IP Library › Granted Patent US 9,191,212
Granted Patent B2
US 9,191,212 · App. 14/091,320 · Granted Nov 17, 2015

Controlling application access to mobile device functions

Inventor: Giten Kulkarni (Bangalore, IN)
Assignee: NXP B.V.
H04L9/3247G06F9/468G06F21/629G06F21/6218H04L63/0823H04L63/10H04L63/123H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,191,212
App. No.
14/091,320
Granted
Nov 17, 2015
Kind
B2
Abstract

There is described a method of controlling application access to predetermined functions of a mobile device. The described method comprises (a) providing a set of keys, each key corresponding to one of the predetermined functions ( 361, 362, 363, 364 ), (b) receiving ( 225 ) an application from an application provider ( 220, 221, 222, 223 ) together with information identifying a set of needed functions, and (c) generating a signed application ( 301, 302, 309 ) by signing the received application with each of the keys that correspond to one of the needed functions identified by the received information. There is also described a device for controlling application access and a system for controlling and authenticating application access. Furthermore, there is described a computer program and a computer program product.

Claims (37)

1. A method of controlling application access to predetermined functions of a mobile device, the method comprising:

generating, with a Trusted Service Manager (TSM), a set of keys, wherein each key is unique and corresponds to only one of the predetermined functions;

receiving, in the TSM, an application from an application provider together with information identifying a set of needed functions;

generating, in the TSM, a signed application by digitally signing the received application with each of the keys that respectively corresponds to one of the needed functions identified by the received information; and

determining, in the TSM, whether the received application is to be signed based on an identity of the application provider, wherein the generating of the signed application is only carried out if it is determined that the received application is to be signed;

wherein the method is performed by one or more hardware processors.

2. The method according to claim 1 , further comprising:

transmitting the signed application from the TSM to the application provider.

3. The method according to claim 1 , further comprising:

transmitting a set of certificates corresponding to the set of keys together with information mapping each certificate to one of the predetermined functions from the TSM to a mobile device manufacturer.

4. The method according to claim 1 , wherein the step of generating the set of keys comprises

transmitting an initial set of keys from the TSM to an owner of the predetermined functions, wherein each key of the initial set of keys corresponds to one of the predetermined functions; and

receiving, in the TSM, the set of transmitted keys after it has been root signed by the owner.

5. The method according to claim 1 , wherein the predetermined functions relate to mobile device services involving Near Field Communication (NFC).

6. The method of claim 1 , wherein the TSM is a dedicated server.

7. The method of claim 6 , wherein the dedicated server is a trusted third party relative to the application provider.

8. The method of claim 6 , wherein the dedicated server is controlled by a manufacturer of the mobile device.

9. A device configured to control application access to predetermined functions of a mobile device, the device comprising:

one or more hardware processors;

a Trusted Service Manager (TSM) configured to generate a set of keys, wherein each key is unique and corresponds to only one of the predetermined functions;

a TSM configured to receive an application from an application provider together with information identifying a set of needed functions; and

a TSM configured to generate a signed application by digitally signing the received application with each of the keys that respectively corresponds to one of the needed functions identified by the received information, determine whether the received application is to be signed based on an identity of the application provider, and generate the signed application only if it is determined that the received application is to be signed.

10. The device of claim 9 , wherein the TSM is a dedicated server.

11. The device of claim 10 , wherein the dedicated server is a trusted third party relative to the application provider.

12. The device of claim 10 , wherein the dedicated server is controlled by a manufacturer of the mobile device.

13. A system for controlling and authenticating application access to predetermined functions of a mobile device, the system comprising:

a device configured to control application access to predetermined functions of a mobile device, the device comprising:

one or more hardware processors,

a Trusted Service Manager (TSM) configured to generate a set of keys, wherein each key is unique and corresponds to only one of the predetermined functions,

a TSM configured to receive an application from an application provider together with information identifying a set of needed functions, and

a TSM configured to generate a signed application by digitally signing the received application with each of the keys that respectively corresponds to one of the needed functions identified by the received information, determine whether the received application is to be signed based on an identity of the application provider, and generate the signed application only if it is determined that the received application is to be signed;

an application provider; and

a mobile device manufacturer, wherein the application provider is configured to transmit an application together with information identifying a set of needed functions to the device, and the device is configured to generate a signed application based on an application and information identifying a set of needed functions received from the application provider, the device is configured to transmit the signed application to the application provider, the device is configured to transmit a set of certificates corresponding to the generated set of keys together with information mapping each certificate to one of the predetermined functions to the mobile device manufacturer, and the mobile device manufacturer is configured to store the set of certificates and the mapping information in the mobile device.

14. The system according to claim 13 , further comprising:

an owner of the predetermined functions, the owner being configured to receive an initial set of keys from the device, wherein each key of the initial set of keys corresponds to one of the predetermined functions, the owner being further configured to root sign each key of the received initial set of keys, and transmit the root signed keys to the device.

15. The system according to claim 13 , further comprising:

a mobile device comprising a memory in which the set of certificates is stored together with the information mapping each certificate to one of the predetermined functions, the mobile device being configured to receive a signed application from the application provider and determine which of the predetermined functions the signed application is authorized to access based on the set of certificates.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2015
From: KULKARNI, GITEN
To: NXP B.V.
Reel/Frame 036200/0371 →
Priority Claims (1)
EP 12194412 · Nov 27, 2012 · regional
Continuity (1)
Related Publication 20140149737A1 · May 29, 2014