Patent · US10305926B2 · B2 · US
Application platform security enforcement in cross device and ownership structures
- (11) Publication number
- US10305926B2
- (21) Application number
- 15/455,638
- (22) Filing date
- 2017-03-10
- (30) Priority date
- 2016-03-11
- (43) Publication date
- 2019-05-28
- (45) Date of grant
- 2019-05-28
- (51) IPC
- H04L 29/06; G06F 21/55; G06F 21/57; H04W 12/08; H04W 4/21; H04W 4/70
- (52) CPC
- (73) Assignee
- Toronto Dominion Bank
- (72) Inventors
- Koko Mihan; Dino D'Agostino; Paul Mon-Wah CHAN; John Jong-Suk Lee; Paul MILKMAN; Steve Brar
- (54) Title
- Application platform security enforcement in cross device and ownership structures
- (57) Abstract
Methods and systems provide application platform security enforcement. A distributed system communicates between a plurality of remote devices and at least one secured server to facility providing a secured service. The distributed system may comprise a remote communication server and a plurality of security layer components where the plurality of remote devices connect through respective ones of the security layer components. Upon detection of a security breach by a first remote device, the distributed system determines potential devices at risk from the plurality of remote devices, analyzing risk factors for commonalities. A lock down of the first remote device and the devices at risk is instructed. Analysis of risk factors examines whether the first remote device and other remote devices communicate via a same security layer component, are geographically proximate; and/or are associated at the user level, for example are proximate users in a social network graph. Reactivation is also provided.
- Full text
- View on Google Patents
Claims (20)
- A communication server, comprising: a storage device; and at least one processor coupled to the storage device, the storage device storing software instructions for controlling the at least one processor when executed, the at least one processor being operative with the software instructions to: communicate, via one or more communication networks, between at least one secured server and a plurality of remote devices including a first remote device to facilitate a secured service to the plurality of remote devices from the at least one secured server, wherein communications between the communication server and the first remote device are communicated through a first security layer component and communications between the communication server and others of the plurality of remote devices are communicated through the first security layer component or at least one other security layer component; receive via the first security layer component a communication of a detection of a security breach in association with the first remote device; determine potential remote devices at risk from the others of the plurality of remote devices by identifying common risk factors between the first remote device and the others of the plurality of remote devices; and instruct initiation of a lock down of the first remote device via the first security layer component and instruct initiation of a lock down of the potential remote devices at risk via the first security layer component or at least one other security layer component; and wherein the communication server is coupled for respective communication with the at least one secured server and the plurality of remote devices.
- The communication server of claim 1, wherein identifying common risk factors examines at least one of the following: whether the first remote device and the others of the plurality of remote devices communicate via a same security layer component; whether the first remote device and the others of the plurality of remote devices are geographically proximate; and whether the first remote device and the others of the plurality of remote devices are operated by users who are associated.
- The communication server of claim 2, wherein the at least one processor is configured to determine whether the first remote device and the others of the plurality of remote devices are operated by users who are associated by examining social network data and performing social network graphical analysis to find proximate users.
- The communication server of claim 2, wherein to examine whether the first remote device and the others of the plurality of remote devices are geographically proximate, the at least one processor is configured to examine at least one of ping latency, network identification, location services data provided by the remote devices and IP address data.
- The communication server of claim 2, wherein the at least one processor is configured to maintain data identifying compliant remote devices permitted to communicate for the secured service; and receive an update to said compliant remote devices from the first security layer component or at least one other security layer component.
- The communication server of claim 5, wherein the at least one processor is configured to initiate a quarantining of the first remote device via the first security layer component.
- The communication server of claim 1, wherein determining potential remote devices at risk comprises evaluating whether the other remote devices and the first remote device have in common software instructions for at least one of: an operating system, an application and/or network protocols to communicate for the secured service; and wherein lock down is responsive to the evaluating.
- The communication server of claim 1 wherein the first security layer component is either provided by the communication server or a separate server of a communication system.
- The communication server of claim 1 wherein the communication of the detection of the security breach is received via the first security layer component from the first remote device.
