IP Library Granted Patent US 12,021,856
Granted Patent B2
US 12,021,856 · App. 17/663,232 · Granted Jun 25, 2024

Unified mobile security system and method of operation

Inventors: Dustin Michael Moore (San Jose, CA); R. Travis Jones (Lake Zurich, IL); Bruce Blaine Lacey (Foster City, CA)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/0823H04L9/321H04L63/126H04W4/14H04W12/03H04W12/06H04L9/006H04L9/3263H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,021,856
App. No.
17/663,232
Granted
Jun 25, 2024
Kind
B2
Abstract

A mobile secure agent on a wireless device executes one or more authenticated data collection profiles provisioned by a private profile producer. Each data package can only be transmitted to a collector certificated by the same private profile producer. Update profiles are signed and provisioned through a tunnel initiated from the mobile secure agent. A Certificate Authority provides libraries, anchors, and certificates in a key management message module to each mobile secure agent which enables revocation and replacement of certificates. Data stored in this way on a wireless device may only be transmitted in encrypted form to an authenticated destination.

Claims (49)

1. A method, comprising:

generating, by a system comprising a processor of a unified mobile security certificate authority, a first certificate for authentication, wherein the first certificate authenticates a private profile producer, wherein the private profile producer is configured to generate a certified profile for distribution to a mobile secure agent operating on a mobile device;

receiving, by the system, a profile from the private profile producer;

signing, by the system, the received profile as the unified mobile security certificate authority;

storing, by the system, the signed profile at a profile update provisioner server;

providing, by the system, the profile update provisioner server with a second certificate signed as the unified mobile security certificate authority;

receiving, by the system, a request from the mobile secure agent to establish a secure channel

receiving, by the system, an encrypted data package generated in accordance with the certified profile from the mobile secure agent;

provisioning, by the system, a data package collector with a third certificate that authorizes the data package collector to receive the encrypted data package during transit from the mobile secure agent that received the certified profile, wherein the third certificate at the data package collector prevents data packages from being misrouted to unauthorized receivers; and

provisioning, by the system, the data package collector with a key that allows the data package collector to decrypt the encrypted data package.

2. The method of claim 1 , further comprising signing, by the system, a black short message system (SMS) message as the unified mobile security certificate authority and transmitting the black short message system (SMS) message to one or more mobile secure agents.

3. The method of claim 1 , further comprising distributing, by the system, the certified profile to the mobile secure agent over the secure channel.

4. The method of claim 1 , wherein the request is generated in response to a notification from the data package collector.

5. The method of claim 4 , wherein the notification comprises a black short message.

6. The method of claim 1 , further comprising delivering, by the system, a key management message to the mobile secure agent over the secure channel.

7. The method of claim 6 , wherein the key management message revokes the third certificate.

8. A system, comprising:

a processor of a unified mobile security certificate authority; and

a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:

generating a first certificate for authentication, wherein the first certificate authenticates a private profile producer, wherein the private profile producer is configured to generate a certified profile for distribution to a mobile secure agent operating on a mobile device;

receiving a profile from the private profile producer;

signing the received profile as the unified mobile security certificate authority;

storing the signed profile at a profile update provisioner server;

providing the profile update provisioner server with a second certificate signed as the unified mobile security certificate authority;

receiving a request from a mobile secure agent to establish a secure channel;

receiving an encrypted data package from the mobile secure agent, wherein the encrypted data package is generated based on a certified profile;

authorizing, via a third certificate, a data package collector to receive the encrypted data package during transit from the mobile secure agent that received the certified profile, wherein the third certificate at the data package collector prevents data packages from being misrouted to unauthorized receivers; and

providing a key to the data package collector that permits the data package collector to decrypt the encrypted data package.

9. The system of claim 8 , wherein the private profile producer is configured to generate the certified profile for distribution to the mobile secure agent operating on a mobile device.

10. The system of claim 8 , wherein the operations further comprise sending the certified profile to the mobile secure agent over the secure channel.

11. The system of claim 8 , wherein the request is generated in response to a notification from the data package collector.

12. The system of claim 11 , wherein the notification comprises a black short message.

13. The system of claim 8 , wherein the operations further comprise sending a key management message to the mobile secure agent over the secure channel.

14. The system of claim 13 , wherein the key management message revokes the third certificate.

15. A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processor of a unified mobile security certificate authority, facilitate performance of operations, comprising:

generating a first certificate for authentication, wherein the first certificate authenticates a private profile producer;

receiving a profile from the private profile producer;

signing the received profile as the unified mobile security certificate authority;

storing the signed profile at a profile update provisioner server;

providing the profile update provisioner server with a second certificate signed as the unified mobile security certificate authority;

receiving a request from a mobile secure agent to establish a secure channel;

receiving an encrypted data package from the mobile secure agent, wherein the encrypted data package is generated based on a certified profile;

sending a third certificate to a data package collector that authenticates the data package collector to receive the encrypted data package during transit from the mobile secure agent that received the certified profile, wherein the third certificate at the data package collector prevents data packages from being misrouted to unauthorized receivers; and

sending a key to the data package collector that enables the data package collector to decrypt the encrypted data package.

16. The non-transitory machine-readable medium of claim 15 , wherein the private profile producer is configured to generate the certified profile for distribution to the mobile secure agent operating on a mobile device.

17. The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise sending the certified profile to the mobile secure agent over the secure channel.

18. The non-transitory machine-readable medium of claim 15 , wherein the request is generated in response to a notification from the data package collector.

19. The non-transitory machine-readable medium of claim 18 , wherein the notification comprises a black short message.

20. The non-transitory machine-readable medium of claim 15 , wherein the operations further comprise sending a key management message to the mobile secure agent over the secure channel.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2023
From: MOORE, DUSTIN MICHAEL; JONES, R. TRAVIS; LACEY, BRUCE BLAINE
To: CARRIER IQ, INC
Reel/Frame 064831/0407 →
MERGER Recorded Jan 10, 2023
From: AT&T MOBILITY IP, LLC
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 062327/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2022
From: CARRIER IQ, INC.
To: AT&T MOBILITY IP, LLC
Reel/Frame 059897/0692 →
Continuity (4)
Division 16803036 · Feb 27, 2020
Continuation 15980504 · May 15, 2018
Division 13726580 · Dec 25, 2012
Related Publication 20220278979A1 · Sep 1, 2022