IP Library Granted Patent US 12,568,093
Granted Patent B2
US 12,568,093 · App. 18/183,220 · Granted Mar 3, 2026

Methods and systems to identify a compromised device through active testing

Inventors: Chang Fung Yang (Mississauga, CA); Robert Joseph Lombardi (Kitchener, CA); Chi Hing Ng (Richmond Hill, CA); Johnathan George White (St. Albans, GB)
Assignee: BlackBerry Limited
H04L63/12G06F16/13G06F16/168G06F21/121G06F21/6218H04L67/06H04L67/306H04W12/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,093
App. No.
18/183,220
Granted
Mar 3, 2026
Kind
B2
Abstract

Methods and devices for determining whether a mobile device has been compromised. File tree structure information for the mobile device is obtained that details at least a portion of a tree-based structure of folders and files in a portion of memory. The file tree structure information is analyzed to determine that the mobile device has been compromised, has not been compromised, or might be compromised. Based on determining that the mobile device might be compromised, the mobile device is instructed to execute a restricted action. If the restricted action occurs on the mobile device then it is determined that the mobile device has been compromised. Based on that determination, an action is taken.

Claims (41)

1 . A computer-implemented method of determining whether security of a mobile device is compromised, the method comprising:

determining that the mobile device might be compromised;

based on the determination that the mobile device might be compromised, carrying out a testing operation that comprises instructing the mobile device to run a process with an expected run-time;

comparing an actual time the process runs with the expected run-time;

determining that the security of the mobile device is compromised, in response to determining that the actual time the process runs deviates from the expected run time by more than a threshold; and

based on the determination that the security of the mobile device is compromised, taking an action.

2 . The computer-implemented method of claim 1 , further comprising:

obtaining file tree structure information for the mobile device, wherein the file tree structure information details at least a portion of a tree-based structure of folders and files in a portion of memory; and

analyzing the file tree structure information to determine that the mobile device might be compromised.

3 . The computer-implemented method of claim 1 , further comprising, in response to the determination that the mobile device might be compromised, instructing the mobile device to execute an operation carried out from within a first user profile included in the mobile device with respect to a file or folder associated with a second user profile included in the mobile device that should not be able to be carried out from within the first user profile.

4 . The computer-implemented method of claim 3 , wherein the determining that the mobile device is compromised comprises determining that the operation occurs on the mobile device.

5 . The computer-implemented method of claim 4 , wherein the operation comprises running through a list of protected systems calls.

6 . The computer-implemented method of claim 1 , further comprising, in response to the determination that the mobile device might be compromised, instructing the mobile device to evaluate whether tasks are scheduled and maintained in an expected manner.

7 . The computer-implemented method of claim 6 , wherein the instructing the mobile device to investigate the system settings to determine whether items have been modified in a way that is required to gain root access comprises determining whether developer options have been changed.

8 . The computer-implemented method of claim 1 , further comprising, in response to the determination that the mobile device might be compromised, instructing the mobile device to investigate system settings to determine whether items have been modified in a way that is required to gain root access.

9 . The computer-implemented method of claim 1 , further comprising instructing the mobile device to automatically cause input of a command line instruction at the mobile device.

10 . The method of claim 1 , wherein the determining that the security of the mobile device is compromised comprises determining that the mobile device is infected with malware, spyware, or a virus, and wherein the action comprises locking the mobile device, wiping the mobile device, or denying access to the mobile device.

11 . The method of claim 1 , wherein the threshold is a threshold amount of time.

12 . A computing device comprising:

a processor;

a memory storing processor-executable instructions that, when executed by the processor, cause the processor to:

determine that the mobile device might be compromised;

based on the determination that the mobile device might be compromised, carry out a testing operation that comprises instructing the mobile device to run a process with an expected run-time;

comparing an actual time the process runs with the expected run-time;

determine that security of the mobile device is compromised, in response to determining that the actual time the process runs deviates from the expected run time by more than a threshold; and

based on the determination that the security of the mobile device has been compromised, take an action.

13 . The computing device of claim 12 , wherein the instructions, when executed, further cause the processor to:

obtain file tree structure information for the mobile device, wherein the file tree structure information details at least a portion of a tree-based structure of folders and files in a portion of the memory; and

analyze the file tree structure information to determine that the mobile device might be compromised.

14 . The computing device of claim 12 , wherein the instructions, when executed, further cause the processor to, in response to the determination that the mobile device might be compromised, execute an operation carried out from within a first user profile included in the mobile device with respect to a file or folder associated with a second user profile included in the mobile device that should not be able to be carried out from within the first user profile.

15 . The computing device of claim 14 , wherein the determining that the mobile device is compromised comprises determining that the operation occurs on the mobile device.

16 . The computing device of claim 15 , wherein the operation comprises running through a list of protected systems calls.

17 . The computing device of claim 12 , wherein the instructions, when executed, further cause the processor to, in response to the determination that the mobile device might be compromised, instructing the mobile device to evaluate whether tasks are scheduled and maintained in an expected manner.

18 . The computing device of claim 12 , wherein the instructions, when executed, further cause the processor to, in response to the determination that the mobile device might be compromised, instructing the mobile device to investigate system settings to determine whether items have been modified in a way that is required to gain root access.

19 . The computing device of claim 18 , wherein the instructing the mobile device to investigate the system settings to determine whether items have been modified in a way that is required to gain root access comprises determining whether developer options have been changed.

