US2022239692A1PendingUtilityA1

Improving Mobile Device Security Using A Secure Execution Context

Assignee: LOOKOUT INCPriority: Jun 7, 2019Filed: Apr 12, 2022Published: Jul 28, 2022
Est. expiryJun 7, 2039(~12.9 yrs left)· nominal 20-yr term from priority
H04L 63/1416H04L 63/1466H04L 9/0897H04L 9/3247H04L 63/1425H04L 63/107H04L 63/0435H04L 63/0428H04L 2209/80G06F 2221/2111G06F 21/88G06F 21/64G06F 21/575
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A device includes a secure execution context that is segregated from an operating system of the device. A security application executing in the operating system interfaces with the secure execution context to obtain verified data. The secure execution context may verify that operating system files are free of malware, obtain sensor readings that may be cryptographically signed, verify functioning of a baseband processor, and verify other aspects of the function and security of the device. The verified data may be used for various purposes such as verifying location of the device, training a machine learning model, and the like.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 providing, via a processor, a secure execution context representing an isolated and secure operating system on a device, the device including one or more sensors;   providing an operating system representing a software supporting device functions and excluding the secure execution context; and   receiving, by the secure execution context, first data representing information about a state of the device, the state of the device including the physical environment of the device, the first data being a first reading from the one or more sensors obtained within the secure execution context.   
     
     
         2 . The method of  claim 1 , further comprising:
 providing a security application executing within the operating system, the security application defining an interface to the secure execution context; and   requesting, by the security application, the first data.   
     
     
         3 . The method of  claim 1 , further comprising cryptographically signing, by the secure execution context, the first reading using a hardware key of the device. 
     
     
         4 . The method of  claim 1 , wherein the one or more sensors include a camera and the first reading is pixel data obtained from the camera. 
     
     
         5 . The method of  claim 1 , wherein the one or more sensors include a global positioning system (GPS) receiver and the first reading is a location obtained from the GPS receiver. 
     
     
         6 . The method of  claim 5 , further comprising:
 receiving, by the processor, a region definition;   evaluating, by the processor, whether the location is within the region definition; and   returning, by the processor, a result of the evaluating.   
     
     
         7 . The method of  claim 1 , wherein the one or more sensors include an accelerometer and the first reading is an accelerometer reading obtained from the accelerometer. 
     
     
         8 . The method of  claim 1 , further comprising:
 performing, by the processor, a biometric assessment of a user of the device using the first reading;   authenticating the user based on the biometric assessment; and   in response to authenticating the user based on the biometric assessment, granting access to the user to an application on the device.   
     
     
         9 . The method of  claim 8 , wherein one or more sensors include an accelerometer and the biometric assessment include assessing one or more of a gait of the user, tremors of the device, and orientation of the device. 
     
     
         10 . The method of  claim 8 , wherein the one or more sensors include a touch screen and the biometric assessment includes assessing touch behavior of the user including one or more of placement, finger size, location, trajectory, and typing behavior. 
     
     
         11 . The method of  claim 8 , wherein the one or more sensors include a radio frequency (RF) sensor and the biometric assessment includes assessing non-touching behaviors around the device. 
     
     
         12 . The method of  claim 11 , wherein the biometric assessment includes assessing signals received from one or more other devices adjacent the device using the RF sensor. 
     
     
         13 . The method of  claim 12 , wherein the signals received from the one or more other devices comprise signals indicating one or more of speech, tapping, and sensor readings detected by the one or more other devices. 
     
     
         14 . The method of  claim 8 , wherein authenticating the user based on the biometric assessment comprises determining that the biometric assessment corresponds to an authenticated behavior model. 
     
     
         15 . A mobile device comprising:
 one or more processing devices defining a secure execution context representing an isolated and secure operating system on a device, the device including one or more sensors; and   one or more memory devices coupled to the one or more processing devices, the one or more memory devices storing executable code that, when executed by the one or more processing devices, causes the one or more processing devices to:   execute an operating system representing a software supporting device functions and excluding the secure execution context;   receive, by the secure execution context, first data representing information about behavior of a user of the device, the first data being a first reading from the one or more sensors obtained within the secure execution context;   obtain biometric data from the first data;   evaluate the biometric data with respect to an authenticated behavior model in the secure execution context; and   if the biometric data corresponds to the authenticated behavior model, grant the user access to a resource on the mobile device.   
     
     
         16 . The mobile device of  claim 15 , wherein the one or more sensors include one or more of an accelerometer, a camera, a microphone, radio frequency (RF) receiver, and a touch screen. 
     
     
         17 . The mobile device of  claim 16 , wherein one or more sensors include the accelerometer and the biometric data includes one or more of a gait of the user, tremors of the device, and orientation of the device. 
     
     
         18 . The mobile device of  claim 16 , wherein one or more sensors include the touch screen and the biometric data includes touch behavior of the user including one or more of placement, finger size, location, trajectory, and typing behavior. 
     
     
         19 . The mobile device of  claim 16 , wherein the one or more sensors include the RF sensor and the biometric data includes one or both of (a) non-touching behaviors around the mobile device and (b) signals received from one or more other devices adjacent the mobile device using the RF sensor. 
     
     
         20 . The mobile device of  claim 19 , wherein the signals received from the one or more other devices comprise signals indicating one or more of speech, tapping, and sensor readings detected by the one or more other devices.

Join the waitlist — get patent alerts

Track US2022239692A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.