IP Library Granted Patent US 11,030,338
Granted Patent B2
US 11,030,338 · App. 16/561,132 · Granted Jun 8, 2021

Selectively wiping a remote device

Inventors: Michael Kenneth Brown (Fergus, CA); Michael Stephen Brown (Kitchener, CA); Herbert Anthony Little (Waterloo, CA); Scott William Totzke (Waterloo, CA)
Assignee: BlackBerry Limited
G06F21/6245G06F21/602G06F21/6218G06F21/88H04L63/0428H04L63/101H04L63/105H04W12/02H04W12/033H04W12/08G06F2221/2107G06F2221/2113G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,338
App. No.
16/561,132
Granted
Jun 8, 2021
Kind
B2
Abstract

A system and method for selectively securing data from unauthorized access on a client device storing a plurality of data types with reference to an authorization level indicated in a command. A command is received at a client device comprising an authorization level indicator. Based on at least one predefined rule, which may be implemented in an IT policy stored at the client device, each of the plurality of data types to be secured is determined, and then the data corresponding to those types is secured. The data may be secured by encrypting and/or deleting the data at the client device. The predefined rules associated with each authorization level may be configured by a user or administrator having an authorization level that exceeds the associated authorization level.

Claims (41)

1. A method of securing data on a client device, the method comprising:

determining, at a server, an authorization level for a command issuer when the command issuer logs into the server, the command issuer being associated with one of a plurality of administrator authorization levels;

creating, at the server, a securing command for securing the client device by:

determining that an administrator authorization level associated with the command issuer provides access to security settings of the client device;

determining that the client device is to be secured based on the command issuer defining, at the server, a predetermined number of times a password is allowed to be incorrectly entered at the client device; and

generating the securing command for securing the client device when the password is incorrectly entered at the client device the predetermined number of times, the securing command including the authorization level of the command issuer; and

transmitting the securing command from the server to the client device.

2. The method of claim 1 , wherein the securing includes deleting at least one data type of a plurality of data types stored on the client device.

3. The method of claim 1 , wherein the client device stores data of a plurality of data types, and wherein the securing includes encrypting at least one data type.

4. The method of claim 3 , wherein the command issuer is a user, and wherein the at least one data type is personal data associated with the user.

5. The method of claim 4 , wherein a second data type is not the at least one data type to be encrypted, and wherein the second data type is not associated with the created securing command.

6. The method of claim 1 , wherein the client device stores data of a plurality of data types, and wherein the command issuer is an administrator, and wherein securing the client device includes securing at least one data type that is not personal data.

7. The method of claim 6 , wherein a second data type is personal data, and wherein the second data type is not associated with the created securing command.

8. The method of claim 1 , wherein the securing command for securing the client device includes securing at least one of applications, data files created at the client device, or data received at the client device that are personal to a user.

9. The method of claim 1 , wherein the securing command for securing the client device includes securing at least one data type in a plurality of data types that is not user-created data, and wherein generating the securing command includes:

generating the securing command to secure data that is not user-created data and preventing the securing of user-created data.

10. A server comprising:

a memory;

a communication subsystem; and

a processor operatively connected to the memory and the communication subsystem, the processor being configured to:

determine an authorization level for a command issuer when the command issuer logs into the server, the command issuer being associated with one of a plurality of administrator authorization levels;

create a securing command for securing a client device by:

determining that the client device is to be secured based on the command issuer defining, at the server, a predetermined number of times a password is allowed to be incorrectly entered at the client device; and

generating the securing command for securing the client device when the password is incorrectly entered at the client device the predetermined number of times, the securing command including the authorization level of the command issuer; and

transmit the securing command from the server to the client device.

11. The server of claim 10 , wherein the securing includes deleting at least one data type of a plurality of data types stored on the client device.

12. The server of claim 10 , wherein the client device stores data of a plurality of data types, and wherein the securing includes encrypting at least one data type.

13. The server of claim 12 , wherein the command issuer is a user, and wherein the at least one data type is personal data associated with the user.

14. The server of claim 13 , wherein a second data type is not the at least one data type to be encrypted, and wherein the second data type is not associated with the created securing command.

15. The server of claim 10 , wherein the client device stores data of a plurality of data types, and wherein the command issuer is an administrator, and wherein securing the client device includes securing at least one data type that is not personal data.

16. The server of claim 15 , wherein a second data type is personal data, and wherein the second data type is not associated with the created securing command.

17. The server of claim 10 , wherein the securing command for securing the client device includes securing at least one of applications, data files created at the client device, or data received at the client device that are personal to a user.

18. The server of claim 10 , wherein the securing command for securing the client device includes securing at least one data type in a plurality of data types that is not user-created data, and wherein generating the securing command includes:

generating the securing command to secure data that is not user-created data and preventing the securing of user-created data.

19. A non-transitory computer-readable medium storing code which, when executed by one or more processor of a server, cause the server to perform operations comprising:

determining an authorization level for a command issuer when the command issuer logs into the server, the command issuer being associated with one of a plurality of administrator authorization levels;

creating a securing command for securing a client device by:

determining that the client device is to be secured based on the command issuer defining, at the server, a predetermined number of times a password is allowed to be incorrectly entered at the client device; and

generating the securing command for securing the client device when the password is incorrectly entered at the client device the predetermined number of times, the securing command including the authorization level of the command issuer; and

transmitting the securing command from the server to the client device.

20. The non-transitory computer-readable medium of claim 19 , wherein the securing includes deleting at least one data type of a plurality of data types stored on the client device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2019
From: BROWN, MICHAEL K.; BROWN, MICHAEL S.; LITTLE, HERBERT A.; TOTZKE, SCOTT W.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 050276/0290 →
CHANGE OF NAME Recorded Sep 5, 2019
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 050276/0663 →
Continuity (7)
Continuation 16187065 · Nov 12, 2018
Continuation 15475901 · Mar 31, 2017
Continuation 14816271 · Aug 3, 2015
Continuation 13245061 · Sep 26, 2011
Continuation 12016723 · Jan 18, 2008
Provisional Application 60885796 · Jan 19, 2007
Related Publication 20190392172A1 · Dec 26, 2019