Smart phone protection system and method using mdm when detecting ransomware
The terminal function restriction system addresses the challenge of automatically restricting wireless communication device functions in public places by using a security agent and terminal function restriction device to limit hardware and application functions when security risks are detected, effectively protecting the device and preventing public disturbances.
Patent Information
- Application Number
- PCT/KR2024/019259
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-27
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-05
AI Technical Summary
Existing wireless communication devices lack effective mechanisms to automatically restrict terminal functions in public places, leading to discomfort and potential safety issues due to ringing and calling sounds, as well as electromagnetic interference with other devices.
A terminal function restriction system that utilizes a security agent in the terminal client to detect security risks, such as ransomware, and transmit notifications to a terminal function restriction device, which then sends authority restriction requests to the terminal client to limit hardware and application functions.
The system effectively restricts terminal functions when a security risk is detected, protecting the terminal storage device and preventing potential threats, while also addressing the issue of public disturbance caused by ringing devices.
Smart Images

Figure KR2024019259_05062025_PF_FP_ABST
Abstract
Description
Terminal protection system and method using MDM when ransomware is detected
[0001] One embodiment of the present invention relates to a system for restricting terminal functions when a security risk is detected.
[0002] The content described below merely provides background information related to the present embodiment and does not constitute prior art.
[0003] Wireless communication devices include mobile telephones, wireless selective calling receivers, and the like. People within different, randomly available areas can communicate with each other using mobile devices. Selective calling receivers, typically pagers, can call users regardless of their location.
[0004] Wireless communication devices have recently become more widely used as their size has decreased and their unit prices have decreased. This widespread use has led to a major social problem: the annoying sounds of incoming calls and calls in public places, such as on trains.
[0005] The potential for traffic accidents caused by using mobile phones while driving has become a significant concern. Furthermore, there is the problem of electromagnetic waves transmitted from mobile phones causing malfunctions in electronic devices installed on aircraft, such as pacemakers, and in electronic medical devices.
[0006] To prevent ringing and calls from wireless communication devices, users must either stop ringing in such places or turn off the power of their mobile phones.
[0007] Therefore, a wireless communication device capable of automatically restricting terminal functions has been proposed to prevent the use of wireless communication devices in public places.
[0008] For example, a prior art technique for restricting the functionality of a wireless communication device involves monitoring a specific channel selected from a communication channel other than the call channel that is always being monitored when a call is received from a base station. When electromagnetic waves are transmitted through a specific channel, the wireless communication device does not generate an incoming call tone and instead displays information on its display indicating that the incoming call tone function is disabled. In other words, when a transmitter transmitting electromagnetic waves through a specific channel is located in a public place, such as a train, where the incoming call tone function should be disabled, the transmitter's functionality is restricted.
[0009] Conventional wireless communication devices monitor specific channels to determine whether certain functions are prohibited, based on the presence or absence of electromagnetic waves on those channels. Therefore, new channels other than those used for communications with base stations need to be provided. In other words, securing new frequency resources is necessary. Frequency is an infinite resource, and even if possible, allocating new frequency bands is extremely difficult. Even if allocating new frequency bands is feasible, if the new frequency bands are substantially separated from the frequency bands used for general wireless communication, additional receivers and antennas suitable for the new frequency band must be installed, hindering the miniaturization of wireless communication devices.
[0010] Meanwhile, it's also possible to set up specific channels and communication channels on the same channel. The transmitter transmits a specific pattern signal through a specific channel, and the wireless communication device must receive and recognize the specific pattern signal to determine the restricted area where use is prohibited. However, because the call signal and the specific pattern signal are received simultaneously from the transmitter through a single channel, the wireless communication device cannot reliably receive the specific pattern signal.
[0011] Another way to restrict the use of a wireless communication device is, for example, when a transmitter transmits electromagnetic waves without modulation over a communication channel, the wireless communication device cannot receive signals on one communication channel due to mutual interference with unmodulated electromagnetic waves. However, the user of the wireless communication device cannot determine whether the inability to use the wireless communication device is caused by the user's location in an area where use of the wireless communication device is prohibited or where reception conditions are poor.
[0012] Conventional mobile radio devices are forced into pager mode when a user carrying a mobile phone passes through a gate by receiving a mode change signal transmitted from a mode change signal transmitter installed at the transit station gate. Therefore, communication is impossible in areas where the use of phones is prohibited.
[0013] However, it's impossible to prevent ringing in pager mode with mobile wireless devices. Therefore, ringing can be annoying to others.
[0014] Even when a user is equipped with another notification method, such as a vibrator, in addition to the ringtone, the user must switch the notification method from the ringtone to the vibrator every time they enter a specific area, which is extremely cumbersome. Furthermore, unless the user knows that their mobile phone is within a specific area before being called, it is impossible to determine whether the notification method needs to be switched.
