Securing data gathering devices of a personal computing device while performing sensitive data gathering activities to prevent the misappropriation of personal user data gathered therewith
Abstract
A functional library can secure data gathering devices of a personal computing device on behalf of a secure application program to provide a more secure computing session during which sensitive data gathering activities are performed using any of those data gathering devices. The functional library, when incorporated within a personal computing device, creates a secure personal computing device on which to execute application programs such as mobile banking applications. The secure functional library acquires exclusive access to one or more of a predetermined plurality of the data gathering devices on behalf of a calling secure software application. Exclusive access is achieved by gaining access to each of the predetermined set and then locking that access throughout either the entire computing session, or at least until the execution of sensitive data gathering activities being performed during that computing session have been completed. The data gathering devices to be included in the predetermined set can be those that are deemed particularly vulnerable to exploitation in view of the types of sensitive data gathering activities to be conducted, or simply all of them for maximum security. The predetermined set can be defined and set for a particular application, or they can be defined more generally within the context of specific sensitive tasks or activities to be conducted.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer program product for securing data gathering devices of a personal computing device while performing sensitive data gathering activities to prevent the misappropriation of personal user data gathered therewith, the personal computing device configured to perform the data gathering activities using one or more of the data gathering devices during a secure computing session associated with execution of one or more secure application programs running thereon, wherein said computer program product includes computer code that is stored on a non-transitory computer readable medium in the form of a functional library, the computer code capable of being accessed and executed by the personal computing device to perform a method comprising:
acquiring exclusive access on behalf one of the one or more secure application programs to each of a predetermined set of the data gathering devices in response to a call from one of the secure application programs when executed by the personal computing device, said acquiring exclusive access further comprising:
requesting access to each of the devices of the predetermined set;
whenever access to the predetermined set is not granted after a first request for access:
issuing a first request to terminate all other non-secure software applications and services running in the background on the personal computing device;
repeating said request for access;
whenever access to the predetermined set is not granted after at least a second request for access, notifying the calling secure application program that exclusive access to the predetermined set has not been acquired; and
whenever access is granted to each of the predetermined set, locking the acquired access on behalf of the calling application to the exclusion of all other non-secure applications running on the personal computing device; and
notifying the calling secure application program that the exclusive access is acquired; and
relinquishing the acquired exclusive access to each of the predetermined set upon notification from the calling secure application program to do so.
2 . The computer program product of claim 1 , wherein said acquiring exclusive access cannot be performed with system level permission, and whenever exclusive access to the predetermined set is not successfully acquired after at least a second request for exclusive access, said acquiring exclusive access further comprising:
issuing a second request to terminate any non-secure applications not terminated in response to the first issued request to terminate; repeating the request for access to each of the predetermined set; and whenever exclusive access to the predetermined set is not successfully acquired after at least a third request for access, notifying the calling software application program that the computing session is not sufficiently secure to perform the sensitive data gathering activities.
3 . The computer program product of claim 3 , wherein the second issued request to terminate is made to the user through a user interface presented to the user on a display of the personal computing device.
4 . The computer program product of claim 1 , wherein the predetermined set is defined by the calling secure application program.
5 . The computer program product of claim 1 , wherein the predetermined set includes at least one camera.
6 . The computer program product of claim 1 wherein each of the predetermined set is provided with a kernel driver for providing access thereto, each kernel driver further including a locking mechanism for locking the access thereto.
7 . The computer program product of claim 2 , further comprising requesting termination of any non-secure applications previously terminated that attempt to re-launch themselves during the secure session.
8 . The computer program product of claim 1 wherein the personal computing device is a mobile smartphone.
9 . The computer program product of claim 1 , wherein the predetermined set includes a scanner device driver.
10 . The computer program product of claim 1 , wherein the functional library is shared by the one or more secure application programs stored on the personal computing device.
11 . The computer program product of claim 10 , wherein the data gathering devices to be included in the predetermined set are chosen by the functional library in view of the calling secure application program.
12 . The computer program product of the application, wherein the data gathering devices to be included in the predetermined set can be at least partially chosen by the user through a user interface.
13 . The computer program product of claim 1 , wherein:
the calling secure software application calls said functional library at the outset of the secure computing session, and the acquired exclusive access is relinquished in response to notification by the calling secure application program that the secure computing session is being terminated.
14 . The computer program product of claim 1 , wherein:
the secure software application issues the call to the secure functional library just prior to engaging in data gathering activities, and the acquired exclusive access is relinquished in response to notification from the calling secure application that the data gathering activities are completed.
15 . The computer program product of claim 13 , wherein the predetermined set includes all vulnerable data gathering devices installed on the personal computing device.
16 . A secure personal computing device capable of securing one or more vulnerable data gathering devices installed thereon while performing sensitive data gathering activities to prevent the misappropriation of personal user data gathered therewith, the personal computing device including non-transitory memory media for storing software instructions including those of a plurality of non-secure application programs and one or more secure application programs, the personal computing device further including one or more processing devices for retrieving the software instructions from the memory media and executing them, the data gathering devices being accessible by the plurality of non-secure applications programs and the one or more secure application programs, the personal computing device configured to perform the sensitive data gathering actions during a secure computing session under control of one of the one or more secure application programs, said secure personal computing device further comprising:
an operating system for controlling the retrieval and execution of software instructions of the non-secure application programs and the at least one secure application program, the operating system including drivers that control access to the one or more data gathering devices by the non-secure application programs and the one or more secure application programs, the device drivers configured to permit acquired access to the one or more data gathering devices to be locked to render the acquired access exclusive; and a secure functional library, stored on the memory media, the secure functional library capable of obtaining exclusive access to a predetermined set of the one or more data gathering devices on behalf of an executing one of the one or more secure application programs when called by the executing one of the secure application programs to do so, the exclusive access being maintained at least concurrently with the performance of any sensitive data gathering activities during the secure computing session associated with execution of the calling secure application, the exclusive access being maintained through the drivers for each of the predetermined set to the exclusion of any non-secure program applications and services running concurrently with the executing secure program application.
17 . The secure personal computing device of claim 16 , wherein the predetermined set is defined by the executing secure application program.
18 . The secure personal computing device of claim 16 , wherein the predetermined set is defined by the secure functional library.
19 . The secure personal computing device of claim 16 , wherein the predetermined set is at least partially defined by the user through a user interface.
20 . The secure personal computing device of claim 16 , wherein the secure functional library is shared by the two or more secure application programs.
21 . The secure personal computing device of claim 16 , wherein the secure functional library has sufficient system level privilege to terminate all non-secure application programs currently having access to any of the predetermined set for gaining exclusive access on behalf of a calling secure application program.
22 . The secure personal computing device of claim 16 , wherein:
the secure functional library has application level privilege to terminate all non-secure application programs and services currently running in the background to acquire exclusive access to the predetermined set on behalf of a calling one of the secure application programs; and if unable to acquire exclusive access to one or more of the predetermined set, the secure functional library can request that the user terminate active non-secure applications running in the background at the system level, through a user interface presented to the user.
23 . The secure personal computing device of claim 22 , wherein if the secure functional library is still unable to acquire exclusive access on behalf of the calling secure application program, the secure functional library notifies the calling secure application program that the secure computing session is not sufficiently secure for the secure application to proceed with performance of the sensitive data gathering activities.Join the waitlist — get patent alerts
Track US2018107831A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.