Methods and systems for secure network connections

US9973534B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9973534-B2
Application numberUS-201314071366-A
CountryUS
Kind codeB2
Filing dateNov 4, 2013
Priority dateNov 4, 2013
Publication dateMay 15, 2018
Grant dateMay 15, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Context information associated with a mobile communications device and a network connection for the mobile communications device is collected. A security policy is applied to determine whether the security offered by the network connection is appropriate for the context. If the security offered by the network connection is not appropriate for the context, the network connection may be made more secure, less secure, or a different network connection having an appropriate level of security may be used for the data associated with the context.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: storing on a mobile communications device a security policy to manage network connections, the security policy received by the mobile communications device from a network administrator or from a server associated with an ultimate destination, the security policy including a plurality of rules defining events, situations, or conditions that trigger the automatic establishment of a secure network connection by a secure connection manager on the mobile communications device; collecting, at the secure connection manager on the mobile communications device, a first context information associated with the mobile communications device including system state data of the mobile communications device, user activity on the mobile communications device, and information related to authentication of the mobile communications device; collecting, at the secure connection manager on the mobile communications device, a second context information associated with a first network connection including a level of security of the first network connection and a provider of the first network connection; collecting, at the secure connection manager on the mobile communications device, a third context information associated with an ultimate destination with which the mobile communications device is attempting to connect, the ultimate destination consisting of a server or a server system comprising one or more of a website, web server, and an application server; evaluating, by the secure connection manager, the first network connection, the evaluation using the collected first context information, the collected second context information, the collected third context information, and the security policy, the evaluating occurring before the first network connection is established, after the first network connection is established, or while the first network connection is being established; and based on the evaluation by the secure connection manager, determining, by the secure connection manager, that a secure network connection for use in the communication between the mobile communications device and the ultimate destination should be established instead of the first network connection between the mobile communications device and the ultimate destination, the secure network connection providing a level of security different from the level of security provided by the first network connection, the establishment of the secure network connection being automatically triggered by at least one rule in the received security policy. 2. The method of claim 1 , further comprising: upon determining that the secure network connection for use in the communication between the mobile communications device and the ultimate destination should be established instead of the first network connection between the mobile communications device and the ultimate destination, terminating the first network connection; and establishing the secure network connection for use in the communication between the mobile communications device and the ultimate destination, wherein the level of security provided by the secure network connection is greater than the level of security provided by the terminated first network connection. 3. The method of claim 1 , further comprising: upon determining that the secure network connection for use in the communication between the mobile communications device and the ultimate destination should be established instead of the first network connection between the mobile communications device and the ultimate destination, terminating the first network connection; and establishing the secure network connection for use in the communication between the mobile communications device and the ultimate destination, wherein the level of security provided by the secure network connection is less than the level of security provided by the terminated first network connection. 4. The method of claim 1 wherein the first context information further includes a location of the mobile communications device. 5. The method of claim 1 wherein the third context information further includes an identifier of the ultimate destination. 6. The method of claim 1 wherein the user activity includes at least one of: an identification of a specific application program on the mobile communications device, a category of the specific application program, a day of week, and a time of day, and further wherein the category of the specific application program includes a financial services application. 7. The method of claim 1 wherein the security policy stored on the mobile communications device originates from at least one of a user, an administrator for the mobile communications device, an administrator for a physical network to which the first network connection is made, and a network destination. 8. The method of claim 1 wherein one of the first or secure network connection includes encryption of the respective network connection, the one of the first or secure network connection including the encryption providing a greater level of security than another of the first or secure network connection. 9. The method of claim 1 wherein one of the first or secure network connection provides safe browsing by controlling a domain name system (DNS) server for resolving network addresses of all connections via whitelisting or blacklisting by specific domains or TLDs or categories of destinations, the one of the first or secure network connection thereby providing a greater level of security than another of the first or secure network connection. 10. The method of claim 1 wherein the first network connection, secure network connection, or both includes at least one of Wi-Fi, virtual private network (VPN), macro cell network, small cell network, micro cell network, Bluetooth, near field communication (NFC), Zigbee/802.15.x/wireless personal area network (WPAN), mobile ad hoc network (MANET), and mesh network. 11. The method of claim 1 wherein the mobile communications device includes a sessile thing of an Internet of Things (IoT). 12. The method of claim 1 wherein the security policy stored on the mobile communications device is selected as a user preference. 13. The method of claim 1 wherein the collected third context information further includes a category to which the ultimate destination belongs. 14. The method of claim 13 wherein the category includes at least one of a cloud services provider, a financial services website, or a shopping website. 15. The method of claim 1 , the collecting a third context information further comprising: storing, at the mobile communications device, a list including a plurality of ultimate destinations and a plurality of categories, each of the plurality of ultimate destinations being categorized into at least one category of the plurality of categories; and the evaluating the first network connection further comprising: scanning, by the mobile communications device, the list to identify a category of the ultimate destination, wherein the determination that the secure network connection for use in the communication between the mobile communications device and the ultimate destination should be established instead of the first network connection between the mobile communications device and the ultimate destination is made based on an identification of the ultimate destination being in a first category. 16. The method of claim 1 , the collecting a third context information further comprising: transmitting, from the mobile communications device to a server, a request to identify a category

Assignees

Inventors

Classifications

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • for detecting or protecting against malicious traffic · CPC title

  • using different networks or channels, e.g. using out of band channels (cryptographic mechanisms or cryptographic arrangements for key distribution involving distinctive intermediate devices or communication paths H04L9/0827; cryptographic mechanisms or cryptographic arrangements for authentication using a plurality of channels H04L9/3215) · CPC title

  • Multiple levels of security · CPC title

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9973534B2 cover?
Context information associated with a mobile communications device and a network connection for the mobile communications device is collected. A security policy is applied to determine whether the security offered by the network connection is appropriate for the context. If the security offered by the network connection is not appropriate for the context, the network connection may be made more…
Who is the assignee on this patent?
Lookout Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 15 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).