[0015] The purpose of this embodiment is to provide a terminal function restriction system when a security risk is detected, in which a security agent installed in a terminal client detects a security risk, a notification is sent to a terminal function restriction device, a request for terminal authority restriction is sent from the terminal function restriction device to a terminal function restriction agent installed in the terminal client to restrict process operation of the terminal and protect the terminal storage device, and a result of terminal process operation restriction is sent from the terminal function restriction agent to the terminal function restriction device to deliver a terminal protection result.
[0016] According to one aspect of the present embodiment, a terminal function restriction system is provided when a security risk is detected, comprising: a terminal client that generates and transmits a security risk notification when a security risk is detected, receives a terminal authority restriction request message corresponding to the security risk notification, and restricts the authority of preset hardware or applications according to the terminal authority restriction request message; and a terminal function restriction device that generates and transmits to the terminal client the terminal authority restriction request message corresponding to the security risk notification after receiving the security risk notification, thereby restricting the authority of preset hardware or applications corresponding to the security risk notification.
[0017] As described above, according to this embodiment, when a security agent installed in a terminal client detects a security risk, it transmits a notification to a terminal function restriction device, and transmits a request for terminal authority restriction from the terminal function restriction device to a terminal function restriction agent installed in the terminal client to restrict process operation of the terminal to protect the terminal storage device, and transmits the result of terminal process operation restriction from the terminal function restriction agent to the terminal function restriction device to deliver the result of terminal protection.
[0018] Fig. 1 is a diagram showing a terminal function restriction system when a security risk is detected according to the present embodiment.
[0019] Fig. 2 is a drawing showing a terminal function restriction system according to the present embodiment.
[0020] Figure 3 is a diagram showing terminal process operation restrictions according to the present embodiment.
[0021] Figure 4 is a diagram showing terminal process operation restrictions according to the present embodiment.
[0022] Fig. 5 is a drawing showing the internal block configuration of a terminal function restriction device according to the present embodiment.
[0023] Fig. 6 is a block diagram specifically showing a lost item management unit according to this embodiment.
[0024] Fig. 7 is a block diagram specifically showing a terminal control function unit according to the present embodiment.
[0025] Figure 8 is a block diagram specifically showing an application management unit according to the present embodiment.
[0026] Figure 9 is a block diagram specifically showing the user management unit according to the present embodiment.
[0027] Fig. 10 is a block diagram specifically showing a terminal monitoring unit according to the present embodiment.
[0028] Fig. 11 is a block diagram specifically showing a terminal process management unit according to the present embodiment.
[0029] Fig. 12 is a block diagram specifically showing a user data management unit according to the present embodiment.
[0030] Figure 13 is a diagram showing a profile registration process according to this embodiment.
[0031] Hereinafter, the present embodiment will be described in detail with reference to the attached drawings.
[0032] Fig. 1 is a diagram showing a terminal function restriction system when a security risk is detected according to the present embodiment.
[0033] The terminal function restriction system for detecting a security risk according to the present embodiment includes a terminal client (110), a network (120), and a terminal function restriction device (130). The components included in the terminal function restriction system for detecting a security risk are not necessarily limited thereto.
[0034] A terminal client (110) refers to an electronic device that performs voice or data communication via a network (120) according to a user's key operation.
[0035] The terminal client (110) has a memory for storing a program or protocol for communicating with a terminal function restriction device (130) via a network (120), a microprocessor for executing the program and performing operations and control, etc.
[0036] The terminal client (110) may be an electronic device such as a smart phone, a tablet, a laptop, a personal computer (PC), a personal digital assistant (PDA), a wireless communication terminal, a media player, etc.
[0037] The terminal client (110) is a variety of devices including (i) a communication device such as a communication modem for communicating with various devices or wired / wireless networks, (ii) a memory for storing various programs and data, and (iii) a microprocessor for executing a program to perform calculations and controls. According to at least one embodiment, the memory may be a computer-readable recording / storage medium such as a Random Access Memory (RAM), a Read Only Memory (ROM), a flash memory, an optical disk, a magnetic disk, a solid state disk (SSD), etc. According to at least one embodiment, the microprocessor may be programmed to selectively perform one or more operations and functions described in the specification. According to at least one embodiment, the microprocessor may be implemented in whole or in part as hardware such as an Application Specific Integrated Circuit (ASIC) of a specific configuration.
[0038] A security agent (112) is installed on a terminal client (110) and detects ransomware, malware, hacking tools, and attacks within the terminal client (110). The security agent (112) may include SaaS (Software as a Service).
