Method and apparatus for securing mobile applications
Abstract
A non-transitory processor-readable medium stores code that represents instructions to be executed by a processor. The code includes code to receive an object code of a first application. The first application is defined by an author different from an author of a second application. The code also includes code to dynamically load at least two intercept points into the object code of the first application, using the second application. The code further includes code to, responsive to a read request for data by the first application, intercept the read request by at least one of the two intercept points. The code further includes code to determine, in response to intercepting the read request, whether or not access to read the data is authenticated. The code further includes code to send a signal to provide the data to the first application, based on the determining.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:
receive an object code of a first application, the first application defined by an author different from an author of a second application; dynamically load at least two intercept points into the object code of the first application, using the second application; responsive to a read request for data by the first application, intercept the read request by at least one of the two intercept points; determine, in response to intercepting the read request, whether or not access to read the data is authenticated; and send a signal to provide the data to the first application, based on the determining.
2 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to:
define a password input on a mobile device associated with the first application; receive a password signal associated with the password input, the password signal having authentication information; and analyze the password signal to determine whether or not access to read the data is authenticated.
3 . The non-transitory processor-readable medium of claim 1 , the code further comprising code to cause the processor to:
decrypt the data prior to sending the signal to provide the data to the first application.
4 . The non-transitory processor-readable medium of claim 1 , wherein the read request includes a read request for at least one of access to a file, access to a network source, or access to a clipboard.
5 . The non-transitory processor-readable medium of claim 1 , wherein the read request is at least one of a file open request, a file read request, a file write request, a file create request, a network accept request, a network open request, a network connect request, a network listen request, a network read request, a network write request, a network create request, a clipboard copy request, or a clipboard paste request.
6 . The non-transitory processor-readable medium of claim 1 , wherein the code to cause the processor to determine includes code to cause the processor to erase the data if access is not authenticated.
7 . A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:
receive an object code of a first application provided by a first party; remove a digital signature from the object code of the first application; install at least two intercept points into the object code of the first application; sign the object code of the first application with a digital signature of a second party to produce a modified object code, the second party is different from the first party; execute the modified object code of the first application on a mobile device associated with the first application; responsive to a read request for data by the modified object code of the first application, intercept the read request by at least one of the two intercept points; determine, in response to intercepting the read request, whether or not access to read the data is authenticated; and send a signal to provide the data to the first application, based on the determining.
8 . The non-transitory processor-readable medium of claim 7 , the code further comprising code to cause the processor to:
define a password input on the mobile device associated with the first application; receive a password signal associated with the password input, the password signal having authentication information; analyze the password signal to determine whether or not access to read the data is authenticated.
9 . The non-transitory processor-readable medium of claim 7 , the code further comprising code to cause the processor to:
decrypt the data prior to sending the signal to provide the data to the first application.
10 . The non-transitory processor-readable medium of claim 7 , wherein the read request includes a read request for at least one of access to a file, access to a network source, or access to a clipboard.
11 . The non-transitory processor-readable medium of claim 7 , wherein the read request is at least one of a file open request, a file read request, a file write request, a file create request, a network accept request, a network open request, a network connect request, a network listen request, a network read request, a network write request, a network create request, a clipboard copy request, or a clipboard paste request.
12 . The non-transitory processor-readable medium of claim 7 , wherein the code to cause the processor to determine includes code to cause the processor to erase the data if access is not authenticated.
13 . The non-transitory processor-readable medium of claim 7 , wherein the first application and the data are stored in a container on the mobile device, the code further comprising code to cause the processor to:
receive a delete request signal for remotely wiping the container, the container including a plurality of applications and a plurality of data associated with the plurality of applications; delete the container, in response to the delete request signal, wherein remaining applications and remaining data on the mobile device are unaffected by the remotely wiping of the container; and produce a confirmation signal indicative of the deletion of the container.
14 . A method, comprising:
executing a first application on a mobile device; receiving a request to share, with a second application, data associated with the first application; sending a signal to provide the data to the second application, while executing the first application, in response to the request to share data with the second application; receiving a request to share, with a third application, the third application not from the set of applications on the mobile device, data associated with the first application; and sending a signal to prevent the data from being provided to the third application, while executing the first application, in response to the request to share data with the third application.
15 . The method of claim 14 , wherein the sending the signal to prevent includes at least one of:
sending the signal to provide garbage data to the third application; sending the signal to provide encrypted data to the third application; sending the signal to produce an error code in the first application and stop the data from being provided to the third application; or sending the signal to produce an exception in the first application and stop the data from being provided to the third application.
16 . The method of claim 14 , further comprising:
producing an audit trail message on the mobile device, the audit trail message including a message indicative of preventing the data from being provided to the third application.
17 . An apparatus comprising:
a controller module implemented in at least one of a memory or a processing device, the controller module configured to be communicatively coupled with a network interface and a storage device, the controller module further configured to: receive an object code of a first application, the first application defined by an author different from an author of a second application; dynamically load at least two intercept points into the object code of the first application, using the second application; responsive to a read request for data by the first application, intercept the read request by at least one of the two intercept points; determine, in response to intercepting the read request, whether or not access to read the data is authenticated; and send a signal to provide the data to the first application, based on the determining.
18 . The apparatus of claim 17 , wherein the controller module is configured to:
define a password input on a mobile device associated with the first application; receive a password signal associated with the password input, the password signal having authentication information; and analyze the password signal to determine whether or not access to read the data is authenticated.
19 . The apparatus of claim 17 , wherein the first application and the data are stored in a container on a mobile device, the controller module configured to:
receive a delete request signal for remotely deleting the container, the container including a plurality of applications and a plurality of data associated with the plurality of applications; delete the container, in response to the delete request signal, applications and data on the mobile device and not within the container being unaffected by deleting the container; and produce a confirmation signal indicative of the deletion of the container.
20 . The apparatus of claim 17 , wherein the read request is at least one of a file open request, a file read request, a file write request, a file create request, a network accept request, a network open request, a network connect request, a network listen request, a network read request, a network write request, a network create request, a clipboard copy request, or a clipboard paste request.Join the waitlist — get patent alerts
Track US2013239192A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.