- The communication server according to claim 1 wherein the secured service is a financial service.
- A computer-implemented method executed by at least one processor of a communication server, the communication server coupled for communication with at least one secured server and a plurality of communication devices, the method comprising: communicate, via one or more communication networks, between the at least one secured server and a plurality of remote devices including a first remote device to facilitate a secured service to the plurality of remote devices from the at least one secured server, wherein communications between the communication server and the first remote device are communicated through a first security layer component and communications between the communication server and others of the plurality of remote devices are communicated through the first security layer component or at least one other security layer component; receiving, via the first security layer component, a communication of a detection of a security breach in association with the first remote device; determining potential remote devices at risk from the others of the plurality of remote devices by identifying common risk factors between the first remote device and the others of the plurality of remote devices; and instructing initiation of a lock down of the first remote device and the potential remote devices at risk wherein the first remote device is instructed via the first security layer component and the potential remote devices at risk are instructed via the first security layer component or at least one other security layer component.
- The method of claim 11, wherein analyzing risk factors for commonalties examines at least one of the following: whether the first remote device and others of the plurality of remote devices communicate via a same security layer component; whether the first remote device and others of the plurality of remote devices are geographically proximate, examining at least one of ping latency, network identification, location services data provided by the remote devices and IP address data; and whether the first remote device and others of the plurality of remote devices are operated by users who are associated, examining social network data and performing social network graphical analysis to find proximate users.
- The method of claim 11, comprising maintaining data identifying compliant remote devices permitted to communicate for the secured service; and receiving, by the at least one processor, an update to said compliant remote devices from the first security layer component or at least one other security layer component.
- The method of claim 13, comprising initiating a quarantining of the first remote device via the first security layer component.
- The method of claim 12 comprising determining whether the first remote device and the others of the plurality of remote devices are operated by users who are associated by examining social network data and performing social network graphical analysis to find proximate users.
- The method of claim 12, wherein to examine whether the first remote device and the others of the plurality of remote devices are geographically proximate comprises examining at least one of ping latency, network identification, location services data provided by the remote devices and IP address data.
- The method of claim 11, wherein determining potential remote devices at risk comprises evaluating whether the other remote devices and the first remote device have in common software instructions for at least one of: an operating system, an application and/or network protocols to communicate for the secured service; and wherein lock down is responsive to the evaluating.
- The method of claim 11, wherein the first security layer component is either provided by the communication server or a separate server of a communication system.
- The method of claim 11, wherein the communication of the detection of the security breach is received via the first security layer component from the first remote device.
- The method of claim 11, wherein the secured service is a financial service.
Description
The disclosed embodiments generally relate to systems, methods, and apparatuses for application security, application platform security and OTA (over the air) security and more particularly to platform security enforcement in cross device and ownership structures.
The use of applications (including financial applications) that require highly sensitive data on mobile devices is becoming more prevalent in the current mobile environment, Several products exist that can manage mobile platforms and applications running on those platforms. OTA application managers can also be used to enforce IT security policies on mobile devices in the field. OTA management of mobile devices can take the form of policy control of existing devices. Typically, the management of mobile devices is at an individual level or at the ownership level where one or all devices under an IT policy are managed through an OTA manager. The control of these devices is also typically conducted by a manual or scheduled update that may create a potential vulnerability point, which hostile elements may exploit. Systems that are designed to control multiple devices typically limit this control to devices that have a common domain, i.e. same corporate server. Though mobile devices, applications and platforms are mentioned above, it will be understood that other environments (e.g. client-server environments) are similar and require similar management. One example is represented by the Internet of Things (IoT). In the IoT environment, client (or client-like) IoT devices may not be mobile devices, per se.