[0039] The terminal function restriction agent (114) is installed in the terminal client (110) and restricts the hardware and software functions within the terminal client (110). The terminal function restriction agent (114) remotely restricts or releases restrictions on various applications installed within the terminal client (110).
[0040] When a security risk is detected, the terminal client (110) generates a security risk notification and transmits it to the terminal function restriction device (130). The terminal client (110) receives a terminal authority restriction request message corresponding to the security risk notification from the terminal function restriction device (130). The terminal client (110) restricts the authority of preset hardware or applications according to the terminal authority restriction request message.
[0041] The terminal client (110) is equipped with a security agent (112) and a terminal function restriction agent (114). The security agent (112) generates a security risk notification when it detects at least one of ransomware detection, malware detection, hacking tool detection, forgery detection, firewall attack detection, loss detection, and theft detection. The terminal function restriction agent (114) restricts the permissions of preset hardware or applications according to a terminal permission restriction request message.
[0042] The terminal function restriction device (130) includes hardware modules identical to those of a typical web server or network server. The terminal function restriction device (130) typically communicates with an unspecified number of clients or other servers via an open computer network such as the Internet.
[0043] The terminal function restriction device (130) refers to a computer system or computer software (web server program) that derives and provides work results corresponding to a work performance request from a client or another web server.
[0044] The terminal function restriction device (130) manages the terminal client (110) when the terminal client (110) is connected to the network (120) using OTA (Over To Air). The terminal function restriction device (130) remotely performs application distribution, environment setting change, loss management, and device management in an integrated manner to the terminal client (110).
[0045] The terminal function restriction device (130) provides a profile-based service to a terminal using iOS as an OS, an iOS application installed on the terminal, a terminal using Android as an OS, and an Android application installed on the terminal.
[0046] The terminal function restriction device (130) supports mobile management services using a standardized management module. The terminal function restriction device (130) is distributed as a standardized module (in the form of a library) and applies its own communication standards.
[0047] The terminal function restriction device (130) uses the network (120) to provide terminal storage data synchronization, various security intrusions, and terminal management services to protect personal data in the event of loss. The terminal function restriction device (130) is composed of an agent and a platform to perform terminal control.
[0048] After receiving a security risk notification, the terminal function restriction device (130) generates a terminal authority restriction request message to restrict the authority of preset hardware or applications corresponding to the security risk notification and transmits the message to the terminal client (110).
[0049] The terminal function restriction device (130) performs at least one of loss management, terminal control management, application management, user management, terminal monitoring, terminal process management, and user data management.
[0050] The terminal function restriction device (130) performs one of remote initialization, initialization status check, terminal lock, and terminal lock release for the terminal client (110) when loss detection or theft detection is confirmed as a result of checking the security risk notification.
[0051] The terminal function restriction device (130) restricts at least one of the following permissions for the terminal client: camera permission restriction, Bluetooth permission restriction, Wi-Fi permission restriction, external memory permission restriction, GPS permission restriction, USB permission restriction, and tethering permission restriction, if any one of ransomware detection, malware detection, hacking tool detection, forgery detection, and firewall attack detection is detected for the terminal client (110) as a result of checking the security risk notification.
[0052] The terminal function restriction device (130) performs at least one of application monitoring, application distribution permission restriction, application deletion, and application patching for a specific application when any one of ransomware detection, malware detection, hacking tool detection, forgery detection, and firewall attack detection is detected for a specific application of the terminal client as a result of checking a security risk notification.
[0053] The terminal function restriction device (130) groups terminal clients and then performs at least one of group management, user information management, organization chart management, and administrator function management for the grouped users.
[0054] The terminal function restriction device (130) performs at least one of user location inquiry, user search, user application inquiry, user history management, and control monitoring for the terminal client.
[0055] The terminal function restriction device (130) performs at least one of the following: setting a white list for a terminal client, preventing terminal multitasking, setting a special user terminal process, setting terminal process permissions, locking an application buffer, changing a terminal process, setting a process by group, encrypting a file, and changing a white list.
[0056] The terminal function restriction device (130) performs at least one of data backup, data management, data recovery, user data access authority management, and terminal data management for the terminal client.
[0057] The terminal client (110) performs ransomware detection using the security agent (112). The terminal client (110) detects ransomware by performing at least one of behavioral analysis, pattern recognition, header and signature inspection on files within the terminal client (110) using the security agent (112). If ransomware is detected in the terminal client (110) as a result of checking the security risk notification, the terminal function restriction device (130) restricts or blocks file access rights within the terminal client (110).
[0058] The terminal client (110) performs malware detection by performing at least one of anti-virus and malware scanning within the terminal client (110) using a security agent (112). If malware is detected within the terminal client (110) as a result of checking a security risk notification, the terminal function restriction device (130) restricts permissions to stop the process of the terminal client (110) or block file access.
