Providing security assurance information
View Patent ↗Systems, methods, and software can be used to provide security assurance information. In some aspects, a certificate request for a client process on a mobile device is received. A security assurance character for the client process is determined. Whether to grant the certificate request is determined based on the determined security assurance character. In response to determining to grant the certificate request, a certificate is generated.
1. A method, comprising:
receiving a certificate request for a client process on a mobile device, wherein the certificate request includes a first requested security assurance attribute;
determining a security assurance character for the client process;
determining that the security assurance character represents a same or higher security level than the first requested security assurance attribute;
determining that the first requested security assurance attribute represents a same or higher security level than a second requested security assurance attribute in a previous certificate request; and
in response to determining that the security assurance character represents a same or higher security level than the first requested security assurance attribute, and that the first requested security assurance attribute represents a same or higher security than the second requested security assurance attribute in the previous certificate request, generating a certificate for the client process, wherein the certificate includes a granted security assurance attribute.
2. The method of claim 1 , wherein the security assurance character includes a mobile device security assurance character.
3. The method of claim 1 , wherein the security assurance character includes a key generation security assurance character.
4. The method of claim 1 , wherein the granted security assurance attribute is different than the first requested security assurance attribute.
5. The method of claim 1 , wherein the security assurance character is determined based on information provided by a manufacturer of the mobile device.
6. A device, comprising:
a memory; and
at least one hardware processor communicatively coupled with the memory and configured to:
receive a certificate request for a client process on a mobile device, wherein the certificate request includes a first requested security assurance attribute;
determine a security assurance character for the client process;
determine that the security assurance character represents a same or higher security level than the first requested security assurance attribute;
determine that the first requested security assurance attribute represents a same or higher security level than a second requested security assurance attribute in a previous certificate request; and
in response to determining that the security assurance character represents a same or higher security level than the first requested security assurance attribute, and that the first requested security assurance attribute represents a same or higher security than the second requested security assurance attribute in the previous certificate request, generate a certificate for the client process, wherein the certificate includes a granted security assurance attribute.
7. The device of claim 6 , wherein the security assurance character includes a mobile device security assurance character.
8. The device of claim 6 , wherein the security assurance character includes a key generation security assurance character.
9. The device of claim 6 , wherein the granted security assurance attribute is different than the first requested security assurance attribute.
10. The device of claim 6 , wherein the security assurance character is determined based on information provided by a manufacturer of the mobile device.
11. A tangible, non-transitory computer-readable medium containing instructions which, when executed, cause a computing device to perform operations comprising:
receiving a certificate request for a client process on a mobile device, wherein the certificate request includes a first requested security assurance attribute;
determining a security assurance character for the client process;
determining that the security assurance character represents a same or higher security level than the first requested security assurance attribute;
determining that the first requested security assurance attribute represents a same or higher security level than a second requested security assurance attribute in a previous certificate request; and
in response to determining that the security assurance character represents a same or higher security level than the first requested security assurance attribute, and that the first requested security assurance attribute represents a same or higher security than the second requested security assurance attribute in the previous certificate request, generating a certificate for the client process, wherein the certificate includes a granted security assurance attribute.
12. The tangible, non-transitory computer-readable medium of claim 11 , wherein the security assurance character includes a mobile device security assurance character.
13. The tangible, non-transitory computer-readable medium of claim 11 , wherein the security assurance character includes a key generation security assurance character.
14. The tangible, non-transitory computer-readable medium of claim 11 , wherein the granted security assurance attribute is different than the first requested security assurance attribute.