Applications of secured memory areas and secure environments in policy-based access control systems for mobile computing devices
US10795985B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 24, 2015 |
| Grant date | Oct 6, 2020 |
| Priority date | — |
| Expiry date | Apr 24, 2035 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04W12/08
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Systems and methods are described for utilizing a secure environment on a mobile computing device for applying policy-based decision management in response to access requests from untrusted areas. A policy decision processor (PDP) within the secure environment provides a policy decision in response to an access query. A decision cache within the secure environment can be used to store policy decisions for faster resolution of access requests. Policy enforcement points (PEPs) are placed between external devices that are trying to access the device and the secured environment, where the PEPs are used to enforce the policy-based decision, and can be located either inside or outside the secure environment. Decision certificates can be formulated using validity information and timestamps, and used for validation policy certificates. Memory in non-secure areas can also be marked (colored) for use in performing trusted operations in order to optimize system resource usage.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.