[0059] The terminal client (110) uses a security agent (112) to perform hacking tool detection (Hacking Tool Detection) for hacking tools or port scanning activities used within the system of the terminal client (110). If a hacking tool is detected within the terminal client (110) as a result of confirming a security risk notification, the terminal function restriction device (130) blocks the network access of the terminal client (110) or restricts the authority to terminate a specific process.
[0060] The terminal client (110) detects changes to the file system of the terminal client (110) using a security agent (112) to verify the integrity of the system and performs tampering detection (Integrity Monitoring). If tampering is detected within the terminal client (110) as a result of checking a security risk notification, the terminal function restriction device (130) restricts the authority of the terminal client (110) and allows the altered file to be restored.
[0061] The terminal client (110) analyzes the network attack pattern of the terminal client (110) using the security agent (112) and adjusts the firewall rules in response to the analysis to perform firewall attack detection. If the terminal function restriction device (130) detects a firewall attack within the terminal client (110) as a result of confirming the security risk notification, it temporarily blocks the network access of the terminal client (110) or restricts specific ports.
[0062] The terminal client (110) performs loss and theft detection using at least one of GPS location tracking, remote device locking, and remote data erasure to detect loss or theft of the terminal client (110) using the security agent (112). If the terminal function restriction device (130) detects loss or theft of the device for the terminal client (110) upon confirming a security risk notification, it temporarily restricts the authority of the terminal client (110) or remotely initializes the device.
[0063] The terminal function restriction device (130) performs permission management for the terminal client (110) after confirming a security risk notification. The terminal function restriction device (130) manages access rights to specific functions or resources for the terminal client (110). For example, the terminal function restriction device (130) designates permissions such as file system access, network access, and system setting changes for specific users or terminals.
[0064] The terminal function restriction device (130) manages group policies for the terminal client (110) after confirming a security risk notification. The terminal function restriction device (130) groups users or terminals of the terminal client (110) and applies a specific security policy. The terminal function restriction device (130) applies the group policy to all users or terminal clients (110) belonging to a specific group at once. For example, the terminal function restriction device (130) restricts file access rights for all users in a specific department or requires the installation of specific security software.
[0065] The terminal function restriction device (130) performs remote management and monitoring of the terminal client (110) after confirming a security risk notification. The terminal function restriction device (130) remotely manages and monitors the terminal client (110). The terminal function restriction device (130) monitors the status of the terminal client (110) in real time and controls it as needed. The terminal function restriction device (130) performs remote management to manipulate and manage at least one of the security policy, software update, and event logging of the terminal client (110).
[0066] The terminal function restriction device (130) performs policy-based management on the terminal client (110) after confirming a security risk notification. The terminal function restriction device (130) controls the operation of the terminal client (110) by defining and applying a security policy. The terminal function restriction device (130) can apply different security policies according to specific events, situations, or regular cycles. For example, the terminal function restriction device (130) can apply a firewall policy to the terminal client (110) accessing from a specific network, or set a policy that restricts file access during a specific time period.
[0067] The terminal function restriction device (130) performs security software and agent utilization for the terminal client (110) after confirming a security risk notification. The terminal function restriction device (130) installs a security agent (112) and a terminal function restriction agent (114) in the terminal client (110) to monitor and control the operation of the terminal client (110). The terminal function restriction device (130) can perform various functions such as malicious activity detection, remote management, and policy application using the security agent (112) and the terminal function restriction agent (114). The terminal function restriction device (130) can periodically evaluate the status of the terminal using the security agent (112) and the terminal function restriction agent (114), and take appropriate responses when a security event is detected.
[0068] Fig. 2 is a drawing showing the internal configuration of a terminal function restriction device according to the present embodiment.
[0069] The terminal function restriction device (130) according to the present embodiment includes an MDM (Mobile Device Management) policy server (210), an MDM database (220), an MDM iOS server (230), an MDM CA server (240), an MDM administrator (Admin) server (250), an MDM administrator console (Console) (280), an iOS push server (260), and an Android push server (270). The components included in the terminal function restriction device (130) are not necessarily limited thereto.
[0070] The MDM policy server (210) manages policies that limit the hardware or application permissions of the terminal client (110).
[0071] The MDM policy server (210) restricts the hardware or application permissions of the terminal client (110) based on the principle of least privilege (Principle of Least Privilege - PoLP), role-based permissions (Role-Based Access Control - RBAC), time-based permissions (Time-Based Access Control), and risk-based permissions (Risk-Based Access Management).
