System and method for generating a secure state indicator on a display
Abstract
A system and method for generating a security indicator on a display of a computing device (e.g. a mobile device), to indicate when the computing device is in a secure state while locked. A determination is made (e.g. by a data protection system) as to whether at least some of the secure data stored on the computing device can be decrypted by any applications on the computing device, while the computing device is in the locked state. An icon or other identifier can be displayed to indicate that the secure state has been attained. In one embodiment, the secure state is considered to have been attained, if it is determined that all tickets that have been issued to applications on the computing device while the computing device was unlocked have been released, and any decrypted encryption keys that may be used to decrypt the secure data have been deleted.
Claims
exact text as granted — not AI-modified1 . A method of generating a security indicator on a display of a computing device, wherein secure data is stored on the computing device, wherein the secure data, when encrypted, can be decrypted using at least one encryption key in decrypted form, and wherein the method comprises:
detecting when the computing device attains a locked state in which access to the computing device is prevented until user authentication at the computing device is successful; determining if any of the secure data can be decrypted by any of one or more applications residing on the computing device while the computing device is in the locked state; displaying a first indicator if it is determined that at least some of the secure data can be decrypted by at least one of the one or more applications while the computing device is in the locked state; and displaying a second indicator if it is determined that none of the secure data can be decrypted by any of the one or more applications on the computing device while the computing device is in the locked state.
2 . The method of claim 1 , wherein the computing device comprises a mobile device.
3 . The method of claim 1 , wherein the first indicator comprises an icon representing an insecure locked state, and wherein the second indicator comprises an icon representing a securely locked state.
4 . The method of claim 1 , further comprising:
while the computing device is not in the locked state, issuing a ticket to each application requesting access to the secure data in order to perform an action, wherein each application is adapted to release the ticket issued thereto when the action is completed; and deleting the at least one encryption key upon determining that all issued tickets have been released, such that none of the secure data can be decrypted by any of the one or more applications residing on the computing device; and wherein said determining if any of the secure data can be decrypted by any of one or more applications residing on the computing device comprises determining whether all issued tickets have been released.
5 . The method of claim 1 , wherein acts of the method are performed when permitted by an IT policy.
6 . The method of claim 1 , wherein the first or second indicator is displayed on a ribbon banner in the display of the computing device.
7 . A physical computer-readable medium comprising a plurality of instructions for execution on a computing device, wherein the instructions, when executed, cause a method of generating a security indicator on a display of the computing device to be performed comprising:
detecting when the computing device attains a locked state in which access to the computing device is prevented until user authentication at the computing device is successful; determining if any of the secure data can be decrypted by any of one or more applications residing on the computing device, while the computing device is in the locked state; displaying a first indicator if it is determined that at least some of the secure data can be decrypted by at least one of the one or more applications while the computing device is in the locked state; and displaying a second indicator if it is determined that none of the secure data can be decrypted by any of the one or more applications on the computing device while the computing device is in the locked state.
8 . The medium of claim 7 , wherein the computing device comprises a mobile device.
9 . The medium of claim 7 , wherein the first indicator comprises an icon representing an insecure locked state, and wherein the second indicator comprises an icon representing a securely locked state.
10 . The medium of claim 7 , wherein the method further comprises:
while the computing device is not in the locked state, issuing a ticket to each application requesting access to the secure data in order to perform an action, wherein each application is adapted to release the ticket issued thereto when the action is completed; and deleting the at least one encryption key upon determining that all issued tickets have been released, such that none of the secure data can be decrypted by any of the one or more applications residing on the computing device; and wherein said determining if any of the secure data can be decrypted by any of one or more applications residing on the computing device comprises determining whether all issued tickets have been released.
11 . The medium of claim 7 , wherein acts of the method are performed when permitted by an IT policy.
12 . The medium of claim 7 , wherein the first or second indicator is displayed on a ribbon banner in the display of the computing device.
13 . A data protection system for generating a security indicator on a display of a computing device, wherein secure data is stored on the computing device, the data protection system comprising a processor, wherein the processor is configured to decrypt secure data, when encrypted, using at least one encryption key in decrypted form, and wherein the processor is further configured to:
detect when the computing device attains a locked state in which access to the computing device is prevented until user authentication at the computing device is successful; determine if any of the secure data can be decrypted by any of one or more applications residing on the computing device while the computing device is in the locked state; display a first indicator if it is determined that at least some of the secure data can be decrypted by at least one of the one or more applications while the computing device is in the locked state; and display a second indicator if it is determined that none of the secure data can be decrypted by any of the one or more applications on the computing device while the computing device is in the locked state.
14 . The data protection system of claim 13 , wherein the computing device comprises a mobile device.
15 . The data protection system of claim 13 , wherein the first indicator comprises an icon representing an insecure locked state, and wherein the second indicator comprises an icon representing a securely locked state.
16 . The data protection system of claim 13 , wherein the processor is further configured to:
while the computing device is not in a locked state, issue a ticket to each application requesting access to the secure data in order to perform an action, wherein each application is adapted to release the ticket issued thereto when the action is completed; and delete the at least one encryption key upon determining that all issued tickets have been released, such that none of the secure data can be decrypted by any of the one or more applications residing on the computing device.
17 . The data protection system of claim 13 , wherein acts of the method are performed when permitted by an IT policy.
18 . The data protection system of claim 13 , wherein the first or second indicator is displayed on a ribbon banner in the display of the computing device.Join the waitlist — get patent alerts
Track US2009240958A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.