US2022263868A1PendingUtilityA1

Methods and systems for providing a secure connection to a mobile communications device with the level of security based on a context of the communication

Assignee: LOOKOUT INCPriority: Nov 4, 2013Filed: May 6, 2022Published: Aug 18, 2022
Est. expiryNov 4, 2033(~7.3 yrs left)· nominal 20-yr term from priority
H04L 63/08H04L 63/105H04L 63/20H04L 63/14H04L 63/18H04W 12/086
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Based on context received regarding a computing device and a security policy, a computing device evaluates a request by an application program to determine whether or not to allow the establishment of an application connection.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 storing on a computing device a security policy to manage network connections;   on the computing device, intercepting an attempt by the computing device to establish a first network connection between the computing device and a target destination; and   applying the security policy on the computing device according to context information associated with the computing device to determine whether or not a second network connection should be established between the computing device and the target destination, wherein a level of security offered by the first network connection is different from a level of security offered by the second network connection.   
     
     
         2 . The method of  claim 1  wherein the context information was collected in response to the attempt by the computing device to establish the first network connection. 
     
     
         3 . The method of  claim 1  wherein the step of intercepting is an operating system event, a network driver event, a baseband processor event, a security application event, or an Android intent filtering event. 
     
     
         4 . The method of  claim 1  further comprising:
 in the applying step, determining that the second network connection need not be established, and allowing the first network connection to be established between the computing device and the target destination; 
 while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the mobile communication device; and 
 based on the newly collected context information, applying the security policy on the computing device to determine whether or not the second network connection should be established between the computing device and the target destination, wherein the level of security offered by the second network connection is greater than the level of security offered by the first network connection. 
 
     
     
         5 . The method of  claim 1  further comprising:
 in the applying step, determining that the second network connection need not be established and allowing the first network connection to be established between the computing device and the target destination; 
 while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the mobile communication device; and 
 based on the newly collected context information, applying the security policy on the computing device to determine whether or not the second network connection should be established between the computing device and the target destination, wherein the level of security offered by the second network connection is less than the level of security offered by the first network connection. 
 
     
     
         6 . The method of  claim 1  further comprising:
 in the applying step, determining that the second network connection need not be established and allowing the first network connection to be established between the computing device and the target destination; 
 while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the mobile communication device; and 
 based on the newly collected context information, applying the security policy on the computing device to determine whether or not the first network connection should remain established between the computing device and the target destination, wherein the level of security offered by the first network connection is greater than the level of security offered by the second network connection. 
 
     
     
         7 . The method of  claim 1  further comprising:
 in the applying step, determining that the first network connection should be established between the computing device and the target destination; 
 while the first network connection is established between the computing device and the target destination, collecting new context information associated with the computing device on the computing device; and 
 based on the newly collected context information, applying the security policy on the mobile device to determine whether or not the first network connection should remain established between the computing device and the target destination, wherein the level of security offered by the first network connection is less than the level of security offered by the second network connection. 
 
     
     
         8 . A method comprising:
 storing on a computing device a security policy;   collecting context information at the computing device to evaluate a request by an application program to establish an application connection over an existing physical network connection;   applying the security policy using the collected context information at the computing device; and   based on the application of the security policy, allowing or not allowing the request.   
     
     
         9 . The method of  claim 8  wherein the allowing the request comprises:
 establishing an overlay connection over the existing physical network connection for the application program. 
 
     
     
         10 . The method of  claim 8  wherein the allowing the request comprises:
 reusing an existing overlay connection over the existing physical network connection for the application program. 
 
     
     
         11 . The method of  claim 8  wherein the not allowing the request comprises:
 terminating the existing physical network connection; and 
 establishing a new physical network connection for the request, wherein the new and existing physical network connections comprise different types of physical network connections. 
 
     
     
         12 . The method of  claim 8  wherein the not allowing the request comprises:
 maintaining the existing physical network connection; and 
 establishing a new physical network connection for the request, wherein the existing physical network connection is maintained for a different application program. 
 
     
     
         13 . The method of  claim 12  comprising:
 establishing an overlay connection over the new physical network connection. 
 
     
     
         14 . The method of  claim 8  wherein the allowing the request comprises:
 routing the application connection over the existing physical network connection because the existing physical network connection includes an overlay connection. 
 
     
     
         15 . The method of  claim 8  wherein the allowing the request comprises:
 routing the application connection over the existing physical network connection because the existing physical network connection does not include an overlay connection. 
 
     
     
         16 . A system comprising a computing device including at least one processor and memory with instructions that when executed by the at least one processor cause the system to perform actions including:
 storing a security policy;   collecting context information to evaluate a request by an application program to establish an application connection over an existing physical network connection;   applying the security policy using the collected context information; and   based on the application of the security policy, allowing or not allowing the request.   
     
     
         17 . The system of  claim 16  wherein the allowing the request comprises:
 establishing an overlay connection over the existing physical network connection for the application program. 
 
     
     
         18 . The system of  claim 16  wherein the allowing the request comprises:
 reusing an existing overlay connection over the existing physical network connection for the application program. 
 
     
     
         19 . The system of  claim 16  wherein the not allowing the request comprises:
 terminating the existing physical network connection; and 
 establishing a new physical network connection for the request, wherein the new and existing physical network connections comprise different types of physical network connections. 
 
     
     
         20 . The system of  claim 16  wherein the not allowing the request comprises:
 maintaining the existing physical network connection; and 
 establishing a new physical network connection for the request, wherein the existing physical network connection is maintained for a different application program.

Join the waitlist — get patent alerts

Track US2022263868A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.