System und Verfahren zur Push-Framework-Sicherheit
Anmelder: Deutsche Telekom AG 🇩🇪
Details
- Veröffentlichungs-Nr.
- EP2892206
- Aktenzeichen
- EP14197956
- Anmeldetag
- 15. Dezember 2014
- Veröffentlichung
- 19. Juli 2017
- Erteilung
- 19. Juli 2017
- Rechtsraum
- EP
- IPC
- H04L29/08H04L29/06H04L9/08H04L9/32H04L9/28H04L9/06
Abstract
The invention relates to a push messaging framework, which offers 2 end-to-end message security models: the "trusted model", which is intended for developers that trust the messaging service (MS) in a sense that they are willing to share the content of push messages with it, and the "untrusted model" for developers that do not trust the MS. There is an essential tradeoff between the two models: a higher level of security in the untrusted model comes at a price of a lower ease-of-use level. The invention offers an easy-to-use implementation of the untrusted model. Furthermore, the invention relates to a method for safekeeping the private key onboard clients for both security models. The method minimizes the duration of private key exposure in memory so that an attacker will have to time an attack to the exact moment that the key is used. This security measure is crucial for Android clients which can easily be compromised. Finally, the invention security model supports application authentication functionality intended to prevent pirating.
Anmelder
- Firma
- Deutsche Telekom AG
- Land
- 🇩🇪 Deutschland
Deutsches Telekommunikationsunternehmen mit Sitz in Bonn. Bietet Festnetz- und Mobilfunkdienste, Internetzugang sowie IT- und Netzwerklösungen für Privat- und Geschäftskunden im In- und Ausland an.
2.494 Patente in unserer Datenbank