IP Library Granted Patent US 10,839,075
Granted Patent B2
US 10,839,075 · App. 16/573,877 · Granted Nov 17, 2020

System and method for providing network security to mobile devices

Inventor: Shlomo Touboul (Kefar Haim, IL)
Assignee: CUPP Computing AS
G06F21/562H04L63/02H04L63/0263H04L63/145H04L63/1416H04L63/1441H04L63/20H04W12/00H04W12/12H04W12/1208
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,075
App. No.
16/573,877
Granted
Nov 17, 2020
Kind
B2
Abstract

A small piece of hardware connects to a mobile device and filters out attacks and malicious code. Using the piece of hardware, a mobile device can be protected by greater security and possibly by the same level of security offered by its associated corporation/enterprise. In one embodiment, a mobile security system includes a connection mechanism for connecting to a data port of a mobile device and for communicating with the mobile device; a network connection module for acting as a gateway to a network; a security policy for determining whether to forward content intended for the mobile device to the mobile device; and a security engine for executing the security policy.

Claims (34)

1. A system, comprising:

memory storing data transfer code,

the data transfer code operable on a mobile device having at least one mobile device processor, mobile device memory and a mobile device data port, and

the data transfer code including a redirector executable by the at least one mobile device processor, the redirector operable to redirect all network data received by the mobile device to a trusted security device before the network data is processed by the mobile device processor,

the trusted security device including at least one security device processor, security device memory and a security device data port, the security device data port configured to couple to the mobile device data port, the at least one security device processor being different than the at least one mobile device processor, the security device memory including security code and a security policy thereon,

the security code operable to receive particular network data from the redirector before the at least one mobile device processor processes the particular network data,

the security code operable to evaluate the particular network data for malware as defined the security policy; and

the security code operable to prevent at least a portion of the particular network data from being processed by the at least one mobile device processor or operable to modify at least a portion of the particular network data before being processed by the at least one mobile device processor, when the network data is determined to contain malware as defined by the security policy.

2. The system of claim 1 , wherein the security code is operable to perform gateway level security services including firewall services.

3. The system of claim 1 , wherein the security code includes at least one of antivirus software, antispyware software, a firewall, IPS/IDS software, content filtering software, a bytecode monitor, and a URL monitor.

4. The system of claim 1 , wherein the security device data port includes a USB connector.

5. The system of claim 1 , wherein the security device data port includes a PCMCIA connector.

6. The system of claim 1 , wherein the security device data port includes an Ethernet connector.

7. The system of claim 1 , wherein the security device data port includes a wireless communication module.

8. The system of claim 1 , wherein the trusted security device includes an external data port configured to receive the particular network data directly.

9. The system of claim 1 , wherein the data transfer code is operable to install a device driver to the mobile device to enable the data transfer via at least one resident device.

10. The system of claim 1 , wherein at least a portion of the trusted security device is a part of the mobile device.

11. A security method, comprising:

storing data transfer code,

the data transfer code operable on a mobile device having at least one mobile device processor, mobile device memory and a mobile device data port, and

the data transfer code including a redirector executable by the at least one mobile device processor, the redirector operable to redirect all network data received by the mobile device to a trusted security device before the network data is processed by the mobile device processor;

transferring the data transfer code to the mobile device;

receiving, by the trusted security device, particular network data from the redirector before the at least one mobile device processor processes the particular network data, the trusted security device including at least one security device processor, security device memory and a security device data port, the security device data port being coupled to the mobile device data port, the at least one security device processor being different than the at least one mobile device processor, the security device memory including security code and a security policy thereon,

using the security code to evaluate the particular network data for malware as defined the security policy; and

using the security code to prevent at least a portion of the particular network data from being processed by the at least one mobile device processor or to modify at least a portion of the particular network data before being processed by the at least one mobile device processor, when the network data is determined to contain malware as defined by the security policy.

12. The method of claim 11 , wherein the using the security code to evaluate the particular network data for malware as defined the security policy includes performing gateway level security services including firewall services.

13. The method of claim 11 , wherein the using the security code to evaluate the particular network data for malware as defined the security policy includes using at least one of antivirus software, antispyware software, a firewall, IPS/IDS software, content filtering software, a bytecode monitor, and a URL monitor.

14. The method of claim 11 , wherein the security device data port includes a USB connector.

15. The method of claim 11 , wherein the security device data port includes a PCMCIA connector.

16. The method of claim 11 , wherein the security device data port includes an Ethernet connector.

17. The method of claim 11 , wherein the security device data port includes a wireless communication module.

18. The method of claim 11 , wherein the trusted security device includes an external data port configured to receive the particular network data directly.

19. The method of claim 11 , wherein the data transfer code is operable to install a device driver to the mobile device to enable the data transfer via at least one resident device.

20. The method of claim 11 , wherein at least a portion of the trusted security device is a part of the mobile device.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded Oct 25, 2019
From: YOGGIE SECURITY SYSTEMS LTD.
To: CUPP COMPUTING AS
Reel/Frame 050834/0431 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2019
From: TOUBOUL, SHLOMO
To: YOGGIE SECURITY SYSTEMS LTD.
Reel/Frame 050834/0656 →
Continuity (9)
Continuation 16144408 · Sep 27, 2018
Continuation 15689795 · Aug 29, 2017
Continuation 15586176 · May 3, 2017
Continuation 15352553 · Nov 15, 2016
Continuation 14092756 · Nov 27, 2013
Continuation 13735836 · Jan 7, 2013
Continuation 11376919 · Mar 15, 2006
Provisional Application 60750326 · Dec 13, 2005
Related Publication 20200026853A1 · Jan 23, 2020