IP Library Granted Patent US 9,736,693
Granted Patent B2
US 9,736,693 · App. 14/805,296 · Granted Aug 15, 2017

Systems and methods for monitoring an operating system of a mobile wireless communication device for unauthorized modifications

Inventor: Eilon Eyal (Galil Elyon, IL)
Assignee: MOTOROLA SOLUTIONS, INC.
H04W12/08H04L43/10H04L63/1433H04L67/34H04W4/003H04W8/183H04W12/06H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,736,693
App. No.
14/805,296
Granted
Aug 15, 2017
Kind
B2
Abstract

A method and system for securely monitoring an operating system of a mobile wireless communication device for unauthorized modifications. A secure application is provided on universal integrated circuit card of the mobile wireless communication device. The secure application is configured to control the wireless connectivity of the mobile wireless communication device, and communicate with a wireless communications network. A monitoring application is provided in a trusted sub-processor of the processor of the mobile wireless communication device. A secure communication link is established between the secure application and the monitoring application. A heartbeat token is generated by the trusted sub-processor, based on a modification status for the operating system and at least one system variable. The secure application receives the heartbeat token, and determines that an unauthorized software modification exists based on the heartbeat token. The secure application activates at least one countermeasure when an unauthorized software modification exists.

Claims (34)

1. A method for secure monitoring an operating system of a mobile wireless communication device for unauthorized modifications, the mobile wireless communication device including an electronic processor and a universal integrated circuit card, the method comprising:

providing a secure application in the universal integrated circuit card, the secure application configured to disable or block wireless connectivity of the mobile wireless communication device, and communicate with a wireless communications network;

providing a monitoring application in a trusted sub-processor of the electronic processor;

establishing a secure communication link between the secure application and the monitoring application;

generating a heartbeat token based on a modification status and at least one system variable selected from the group consisting of a temporary mobile subscriber identity, a location area identity, and an international mobile subscriber identity; and

receiving, with the secure application, the heartbeat token.

2. The method of claim 1 , wherein generating the heartbeat token includes generating the heartbeat token further based on a message authentication code.

3. The method of claim 1 , further comprising:

determining, with the secure application, that an unauthorized software modification exists based on the heartbeat token; and

activating, with the secure application, at least one countermeasure.

4. The method of claim 3 , wherein determining that the unauthorized software modification exists includes verifying a message authentication code.

5. The method of claim 3 , wherein activating the at least one countermeasure includes selecting the at least one countermeasure from the group consisting of sending a message to the wireless communications network, and disabling user-accessible wireless services on the mobile wireless communication device.

6. The method of claim 1 , further comprising:

determining, with the secure application, that an unauthorized software modification exists when the heartbeat token is not received; and

activating, with the secure application, at least one countermeasure.

7. The method of claim 6 , wherein activating the at least one countermeasure includes selecting the at least one countermeasure from the group consisting of sending a message to the wireless communications network, and disabling user-accessible wireless services on the mobile wireless communication device.

8. A system for secure monitoring of an operating system of a mobile wireless communication device for unauthorized modifications, the system comprising:

a universal integrated circuit card configured to

disable or block wireless connectivity of the mobile wireless communication device, and communicate with a wireless communications network; and

receive a heartbeat token; and

an electronic processor having a trusted sub-processor, the trusted sub-processor configured to

establish a secure communication link between the trusted sub-processor and the universal integrated circuit card; and

generate the heartbeat token based on a modification status and at least one system variable selected from the group consisting of a temporary mobile subscriber identity, a location area identity, and an international mobile subscriber identity.

9. The system of claim 8 , wherein the trusted sub-processor is further configured to generate a message authentication code; and wherein generating the heartbeat token includes generating the heartbeat token further based on the message authentication code.

10. The system of claim 8 , wherein the universal integrated circuit card is further configured to determine that an unauthorized software modification exists based on the heartbeat token; and

activate at least one countermeasure.

11. The system of claim 10 , wherein determining that the unauthorized software modification exists includes verifying a message authentication code.

12. The system of claim 10 , wherein the at least one countermeasure includes at least one selected from the group consisting of sending a message to the wireless communications network, and disabling user-accessible wireless services on the mobile wireless communication device.

13. The system of claim 8 , wherein the universal integrated circuit card is further configured to determine that an unauthorized software modification exists when the heartbeat token is not received; and

activate at least one countermeasure.

14. The system of claim 13 , wherein the at least one countermeasure includes at least one selected from the group consisting of sending a message to the wireless communications network, and disabling user-accessible wireless services on the mobile wireless communication device.

15. A system for secure monitoring of an operating system of a mobile wireless communication device for unauthorized modifications, the system comprising:

a universal integrated circuit card that disables or blocks wireless connectivity of the mobile wireless communication device, communicates with a wireless communications network, and receive a heartbeat token; and

an electronic processor having a trusted sub-processor, that establishes a secure communication link between the trusted sub-processor and the universal integrated circuit card, and generates the heartbeat token based on a modification status and at least one system variable selected from the group consisting of a temporary mobile subscriber identity, a location area identity, and an international mobile subscriber identity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2015
From: EYAL, EILON
To: MOTOROLA SOLUTIONS, INC.
Reel/Frame 036146/0750 →
Continuity (1)
Related Publication 20170026840A1 · Jan 26, 2017