×

System for enforcing security policies on mobile communications devices

  • US 8,413,209 B2
  • Filed: 03/27/2006
  • Issued: 04/02/2013
  • Est. Priority Date: 03/27/2006
  • Status: Active Grant
First Claim
Patent Images

1. A system for enforcing security policies on mobile communications devices, the mobile communications devices being adapted to be used in a mobile communications network in operative association with a subscriber identity module, the system having a client-server architecture and comprising:

  • a server including a computer operated by a mobile communications network operator; and

    a client resident on a mobile communications device on which security policies are to be enforced,wherein said server is adapted to;

    determine security policies to be applied on said mobile communications device;

    send thereto a security policy to be applied; and

    send to the client a policy apply message instructing the client to apply a specified security policy already stored in the client,the server comprising a server authentication function adapted to authenticate the security policy to be sent to the mobile communications device; and

    wherein the mobile communication device, when instructed by said client, is adapted to;

    receive the security policy to be applied from the server;

    assess authenticity of the security policy received from the server by exploiting a client authentication function resident on the subscriber identity module; and

    apply the received security policy;

    the mobile communication device further comprising;

    an interface component, which, when the subscriber identity module is executed by the mobile communications device, interacts with the subscriber identity module;

    the interface component invoking the client authentication function on the subscriber identity module when the client receives the security policy; and

    the client authentication function resident on the subscriber identity module calculating authentication information on the security policy received from the server; and

    a manager module, upon receipt from the server of the policy apply message, causes the client to;

    invoke the client authentication function for assessing an integrity of the identified security policy by exploiting the authentication information; and

    pass the specified security policy to an enforcer module for applying the specified security policy.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×