Smart card with domain-trust evaluation and domain policy management functions

US9363676B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9363676-B2
Application numberUS-201113991530-A
CountryUS
Kind codeB2
Filing dateDec 6, 2011
Priority dateDec 6, 2010
Publication dateJun 7, 2016
Grant dateJun 7, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One or more wireless communications device may include one or more domains that may be owned or controlled by one or more different owners. One of the domains may include a security domain having ultimate control over the enforcement of security policies on the one or more wireless communications devices. Another one of the domains may include a system-wide domain manager that is subsidiary to the security domain and may enforce the policies of one or more subsidiary domains. The system-wide domain manager may enforce its policies based on a privilege level received from the security domain. The privilege level may be based on the level of trust between an external stakeholder, such as an owner of a domain that is subsidiary to the system-wide domain manager, and the security domain.

First claim

Opening claim text (preview).

What is claimed: 1. A mobile wireless communications device having a processor and a memory, the mobile wireless communications device comprising: a plurality of domains residing on the mobile wireless communications device, wherein the plurality of domains are supported by at least one platform, each domain of the plurality of domains comprising a configuration of computing resources executing on the at least one platform and each domain of the plurality of domains having a domain owner, wherein each domain of the plurality of domains is configured to perform functions for its domain owner and wherein each domain owner may specify policies for operation of its domain; a security domain being one of the plurality of domains, wherein the security domain is configured to determine a level of trust between an external stakeholder and the security domain; and a system-wide domain manager being resident on another one of the plurality of domains, wherein the domain on which the system-wide domain manager resides is subsidiary to the security domain, the system-wide domain manager being configured to enforce the policies on one or more subsidiary domains of the plurality of domains based on a privilege level received from the security domain, the privilege level based on the level of trust between the external stakeholder and the security domain, wherein, when a policy of the security domain conflicts with a policy of the domain on which the system-wide domain manager resides, the system-wide domain manager is further configured to enforce the policy of the security domain. 2. The device of claim 1 , wherein the external stakeholder is an application provider of an application on the device. 3. The device of claim 2 , wherein the security domain is a card issuer security domain that is owned by a card issuer. 4. The device of claim 1 , wherein the external stakeholder comprises an owner of at least one of the one or more subsidiary domains. 5. The device of claim 1 , wherein the security domain and the system-wide domain manager reside on a global platform (GP) compliant card. 6. The device of claim 1 , wherein the plurality of domains reside on a global platform (GP) compliant card, each domain being configured to communicate with one or more off-card entities. 7. The device of claim 1 , wherein the privilege level comprises at least one of a delegated management privilege or an authorized management privilege. 8. The device of claim 7 , wherein the delegated management privilege and the authorized management privilege are each configured to enable the system-wide domain manager to enforce the policies with a corresponding level of autonomy. 9. The device of claim 8 , wherein the level of autonomy corresponding to the authorized management privilege is greater than the level of autonomy corresponding to the delegated management privilege. 10. The device of claim 1 , wherein each domain is associated with a state, and wherein each associated state is one of an installed state, a selectable state, a personalized state, or a locked state. 11. The device of claim 1 , the device further comprising: one or more applications loaded onto at least one of the one or more subsidiary domains of the system-wide domain manager, the one or more applications each associated with a state, wherein each associated state is one of an installed state, a selectable state, a personalized state, or a locked state. 12. The device of claim 11 , wherein one of the one or more applications is configured to change the associated state to another state according to an indication from a controlling authority, wherein the other state and the indication from the controlling authority are based on the privilege level, and wherein the controlling authority is one of the security domain or the system-wide domain manager. 13. The device of claim 1 , wherein the system-wide domain manager is further configured to: enforce the policies for operation of the domain on which it is resident; coordinate the enforcement of respective policies of the subsidiary domains in relation to the domain in which the system-wide domain manager resides; or coordinate interaction among the subsidiary domains in accordance with their respective policies and the policies of the domain on which the system-wide domain manager resides. 14. In a mobile wireless communications device comprising a processor, a memory, and a plurality of domains residing on the mobile wireless communications device, wherein the plurality of the domains are supported by at least one platform, each domain of the plurality of domains comprising a configuration of computing resources executing on the at least one platform and each domain of the plurality of domains having a domain owner, and wherein each domain owner may specify policies for operation of its domain, a method comprising: determining, by a security domain, a level of trust between an external stakeholder and the security domain, wherein the security domain is one of the plurality of domains; enforcing, by a system-wide domain manager residing on another one of the plurality of domains that is subsidiary to the security domain, the policies on one or more subsidiary domains of the plurality of the domains based on a privilege level received from the security domain, wherein the privilege level is based on the level of trust between the external stakeholder and the security domain; and when a policy of the security domain conflicts with a policy of the domain on which the system-wide domain manager resides, enforcing, by the system-wide domain, the policy of the security domain. 15. The method of claim 14 , further comprising: enforcing, by the system-wide domain manager, the policies of the domain on which the system-wide domain manager is resident; coordinating, by the system-wide domain manager, the enforcement of respective policies of the subsidiary domains in relation to the domain in which the system-wide domain manager resides; or coordinating, by the system-wide domain manager, the interaction among the subsidiary domains in accordance with their respective policies and the policies of the domain in which the system-wide domain manager resides. 16. The method of claim 13 , wherein the external stakeholder is an application provider of an application on the one or more devices. 17. The method of 13 , wherein the security domain is a card issuer security domain that is owned by a card issuer. 18. A mobile wireless communications device having a processor and a memory, the mobile wireless communications device comprising: a plurality of domains residing on the mobile wireless communications device, wherein the plurality of domains are supported by at least one platform, each domain of the plurality of domains comprising a configuration of computing resources executing on the at least one platform and each domain of the plurality of domains having a domain owner, wherein each domain of the plurality of domains is configured to perform functions for its domain owner, and wherein each domain owner may specify policies for operation of its the domain; a card issuer security domain of a global platform (GP) compliant card being one of the plurality of domains, wherein the card issuer security domain is configured to determine a level of trust between an external stakeholder and the card issuer security domain; and a system-wide domain manager being resident on another one of the plurality of domains, wherein the domain on which the system-wide domain manager resides is subsidiary

Assignees

Inventors

Classifications

  • Network architectures or network communication protocols for network security (cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00; network architectures or network communication protocols for wireless network security H04W12/00; security arrangements for protecting computers or computer systems against unauthorised activity G06F21/00) · CPC title

  • H04W12/12Primary

    Detection or prevention of fraud · CPC title

  • Access security · CPC title

  • G06F21/10Primary

    Protecting distributed programs or content, e.g. vending or licensing of copyrighted material (protection in video systems or pay television H04N7/16) {; Digital rights management [DRM]} · CPC title

  • Integrity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9363676B2 cover?
One or more wireless communications device may include one or more domains that may be owned or controlled by one or more different owners. One of the domains may include a security domain having ultimate control over the enforcement of security policies on the one or more wireless communications devices. Another one of the domains may include a system-wide domain manager that is subsidiary to …
Who is the assignee on this patent?
Guccione Louis J, Meyerstein Michael V, Cha Inhyok, and 4 more
What technology area does this patent fall under?
Primary CPC classification H04W12/12. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 07 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).