[0072] The MDM policy server (210) strengthens security by granting only the minimum necessary rights to the terminal client (110) by applying the principle of least privilege in accordance with security risk notifications, and ensures that the terminal client (110) has only the minimum rights necessary to perform its work, and prevents malicious attacks or misuse by ensuring that general users do not have system administrator rights.
[0073] The MDM policy server (210) is an access control model that grants permissions according to the job or role of a terminal client (110) by applying role-based authorization according to a security risk notification. It allocates and represents a set of specific permissions to each role, and dynamically grants permissions such as file access and network access according to the role or group required for performing a task by allowing each terminal client (110) to be granted permissions according to its role.
[0074] The MDM policy server (210) applies time-based access control based on security risk notifications to define rules that grant specific permissions only during specific time periods, thereby strengthening security by enabling permissions only when work is required and disabling them at other times, and allowing access to specific terminals only while a specific project is in progress.
[0075] The MDM policy server (210) applies risk-based access management according to security risk notifications to dynamically adjust permissions according to security situations, and when the risk increases, it strengthens or restricts permissions for specific users or terminals, and when abnormal behavior is detected, it immediately restricts the permissions of the terminal client (110) to prevent security accidents.
[0076] The MDM database (220) stores device management messages. The MDM database (220) stores terminal authority restriction request messages. The MDM administrator server (250) restricts administrator authority for the terminal client (110). The MDM administrator console (280) inputs a command to restrict administrator authority for the terminal client (110). The MDM iOS server (230) manages iOS terminals among the terminal clients (110). The MDM CA server (240) retrieves push messages from the MDM database (220). The MDM CA server (240) performs certificate management for the terminal client (110) and retrieves terminal authority restriction request messages from the MDM database (220) in a push format. The iOS push server (260) transmits push messages to the iOS application in the terminal client (110). The Android push server (270) transmits push messages to the Android application in the terminal client (110).
[0077] Figure 3 is a diagram illustrating a method for limiting terminal functions when ransomware is detected according to this embodiment.
[0078] The terminal client (110) detects at least one of ransomware detection, malware detection, hacking tool detection, forgery detection, firewall attack detection, loss detection, and theft detection using the installed security agent (112). If at least one of ransomware detection, malware detection, hacking tool detection, forgery detection, firewall attack detection, loss detection, and theft detection is detected using the security agent (112), the terminal client (110) notifies a security risk to the terminal function restriction device (130) (S310).
[0079] The terminal function restriction device (130) receives a security risk notification from the terminal client (110). The terminal function restriction device (130) transmits a terminal authority restriction request message to the terminal client (110) (S320).
[0080] The terminal client (110) receives a terminal authority restriction request message from the terminal function restriction device (130). When the terminal client (110) receives the terminal authority restriction request message, it performs terminal authority restriction using the installed terminal function restriction agent (114) (S330).
[0081] In step S330, the terminal client (110) performs terminal process operation restrictions using the terminal function restriction agent (114) to perform operations corresponding to at least one of ransomware detection, malware detection, hacking tool detection, forgery detection, firewall attack detection, loss detection, and theft detection. The terminal client (110) performs terminal storage device protection using the terminal function restriction agent (114).
[0082] The terminal client (110) transmits terminal status information, which is the result of performing terminal authority restriction using the terminal function restriction agent (114), to the terminal function restriction device (130) (S340).
[0083]
[0084] In step S340, the terminal client (110) transmits terminal status information including at least one of a terminal process operation restriction result, a terminal storage device protection result, and terminal location information to the terminal function restriction device (130) using a terminal function restriction agent (114).
[0085] Although FIG. 3 describes steps S310 to S340 as being executed sequentially, this is not necessarily the case. In other words, it is possible to modify the steps described in FIG. 2 and execute them, or to execute one or more steps in parallel, and thus FIG. 3 is not limited to a chronological order.
[0086] As described above, the method for limiting terminal functions upon ransomware detection according to the present embodiment described in FIG. 3 may be implemented as a program and recorded on a computer-readable recording medium. The computer-readable recording medium on which the program for implementing the method for limiting terminal functions upon ransomware detection according to the present embodiment is recorded includes any type of recording device that stores data that can be read by a computer system.
[0087] Figure 4 is a diagram showing terminal process operation restrictions according to the present embodiment.
[0088] The terminal client (110) receives a terminal authority restriction request message from the terminal function restriction device (130). When the terminal client (110) receives the terminal authority restriction request message, it performs terminal authority restriction using the installed terminal function restriction agent (114).
[0089] The terminal client (110) prevents ransomware operation by restricting terminal process operation using the terminal function restriction agent (114). The terminal client (110) restricts terminal process operation using the terminal function restriction agent (114) and outputs the number of times the restriction is applied (e.g., kill -9 PID).
