US2022263868A1PendingUtilityA1
Methods and systems for providing a secure connection to a mobile communications device with the level of security based on a context of the communication
Est. expiryNov 4, 2033(~7.3 yrs left)· nominal 20-yr term from priority
H04L 63/08H04L 63/105H04L 63/20H04L 63/14H04L 63/18H04W 12/086
69
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Based on context received regarding a computing device and a security policy, a computing device evaluates a request by an application program to determine whether or not to allow the establishment of an application connection.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
storing on a computing device a security policy to manage network connections; on the computing device, intercepting an attempt by the computing device to establish a first network connection between the computing device and a target destination; and applying the security policy on the computing device according to context information associated with the computing device to determine whether or not a second network connection should be established between the computing device and the target destination, wherein a level of security offered by the first network connection is different from a level of security offered by the second network connection.
2 . The method of claim 1 wherein the context information was collected in response to the attempt by the computing device to establish the first network connection.
3 . The method of claim 1 wherein the step of intercepting is an operating system event, a network driver event, a baseband processor event, a security application event, or an Android intent filtering event.
4 . The method of claim 1 further comprising:
in the applying step, determining that the second network connection need not be established, and allowing the first network connection to be established between the computing device and the target destination;
while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the mobile communication device; and
based on the newly collected context information, applying the security policy on the computing device to determine whether or not the second network connection should be established between the computing device and the target destination, wherein the level of security offered by the second network connection is greater than the level of security offered by the first network connection.
5 . The method of claim 1 further comprising:
in the applying step, determining that the second network connection need not be established and allowing the first network connection to be established between the computing device and the target destination;
while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the mobile communication device; and
based on the newly collected context information, applying the security policy on the computing device to determine whether or not the second network connection should be established between the computing device and the target destination, wherein the level of security offered by the second network connection is less than the level of security offered by the first network connection.
6 . The method of claim 1 further comprising:
in the applying step, determining that the second network connection need not be established and allowing the first network connection to be established between the computing device and the target destination;
while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the mobile communication device; and
based on the newly collected context information, applying the security policy on the computing device to determine whether or not the first network connection should remain established between the computing device and the target destination, wherein the level of security offered by the first network connection is greater than the level of security offered by the second network connection.
7 . The method of claim 1 further comprising:
in the applying step, determining that the first network connection should be established between the computing device and the target destination;
while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the computing device; and
based on the newly collected context information, applying the security policy on the mobile device to determine whether or not the first network connection should remain established between the computing device and the target destination, wherein the level of security offered by the first network connection is less than the level of security offered by the second network connection.
8 . A method comprising:
storing on a computing device a security policy; collecting context information at the computing device to evaluate a request by an application program to establish an application connection over an existing physical network connection; applying the security policy using the collected context information at the computing device; and based on the application of the security policy, allowing or not allowing the request.
9 . The method of claim 8 wherein the allowing the request comprises:
establishing an overlay connection over the existing physical network connection for the application program.
10 . The method of claim 8 wherein the allowing the request comprises:
reusing an existing overlay connection over the existing physical network connection for the application program.
11 . The method of claim 8 wherein the not allowing the request comprises:
terminating the existing physical network connection; and
establishing a new physical network connection for the request, wherein the new and existing physical network connections comprise different types of physical network connections.
12 . The method of claim 8 wherein the not allowing the request comprises:
maintaining the existing physical network connection; and
establishing a new physical network connection for the request, wherein the existing physical network connection is maintained for a different application program.
13 . The method of claim 12 comprising:
establishing an overlay connection over the new physical network connection.
14 . The method of claim 8 wherein the allowing the request comprises:
routing the application connection over the existing physical network connection because the existing physical network connection includes an overlay connection.
15 . The method of claim 8 wherein the allowing the request comprises:
routing the application connection over the existing physical network connection because the existing physical network connection does not include an overlay connection.
16 . A system comprising a computing device including at least one processor and memory with instructions that when executed by the at least one processor cause the system to perform actions including:
storing a security policy; collecting context information to evaluate a request by an application program to establish an application connection over an existing physical network connection; applying the security policy using the collected context information; and based on the application of the security policy, allowing or not allowing the request.
17 . The system of claim 16 wherein the allowing the request comprises:
establishing an overlay connection over the existing physical network connection for the application program.
18 . The system of claim 16 wherein the allowing the request comprises:
reusing an existing overlay connection over the existing physical network connection for the application program.
19 . The system of claim 16 wherein the not allowing the request comprises:
terminating the existing physical network connection; and
establishing a new physical network connection for the request, wherein the new and existing physical network connections comprise different types of physical network connections.
20 . The system of claim 16 wherein the not allowing the request comprises:
maintaining the existing physical network connection; and
establishing a new physical network connection for the request, wherein the existing physical network connection is maintained for a different application program.Join the waitlist — get patent alerts
Track US2022263868A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.