managed location at least in part based on communication signals received from an apparatus in proximity to the first device;

receiving the message associated with the policy managed location from the apparatus;

authenticating the message at least in part using the secure policy validation code;

temporarily disabling the feature of the first device; and

enabling said temporarily disabled feature after a time-out period has elapsed.

11. The method of claim 10 , wherein enabling said temporarily disabled feature after a time-out period has elapsed further comprises enabling said temporarily disabled feature after a time-out period has elapsed and no additional signals are received from said apparatus.

12. The method of claim 10 , wherein enabling said temporarily disabled feature after a time-out period has elapsed further comprises enabling said temporarily disabled feature after a time-out period has elapsed and additional signals are received from said apparatus and a second said determining step using said additional signals indicates that the first device is no longer located in a policy managed location.

13. The method of claim 10 , wherein enabling said temporarily disabled feature after a time-out period has elapsed further comprises enabling said temporarily disabled feature after a time-out period has elapsed and a second message is received from the apparatus that cannot be successfully authenticated using said validation code.

14. The method of claim 10 , further comprising the steps of:

receiving a second policy at the apparatus, said second policy specifying one or more actions to be performed by the apparatus in response to detecting that a second device is located in a policy-managed location, said second policy further including a secure policy validation code to be used to authenticate one or more messages exchanged between said apparatus and a second device in proximity to the apparatus.

15. The method of claim 14 , wherein the second policy is received from said first party.

16. The method of claim 14 , wherein the first device is the same as the second device.

17. A method for securely managing the use of an electronic device in a policy managed location, the method comprising:

receiving a first policy at a first electronic device from a first party, said first policy specifying at least temporarily disabling a feature of the first device in response to determining that the first device is located in a policy-managed location and receiving a message associated with the policy managed location;

wirelessly receiving short range communication signals from an apparatus in proximity to the first device, said signals being operable to determine the location of the first device relative to a policy managed location within or near the apparatus;

determining the first device is located in a policy managed location at least in part based on said signals;

receiving the message associated with the policy managed location from the apparatus;

temporarily disabling the feature of the first device; and

enabling said temporarily disabled feature after a time-out period has elapsed and no additional signals are received from said apparatus.

18. The method of claim 17 , further comprising the steps of:

receiving a second policy at the apparatus, said second policy specifying one or more actions to be performed by the apparatus in response to detecting that a second device is located in a policy-managed location, said second policy further including a secure policy validation code to be used to authenticate one or more messages exchanged between said apparatus and a second device in proximity to the apparatus.

19. The method of claim 18 , wherein the second policy is received from said first party.

20. The method of claim 18 , wherein the first device is the same as the second device.

Assignments (2)
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
SECURITY INTEREST Recorded Mar 18, 2020
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD
Reel/Frame 052189/0343 →
Continuity (3)
Continuation 13769357 · Feb 17, 2013
Provisional Application 61600572 · Feb 17, 2012
Related Publication 20160286384A1 · Sep 29, 2016