[0090] The terminal client (110) performs terminal storage device protection using the terminal function restriction agent (114) and performs operations corresponding to ransomware detection, malware detection, hacking tool detection, forgery detection, firewall attack detection, loss detection, and theft detection. The terminal client (110) restricts specific directory permissions using the terminal function restriction agent (114).
[0091] Fig. 5 is a drawing showing the internal block configuration of a terminal function restriction device according to the present embodiment.
[0092] The terminal function restriction device (130) provides a mobile security solution that integrates security and management of the terminal client (110). The terminal function restriction device (130) provides functions such as loss and theft prevention, remote data protection, smart device function control, administrator functions, application management, and security policy establishment for the terminal client (110).
[0093] The terminal function restriction device (130) according to the present embodiment includes a loss management unit (510), a terminal control function unit (520), an application management unit (530), a user management unit (540), a terminal monitoring unit (550), a terminal process management unit (560), and a user data management unit (570). The components included in the terminal function restriction device (130) are not necessarily limited thereto.
[0094] The Lost Management Unit (510) provides a function for controlling a terminal client (110) when the terminal client (110) is lost or important data within the terminal cannot be protected for other reasons. The Lost Management Unit (510) provides a function for suspending and initializing the terminal client (110) when it is lost or stolen.
[0095] The terminal control function unit (520) provides a control function that can selectively restrict or release individual functions of the terminal client (110). The terminal control function unit (520) provides device control, process control, application control, and data control functions for the terminal client (110).
[0096] The application management unit (530) provides a function for managing applications installed on a terminal client (110) in real time.
[0097] The user management unit (540) provides an administrator function that can create, move, and delete users of the terminal client (110) by group. The user management unit (540) provides security management, registration, approval, and retrieval functions for the terminal client (110).
[0098] The terminal monitoring unit (550) provides a web service to enable remote monitoring of terminal status information of terminal client (110) users. The terminal process management unit (560) provides a terminal process management function that manages and controls various detailed functions according to the terminal client (110) management policy. The user data management unit (570) applies a function that can back up and manage the terminal client (110), and configures and provides NAS storage after calculating a separate storage capacity.
[0099] Fig. 6 is a block diagram specifically showing a lost item management unit according to this embodiment.
[0100] The lost management unit (510) according to the present embodiment includes a remote initialization unit (610), an initialization status confirmation unit (620), a terminal lock unit (630), and a terminal lock release unit (640). The components included in the lost management unit (510) are not necessarily limited thereto.
[0101] The remote initialization unit (610) provides a function for setting a remotely designated terminal client (110) to a factory initialization state. The remote initialization unit (610) performs a remote factory reset of the terminal client (110).
[0102] The initialization status verification unit (620) verifies initialization setting confirmation information via the network (120) after an initialization attempt for the terminal client (110). The initialization status verification unit (620) sets specific conditions for the terminal client (110) and resets and installs an application.
[0103] The terminal lock unit (630) remotely designates the terminal client (110) and sets the lock function by an administrator password.
[0104] The terminal lock release unit (640) provides a function to remotely release the lock status of the terminal client (110). The terminal lock release unit (640) supports lock release settings by sharing administrator-specified password information for the terminal client (110).
[0105] Fig. 7 is a block diagram specifically showing a terminal control function unit according to the present embodiment.
[0106] The terminal control function unit (520) according to the present embodiment includes a camera control unit (710), a Bluetooth control unit (720), a Wi-Fi control unit (730), an external memory control unit (740), a GPS control unit (750), a USB control unit (760), and a tethering control unit (770). The components included in the terminal control function unit (520) are not necessarily limited thereto.
[0107] The camera control unit (710) performs at least one of camera control, camera function blocking, and camera function unblocking for the terminal client (110). The Bluetooth control unit (720) provides the Bluetooth function blocking and Bluetooth function unblocking functions for the terminal client (110).
[0108] The Wi-Fi control unit (730) provides functions for blocking and unblocking Wi-Fi modem functions for the terminal client (110). The external memory control unit (740) provides functions for blocking storage media such as Micro SD for the terminal client (110) and unblocking external storage media.
[0109] The GPS control unit (750) provides functions for blocking and unblocking GPS functions for the terminal client (110). The USB control unit (760) provides functions for blocking and unblocking USB functions for the terminal client (110). The tethering control unit (770) provides functions for blocking and unblocking tethering functions for the terminal client (110).
[0110] Figure 8 is a block diagram specifically showing an application management unit according to the present embodiment.
[0111] The application management unit (530) according to the present embodiment includes an application monitoring unit (810), an application distribution unit (820), an application deletion unit (830), and an application patch unit (840). The components included in the application management unit (530) are not necessarily limited thereto.