Citations (5)
- US8839431B2
- US8347386B2
- US8800050B2
- US20140237545A1
- US20150229664A1
Record as JSON
{
"publication_number": "US10305926B2",
"country": "US",
"kind": "B2",
"title": "Application platform security enforcement in cross device and ownership structures",
"abstract": "Methods and systems provide application platform security enforcement. A distributed system communicates between a plurality of remote devices and at least one secured server to facility providing a secured service. The distributed system may comprise a remote communication server and a plurality of security layer components where the plurality of remote devices connect through respective ones of the security layer components. Upon detection of a security breach by a first remote device, the distributed system determines potential devices at risk from the plurality of remote devices, analyzing risk factors for commonalities. A lock down of the first remote device and the devices at risk is instructed. Analysis of risk factors examines whether the first remote device and other remote devices communicate via a same security layer component, are geographically proximate; and/or are associated at the user level, for example are proximate users in a social network graph. Reactivation is also provided.",
"claims": [
"1. A communication server, comprising: a storage device; and at least one processor coupled to the storage device, the storage device storing software instructions for controlling the at least one processor when executed, the at least one processor being operative with the software instructions to: communicate, via one or more communication networks, between at least one secured server and a plurality of remote devices including a first remote device to facilitate a secured service to the plurality of remote devices from the at least one secured server, wherein communications between the communication server and the first remote device are communicated through a first security layer component and communications between the communication server and others of the plurality of remote devices are communicated through the first security layer component or at least one other security layer component; receive via the first security layer component a communication of a detection of a security breach in association with the first remote device; determine potential remote devices at risk from the others of the plurality of remote devices by identifying common risk factors between the first remote device and the others of the plurality of remote devices; and instruct initiation of a lock down of the first remote device via the first security layer component and instruct initiation of a lock down of the potential remote devices at risk via the first security layer component or at least one other security layer component; and wherein the communication server is coupled for respective communication with the at least one secured server and the plurality of remote devices.",
"2. The communication server of claim 1, wherein identifying common risk factors examines at least one of the following: whether the first remote device and the others of the plurality of remote devices communicate via a same security layer component; whether the first remote device and the others of the plurality of remote devices are geographically proximate; and whether the first remote device and the others of the plurality of remote devices are operated by users who are associated.",
"3. The communication server of claim 2, wherein the at least one processor is configured to determine whether the first remote device and the others of the plurality of remote devices are operated by users who are associated by examining social network data and performing social network graphical analysis to find proximate users.",
"4. The communication server of claim 2, wherein to examine whether the first remote device and the others of the plurality of remote devices are geographically proximate, the at least one processor is configured to examine at least one of ping latency, network identification, location services data provided by the remote devices and IP address data.",
"5. The communication server of claim 2, wherein the at least one processor is configured to maintain data identifying compliant remote devices permitted to communicate for the secured service; and receive an update to said compliant remote devices from the first security layer component or at least one other security layer component.",
"6. The communication server of claim 5, wherein the at least one processor is configured to initiate a quarantining of the first remote device via the first security layer component.",
"7. The communication server of claim 1, wherein determining potential remote devices at risk comprises evaluating whether the other remote devices and the first remote device have in common software instructions for at least one of: an operating system, an application and/or network protocols to communicate for the secured service; and wherein lock down is responsive to the evaluating.",
"8. The communication server of claim 1 wherein the first security layer component is either provided by the communication server or a separate server of a communication system.",
"9. The communication server of claim 1 wherein the communication of the detection of the security breach is received via the first security layer component from the first remote device.",
"10. The communication server according to claim 1 wherein the secured service is a financial service.",
