IP Library Granted Patent US 10,642,730
Granted Patent B2
US 10,642,730 · App. 16/244,159 · Granted May 5, 2020

Secure garbage collection on a mobile device

Inventors: Herbert Anthony Little (Waterloo, CA); Neil Patrick Adams (Waterloo, CA); Stefan E. Janhunen (Waterloo, CA); John Fredric Arthur Dahms (Waterloo, CA)
Assignee: Citrix Systems International GmbH
G06F12/0253G06F12/0261G06F12/1408G06F16/951G06F21/62H04L9/00H04L63/0435H04L63/061G06F2212/1044G06F2212/1052G06F2212/171G06F2212/402G06F2212/702G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,642,730
App. No.
16/244,159
Granted
May 5, 2020
Kind
B2
Abstract

Methods and systems for performing garbage collection involving sensitive information on a mobile device are described herein. Secure information is received at a mobile device over a wireless network. The sensitive information is extracted from the secure information. A software program operating on the mobile device uses an object to access the sensitive information. Secure garbage collection is performed upon the object after the object becomes unreachable.

Claims (32)

1. A method for performing secure garbage collection involving unreferenced data objects on a computing device, the method comprising, in response to data indicating that the particular data object has become unreferenced:

calling a wipe function to overwrite the addressable storage memory of the computing device where a first, second, and third data objects are stored, wherein the third data object is the particular data object, and

reclaiming the addressable storage memory where the first, second, and third data objects were stored.

2. The method of claim 1 , further comprising:

receiving information over a network;

creating the first data object corresponding to the received information;

storing the first data object in an addressable storage memory on the computing device; and

extracting the second data object from the first data object, wherein the second data object is accessible using the third data object.

3. The method of claim 2 , wherein the first data object is a secure data object comprising an encrypted message, the second data object is a sensitive data object comprising an unencrypted message of the first data object, and the third data object is a user interface object, and wherein said extracting further comprises generating, by a private key, the second data object from the first data object.

4. The method of claim 2 , wherein the first, second, and third data objects are indexed inside of storage elements in a reference table in the addressable storage memory.

5. The method of claim 2 , wherein said unreferencing is performed in response to receiving a trigger event, the trigger event comprising at least a timeout event, a holster event, a cradle event, a screen lock event, a screen unlock event, an application event, a time zone alteration event, or a communication event.

6. The method of claim 2 , wherein the first data object is an S/MIME encrypted message.

7. The method of claim 6 , wherein the second data object is an unencrypted version of the S/MIME message.

8. The method of claim 6 , wherein the object is a user interface object configured to display the sensitive information.

9. One or more non-transitory computer readable media comprising computer readable instructions that, when executed, cause a computing device to perform, in response to data indicating that the particular data object has become unreferenced:

calling a wipe function to overwrite the addressable storage memory of the computing device where a first, second, and third data objects are stored, wherein the third data object is the particular data object, and

reclaiming the addressable storage memory where the first, second, and third data objects were stored.

10. The computer readable media of claim 9 , wherein the first data object is a secure data object comprising an encrypted message, the second data object is a sensitive data object comprising an unencrypted message of the first data object, and the third data object is a user interface object, and wherein said extracting further comprises generating, by a private key, the second data object from the first data object.

11. The computer readable media of claim 9 , wherein the first, second, and third data objects are indexed inside of storage elements in a reference table in the addressable storage memory.

12. The computer readable media of claim 9 , wherein said unreferencing is performed in response to receiving a trigger event, the trigger event comprising at least a timeout event, a holster event, a cradle event, a screen lock event, a screen unlock event, an application event, a time zone alteration event, or a communication event.

13. The computer readable media of claim 9 , wherein the first data object is an S/MIME encrypted message.

14. The computer readable media of claim 13 , wherein the second data object is an unencrypted version of the S/MIME message.

15. The non-transitory computer readable media of claim 9 , wherein the mobile device is one of a mobile communication device, a cellular telephone with messaging capabilities, a mobile device with wireless two-way communications, a data messaging device, or an internet appliance.

16. The non-transitory computer readable media of claim 9 , wherein the sensitive information is an S/MIME encrypted message.

17. The non-transitory computer readable media of claim 9 , wherein the sensitive information arises from use of a Personal Information Management (PIM) application.

18. The non-transitory computer readable media of claim 9 , wherein overwriting the unreachable object includes overwriting the memory location where the unreachable object is stored with a sequence of bits comprising all zeros, all ones, or random data.

19. The non-transitory computer readable media of claim 9 , wherein the object is a user interface object configured to display the sensitive information.

20. A system comprising:

a processor; and

memory storing computer readable instructions that, when executed, cause the system to perform, in response to data indicating that the particular data object has become unreferenced:

calling a wipe function to overwrite the addressable storage memory of the computing device where a first, second, and third data objects are stored, wherein the third data object is the particular data object, and

reclaiming the addressable storage memory where the first, second, and third data objects were stored.

Assignments (1)
CHANGE OF NAME Recorded Nov 7, 2023
From: CITRIX SYSTEMS INTERNATIONAL GMBH
To: CLOUD SOFTWARE GROUP SWITZERLAND GMBH
Reel/Frame 065478/0561 →
Continuity (8)
Continuation 15389756 · Dec 23, 2016
Continuation 15078435 · Mar 23, 2016
Division 14635845 · Mar 2, 2015
Continuation 13556959 · Jul 24, 2012
Continuation 12702635 · Feb 9, 2010
Continuation 10508187
Provisional Application 60365515 · Mar 20, 2002
Related Publication 20190220398A1 · Jul 18, 2019