[0112] The application monitoring unit (810) checks the user-specific application installation list for the terminal client (110). The application distribution unit (820) provides a function that can remotely force or install applications after user consent for the terminal client (110).
[0113] The application deletion unit (830) provides a function to remotely force an application to be installed on a terminal client (110) or after user consent. The application patch unit (840) provides a function to remotely force an application to be patched on a terminal client (110) or after user consent.
[0114] Figure 9 is a block diagram specifically showing the user management unit according to the present embodiment.
[0115] The user management unit (540) according to this embodiment includes a group management unit (910), a user information management unit (920), an organization chart management unit (930), and an administrator function unit (940). The components included in the user management unit (540) are not necessarily limited thereto.
[0116] The group management unit (910) provides a group creation function that can create a user group for a terminal client (110) and a group deletion function that can delete a user group.
[0117] The user information management unit (920) provides a user creation function that allows an administrator to forcibly create a user instead of a normal user registration for user management of the terminal client (110). The user information management unit (920) provides a user deletion function that allows an administrator to forcibly delete a user for user management of the terminal client (110). The user information management unit (920) provides a user movement function that allows a user set in a specific group to be dragged to another group for user management of the terminal client (110).
[0118] The organization chart management unit (930) can force users to upload a CSV (Comma-Separated Values) file for organizational chart management of the terminal client (110). The administrator function unit (940) can create sub-administrators for the terminal client (110) and provides a function for creating administrators by group.
[0119] Fig. 10 is a block diagram specifically showing a terminal monitoring unit according to the present embodiment.
[0120] The terminal monitoring unit (550) according to the present embodiment includes a user location inquiry unit (1010), a user search unit (1020), a user application inquiry unit (1030), a user history management unit (1040), and a control monitoring unit (1050). The components included in the terminal monitoring unit (550) are not necessarily limited thereto.
[0121] The user location query unit (1010) provides a function to confirm the location of a user query for a terminal client (110). The user search unit (1020) provides a function to search for a specific user by searching for a user for a terminal client (110). The user application query unit (1030) provides a function to monitor the user's application installation status for a terminal client (110).
[0122] The user history management unit (1040) provides a function capable of monitoring user-specific control history for terminal clients (110). The control monitoring unit (1050) provides a function capable of monitoring the user's control settings for terminal clients (110).
[0123] Fig. 11 is a block diagram specifically showing a terminal process management unit according to the present embodiment.
[0124] The terminal process management unit (560) according to the present embodiment includes a white list setting unit (1110), a terminal multitasking prevention unit (1120), a special user terminal process setting unit (1130), a terminal process permission setting unit (1140), an application buffer locking unit (1150), a terminal process change unit (1160), a group-specific process setting unit (1170), a file encryption unit (1180), and a white list change unit (1190). The components included in the terminal process management unit (560) are not necessarily limited thereto.
[0125] The white list setting unit (1110) provides a white list setting function that can set terminal processes according to the terminal process permission policy of all users for the terminal client (110).
[0126] The terminal multitasking prevention unit (1120) provides a terminal multitasking prevention function that prevents other processes from running while a business program for the terminal client (110) is running.
[0127] The special user terminal process setting unit (1130) provides a special user terminal process setting function that can monitor the user's application installation status for the terminal client (110).
[0128] The terminal process permission setting unit (1140) provides a terminal process permission setting function that embeds a management module into a business application according to the terminal process management policy for the terminal client (110).
[0129] The application buffer lock unit (1150) provides an application buffer lock that blocks access to temporary memory used during the execution of a terminal process for a terminal client (110). The terminal process change unit (1160) provides a terminal process change function that can change a terminal process for each group / special user for the terminal client (110). The group process setting unit (1170) provides a group process setting function that can set a terminal process for each group according to a group-specific terminal process permission policy for the terminal client (110).
[0130] The file encryption unit (1180) provides a file encryption function that can apply file encryption to prevent business files for the terminal client (110) from being opened even if copied through intentional memory tracing. The white list change unit (1190) provides a white list change function that can change the white list settings for the terminal client (110).
[0131] Fig. 12 is a block diagram specifically showing a user data management unit according to the present embodiment.
[0132] The user data management unit (570) according to the present embodiment includes a data backup unit (1210), a data management unit (1220), a data recovery unit (1230), a user data access authority unit (1240), and a terminal data management unit (1250). The components included in the user data management unit (570) are not necessarily limited thereto.
[0133] The data backup unit (1210) provides a data backup function that can remotely back up user terminal data for the terminal client (110). The data management unit (1220) provides a data management function that can encrypt and store user-specific backup data for the terminal client (110). The data recovery unit (1230) provides a data recovery function that can remotely restore data backed up on the user's smartphone for the terminal client (110).