20 . A non-transitory computer-readable storage medium storing instructions that, when executed by a processor of a mobile device, cause the processor to:

determine that the mobile device might be compromised;

based on the determination that the mobile device might be compromised, carry out a testing operation that comprises instructing the mobile device to run a process with an expected run-time;

compare an actual time the process runs with the expected run-time;

determine that security of the mobile device is compromised, in response to determining that the actual time the process runs deviates from the expected run time by more than a threshold; and

based on the determination that the security of the mobile device is compromised, take an action.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2023
From: YANG, CHANG FUNG; LOMBARDI, ROBERT JOSEPH; NG, CHI HING
To: BLACKBERRY LIMITED
Reel/Frame 062970/0746 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2023
From: WHITE, JOHNATHAN GEORGE
To: BLACKBERRY UK LIMITED
Reel/Frame 062970/0849 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2023
From: BLACKBERRY UK LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 062970/0910 →
Continuity (2)
Continuation 16541672 · Aug 15, 2019
Related Publication 20230224307A1 · Jul 13, 2023
References Cited (45)
US 8370362B2 · Szabo · 2013 [cited by applicant]
US 10038711B1 · Gorodissky et al. · 2018 [cited by applicant]
US 10250588B1 · Tarafdar et al. · 2019 [cited by applicant]
US 10440044B1 · Zini et al. · 2019 [cited by applicant]
US 10469521B1 · Segal et al. · 2019 [cited by applicant]
US 10769277B2 · Branson · 2020 [cited by examiner]
US 10880326B1 · Gofman · 2020 [cited by applicant]
US 11632377B2 · Yang · 2023 [cited by examiner]
US 20080195676A1 · Lyon et al. · 2008 [cited by applicant]
US 20100250509A1 · Andersen · 2010 [cited by applicant]
US 20100262584A1 · Turbin et al. · 2010 [cited by applicant]
US 20130185800A1 · Miller et al. · 2013 [cited by applicant]
US 20130333033A1 · Khesin · 2013 [cited by applicant]
US 20140040630A1 · Swaminathan · 2014 [cited by applicant]
US 20140289733A1 · Fritz · 2014 [cited by examiner]
US 20140317734A1 · Valencia et al. · 2014 [cited by applicant]
US 20140344922A1 · Lam · 2014 [cited by examiner]
US 20170147827A1 · Bowers · 2017 [cited by examiner]
US 20170235966A1 · Ray · 2017 [cited by applicant]
US 20190098037A1 · Shenoy · 2019 [cited by applicant]
US 20190332576A1 · Godman · 2019 [cited by applicant]
US 20190394221A1 · Xiao · 2019 [cited by examiner]
US 20210165969A1 · Galitsky · 2021 [cited by applicant]
WO 2015187716 · 2015 [cited by applicant]
WO 2018104799 · 2018 [cited by applicant]
USPTO: US Office Action relating to U.S. Appl. No. 18/163,190 dated Jun. 8, 2023. [cited by applicant]
Extended European Search Report, Application No. EP20186204 Dec. 16, 2020. [cited by applicant]
USPTO: US Office Action relating to U.S. Appl. No. 16/541,795, dated Mar. 23, 2022. [cited by applicant]
USPTO: US Office Action relating to U.S. Appl. No. 16/541,630, dated Nov. 5, 2021. [cited by applicant]
USPTO: Advisory Action related to U.S. Appl. No. 16/541,630 dated May 4, 2022. [cited by applicant]
USPTO: US Office Action relating to U.S. Appl. No. 16/541,630 dated Jun. 3, 2022. [cited by applicant]
US Notice of Allowance, U.S. Appl. No. 16/541,672 dated Dec. 14, 2022. [cited by applicant]
US Notice of Allowance, U.S. Appl. No. 16/541,795 dated Sep. 9, 2022. [cited by applicant]
US Final Office Action, U.S. Appl. No. 16/541,672 dated Sep. 28, 2022. [cited by applicant]
2nd US Notice of Allowance, U.S. Appl. No. 16/541,795 dated Oct. 31, 2022. [cited by applicant]
US Office Action, U.S. Appl. No. 16/541,672, filed Mar. 15, 2022. [cited by applicant]
US Final Office Action, U.S. Appl. No. 16/541,672 dated Oct. 8, 2021. [cited by applicant]
US Office Action, U.S. Appl. No. 16/541,735, filed Aug. 16, 2021. [cited by applicant]
US Office Action, U.S. Appl. No. 16/541,672, filed Jun. 23, 2021. [cited by applicant]
USPTO: Advisory Action relating to U.S. Appl. No. 16/541,672, dated Dec. 22, 2020. [cited by applicant]
USPTO: US Final Office Action relating to U.S. Appl. No. 16/541,672, dated Sep. 17, 2020. [cited by applicant]
US Office Action, U.S. Appl. No. 16/541,672, filed Mar. 6, 2020. [cited by applicant]
Extended European Search Report—EP23192757.5 Nov. 24, 2023. [cited by applicant]
Michael Witt et al: “Sandboxing of biomedical applications in Linux containers based on system call evaluation”, Concurrency and Computation: Practice and Experience, Wiley, London, GB, vol. 30, No. 12, Apr. 25, 2018 (A… [cited by applicant]
Shao Yuru et al: “RootGuard: Protecting Rooted Android Phones”, IEEE Computer Society, IEEE, USA, vol. 47, No. 6, Jun. 1, 2014 (Jun. 1, 2014), pp. 32-40, XP011551335, ISSN: 0018-9162, DOI: 10.1109/MC.2014.163 [retrieved… [cited by applicant]