Policy-Based Application Management
Abstract
Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of providing a secure storage location on an electronic mobile device, comprising:
receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files; receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; running, by the processor, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files; storing and executing multiple managed applications on the device; associating each managed application with an application group; associating each application group with a different secure persistent storage area; and providing access to each secure persistent storage area only to those managed applications in the associated application group.
2 . The method of claim 1 , further comprising:
receiving a set of encryption/decryption keys in one of the policy files; and using the received set of keys to encrypt data written to the secure persistent storage area, and to decrypt data read from the secure persistent storage area.
3 . The method of claim 1 , further comprising:
receiving a request to delete content from the secure persistent storage area; responsive to the request, determining whether an originator of the request is authorized to delete the content; and deleting the content from the secure persistent storage area when the originator is authorized to delete the content.
4 . The method of claim 3 , wherein the originator is other than a user of the electronic mobile device.
5 . The method of claim 3 , wherein the originator is an administrator of an enterprise mobility management (EMM) service.
6 . The method of claim 1 , wherein the set of one or more policy files act to provide access by the managed application to a secure persistent storage area of the electronic mobile device, said secure persistent storage area accessible by an enterprise administrator, and usable to store a plurality of discrete data files.
7 . The method of claim 1 , further comprising:
storing and executing multiple managed applications on the device; and permitting each managed application access to the secure persistent storage area, based on one or more policy files.
8 . One or more non-transitory computer readable media storing computer instructions that, when executed, provide a secure storage location on an electronic mobile device by:
receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files; receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and running, by the processor, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files, wherein the set of one or more policy files act to provide access by the managed application to a secure persistent storage area of the electronic mobile device, said secure persistent storage area accessible by an enterprise administrator, and usable to store a plurality of discrete data files.
9 . The computer readable media of claim 8 , said instructions further comprising:
receiving a set of encryption/decryption keys in one of the policy files; and using the received set of keys to encrypt data written to the secure persistent storage area, and to decrypt data read from the secure persistent storage area.
10 . The computer readable media of claim 9 , said instructions further comprising:
receiving a request to delete content from the secure persistent storage area; responsive to the request, determining whether an originator of the request is authorized to delete the content; and deleting the content from the secure persistent storage area when the originator is authorized to delete the content.
11 . The computer readable media of claim 10 , wherein the originator is other than a user of the electronic mobile device.
12 . The computer readable media of claim 10 , wherein the originator is an administrator of an enterprise mobility management (EMM) service.
13 . The computer readable media of claim 8 , said instructions further comprising:
storing and executing multiple managed applications on the device; associating each managed application with an application group; associating each application group with a different secure persistent storage area; and providing access to each secure persistent storage area only to those managed applications in the associated application group.
14 . The computer readable media of claim 8 , said instructions further comprising:
storing and executing multiple managed applications on the device; and permitting each managed application access to the secure persistent storage area, based on one or more policy files.
15 . An electronic mobile device, comprising:
a processor; and memory storing computer readable instructions that, when executed by the processor, cause the device to provide a secure storage location by: receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being to operate in accordance with a set of one or more policy files; receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; running, by the processor, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files; storing and executing multiple managed applications on the device; associating each managed application with an application group; associating each application group with a different secure persistent storage area; and providing access to each secure persistent storage area only to those managed applications in the associated application group.
16 . The device of claim 15 , said instructions further comprising:
receiving a set of encryption/decryption keys in one of the policy files; and using the received set of keys to encrypt data written to the secure persistent storage area, and to decrypt data read from the secure persistent storage area.
17 . The device of claim 16 , said instructions further comprising:
receiving a request to delete content from the secure persistent storage area; responsive to the request, determining whether an originator of the request is authorized to delete the content; and deleting the content from the secure persistent storage area when the originator is authorized to delete the content.
18 . The device of claim 17 , wherein the originator is other than a user of the electronic mobile device.
19 . The device of claim 17 , wherein the originator is an administrator of an enterprise mobility management (EMM) service.
20 . The device of claim 15 , wherein the set of one or more policy files act to provide access by the managed application to a secure persistent storage area of the electronic mobile device, said secure persistent storage area accessible by an enterprise administrator, and usable to store a plurality of discrete data files.Join the waitlist — get patent alerts
Track US2014032733A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.