"11. A computer-implemented method executed by at least one processor of a communication server, the communication server coupled for communication with at least one secured server and a plurality of communication devices, the method comprising: communicate, via one or more communication networks, between the at least one secured server and a plurality of remote devices including a first remote device to facilitate a secured service to the plurality of remote devices from the at least one secured server, wherein communications between the communication server and the first remote device are communicated through a first security layer component and communications between the communication server and others of the plurality of remote devices are communicated through the first security layer component or at least one other security layer component; receiving, via the first security layer component, a communication of a detection of a security breach in association with the first remote device; determining potential remote devices at risk from the others of the plurality of remote devices by identifying common risk factors between the first remote device and the others of the plurality of remote devices; and instructing initiation of a lock down of the first remote device and the potential remote devices at risk wherein the first remote device is instructed via the first security layer component and the potential remote devices at risk are instructed via the first security layer component or at least one other security layer component.",
"12. The method of claim 11, wherein analyzing risk factors for commonalties examines at least one of the following: whether the first remote device and others of the plurality of remote devices communicate via a same security layer component; whether the first remote device and others of the plurality of remote devices are geographically proximate, examining at least one of ping latency, network identification, location services data provided by the remote devices and IP address data; and whether the first remote device and others of the plurality of remote devices are operated by users who are associated, examining social network data and performing social network graphical analysis to find proximate users.",
"13. The method of claim 11, comprising maintaining data identifying compliant remote devices permitted to communicate for the secured service; and receiving, by the at least one processor, an update to said compliant remote devices from the first security layer component or at least one other security layer component.",
"14. The method of claim 13, comprising initiating a quarantining of the first remote device via the first security layer component.",
"15. The method of claim 12 comprising determining whether the first remote device and the others of the plurality of remote devices are operated by users who are associated by examining social network data and performing social network graphical analysis to find proximate users.",
"16. The method of claim 12, wherein to examine whether the first remote device and the others of the plurality of remote devices are geographically proximate comprises examining at least one of ping latency, network identification, location services data provided by the remote devices and IP address data.",
"17. The method of claim 11, wherein determining potential remote devices at risk comprises evaluating whether the other remote devices and the first remote device have in common software instructions for at least one of: an operating system, an application and/or network protocols to communicate for the secured service; and wherein lock down is responsive to the evaluating.",
"18. The method of claim 11, wherein the first security layer component is either provided by the communication server or a separate server of a communication system.",
"19. The method of claim 11, wherein the communication of the detection of the security breach is received via the first security layer component from the first remote device.",
"20. The method of claim 11, wherein the secured service is a financial service."
],
"description_excerpt": "The disclosed embodiments generally relate to systems, methods, and apparatuses for application security, application platform security and OTA (over the air) security and more particularly to platform security enforcement in cross device and ownership structures.\n\nThe use of applications (including financial applications) that require highly sensitive data on mobile devices is becoming more prevalent in the current mobile environment, Several products exist that can manage mobile platforms and applications running on those platforms. OTA application managers can also be used to enforce IT security policies on mobile devices in the field. OTA management of mobile devices can take the form of policy control of existing devices. Typically, the management of mobile devices is at an individual level or at the ownership level where one or all devices under an IT policy are managed through an OTA manager. The control of these devices is also typically conducted by a manual or scheduled update that may create a potential vulnerability point, which hostile elements may exploit. Systems that are designed to control multiple devices typically limit this control to devices that have a common domain, i.e. same corporate server. Though mobile devices, applications and platforms are mentioned above, it will be understood that other environments (e.g. client-server environments) are similar and require similar management. One example is represented by the Internet of Things (IoT). In the IoT environment, client (or client-like) IoT devices may not be mobile devices, per se.",
"cpc": [
"H04L 63/1441",
"G06F 21/554",
"G06F 21/577",
"H04L 63/1408",
"H04L 63/1416",
"H04L 63/1425",
"H04L 63/1433",
"H04L 63/18",
"H04L 63/20",
"H04W 12/08",
"H04W 4/21",
"H04W 4/70"
],
"ipc": [
"H04L 29/06",
"G06F 21/55",
"G06F 21/57",
"H04W 12/08",
"H04W 4/21",
"H04W 4/70"
],
"assignees": [
"Toronto Dominion Bank"
],
"inventors": [
"Koko Mihan",
"Dino D'Agostino",
"Paul Mon-Wah CHAN",
"John Jong-Suk Lee",
"Paul MILKMAN",
"Steve Brar"
],
"filing_date": "2017-03-10",
"publication_date": "2019-05-28",
"grant_date": "2019-05-28",
"priority_date": "2016-03-11",
"application_number": "US-201715455638-A",
"family_id": "59787324",
"cited_by_count": 211,
"citations": [
"US8839431B2",
"US8347386B2",
"US8800050B2",
"US20140237545A1",
"US20150229664A1"
]
}
Record 2,792 of 8,000 in Patents full text (MLC-0201). Request the full dataset.