[0134] The user data access authority (1240) provides a function for creating a functional group that sets the authority to access user data for the terminal client (110). The user data access authority (1240) provides a function for creating a user group for the terminal client (110).
[0135] The terminal data management unit (1250) provides a data management function that remotely manages user statistical information including at least one of voice history, SMS history, call history, roaming information, and data usage for the terminal client (110).
[0136] Figure 13 is a diagram showing a profile registration process according to this embodiment.
[0137] The terminal function restriction device (130) registers user information (S1310). The terminal function restriction device (130) creates a profile for each registered user information (S1320).
[0138] The terminal function restriction device (130) registers the terminal client (110) based on the profile (S1330). In step S1330, the terminal function restriction device (130) performs terminal status registration and user authentication based on user information. The terminal function restriction device (130) checks the terminal automatic installation status. The terminal function restriction device (130) provides terminal status registration and terminal management services. The terminal function restriction device (130) automatically registers USIM changes and device profile changes based on the generated profile. The terminal function restriction device (130) performs phone number and USIM serial authentication based on the user authentication system.
[0139] The terminal function restriction device (130) restricts terminal functions when ransomware is detected by using a security agent (112) and a terminal function restriction agent (114) installed in the terminal client (110) (S1340).
[0140] In step S1340, the terminal function restriction device (130) accesses the user service web interface. The terminal function restriction device (130) selects a service function after user authentication. The terminal function restriction device (130) monitors the terminal status and then performs the selected function. The terminal function restriction device (130) sends a push message to the corresponding terminal client (110). The terminal client (110) receives the terminal message from the terminal function restriction device (130) and then performs the corresponding function to perform initialization, backup, etc.
[0141] The above description is merely an example of the technical idea of the present embodiment, and those skilled in the art will appreciate that various modifications and variations can be made without departing from the essential characteristics of the present embodiment. Therefore, the present embodiments are not intended to limit the technical idea of the present embodiment, but rather to explain it, and the scope of the technical idea of the present embodiment is not limited by these embodiments. The scope of protection of the present embodiment should be interpreted by the claims below, and all technical ideas within a scope equivalent thereto should be interpreted as being included in the scope of rights of the present embodiment.
Claims
1. A terminal client that generates and transmits a security risk notification when a security risk is detected, receives a terminal authority restriction request message corresponding to the security risk notification, and restricts the authority of preset hardware or applications according to the terminal authority restriction request message; A terminal function restriction device that generates a terminal authority restriction request message to restrict the authority of preset hardware or applications corresponding to the security risk notification after receiving the above security risk notification and transmits the message to the terminal client; A system for limiting terminal functions upon detection of a security risk, characterized by including:
2. In paragraph 1, The above terminal client, A security agent that generates the above security risk notification when detecting at least one of ransomware detection, malware detection, hacking tool detection, forgery detection, firewall attack detection, loss detection, and theft detection; A terminal function restriction agent that restricts the authority of a preset hardware or application according to the above terminal authority restriction request message; A system for limiting terminal functions when detecting a security risk, characterized by being equipped with a .
3. In paragraph 1, The above terminal function limiting device is, A terminal function restriction system upon detection of a security risk, characterized in that it performs at least one of loss management, terminal control management, application management, user management, terminal monitoring, terminal process management, and user data management.
4. In paragraph 1, The above terminal function limiting device is, A system for restricting terminal functions upon detection of a security risk, characterized in that when loss detection or theft detection is confirmed for the terminal client as a result of checking the above security risk notification, one of remote initialization, initialization status check, terminal lock, and terminal lock release is performed for the terminal client.
5. In paragraph 1, The above terminal function limiting device is, A terminal function restriction system when detecting a security risk, characterized in that if any one of ransomware detection, malware detection, hacking tool detection, forgery detection, and firewall attack detection is detected for the terminal client as a result of checking the above security risk notification, at least one or more of the following permissions for the terminal client are restricted: camera permission restriction, Bluetooth permission restriction, Wi-Fi permission restriction, external memory permission restriction, GPS permission restriction, USB permission restriction, and tethering permission restriction.
6. In paragraph 1, The above terminal function limiting device is, A system for restricting terminal functions upon detection of a security risk, characterized in that if any one of ransomware detection, malware detection, hacking tool detection, forgery detection, and firewall attack detection for a specific application of the terminal client is detected as a result of checking the above security risk notification, at least one or more of application monitoring, application distribution permission restriction, application deletion, and application patching for the specific application is performed.
Citation Information
Patent Citations
System and method for strengthening security of mobile terminal
KR1020130005950A
A malware detecting system performing monitoring of malware and controlling a device of user
KR102180098B1
System sliding window
KR102307629B1
KR20190044435A
KR20210068388A