Policy-Based Application Management
Abstract
Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of managing an application based on authentication credentials, comprising:
receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files; receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; selecting the set of one or more policy files based on user credentials authenticated during a single sign-on process, such that a first set of authenticated user credentials result in a first set of one or more policy files, and a second set of authenticated user credentials result in a second set of one or more policy files; and running, by a processor of the device, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files.
2 . The method of claim 1 , wherein the single sign-on process comprises:
receiving a single set of authentication credentials; sending the single set of authentication credentials to an authentication service; receiving confirmation from the authentication service that the authentication credentials are valid; and automatically providing access to one or more resources identified in the one or more policy files responsive to the validity of the authentication credentials.
3 . The method of claim 2 , further comprising restricting access to the one or more resources identified in the one or more policy files responsive to a determination of invalidity of the authentication credentials.
4 . The method of claim 2 , wherein the determination of validity of the authentication credentials is performed responsive to a request originating at the device for access to one of the one or more resources.
5 . The method of claim 1 , further comprising, upon determining that a set of user credentials has expired, revoking the set of one or more policy files.
6 . The method of claim 5 , wherein the client certificate is retrieved from a remote keystore accessible by the electronic mobile device.
7 . The method of claim 6 , wherein the keystore comprises a smart card.
8 . One or more non-transitory computer readable media storing computer instructions that, when executed, manage an application based on authentication credentials by:
receiving, of an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files; receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and running, by a processor of the device, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files, wherein said one or more policy files define a policy based on user credentials authenticated during a single sign-on process.
9 . The computer readable media of claim 8 , wherein the single sign-on process comprises:
receiving a single set of authentication credentials; sending the single set of authentication credentials to an authentication service; receiving confirmation from the authentication service that the authentication credentials are valid; and automatically providing access to one or more resources identified in the one or more policy files responsive to the validity of the authentication credentials.
10 . The computer readable media of claim 9 , further comprising restriction access to the one or more resources identified in the one or more policy files responsive to a determination of invalidity of the authentication credentials.
11 . The computer readable media of claim 9 , wherein the determination of validity of the authentication credentials is performed responsive to a request originating at the device for access to one of the one or more resources.
12 . The computer readable media of claim 8 , wherein the single sign-on process comprises requiring the electronic mobile device to properly sign an authentication message using a client certificate.
13 . The computer readable media of claim 12 , wherein the client certificate is retrieved from a remote keystore accessible by the electronic mobile device.
14 . The computer readable media of claim 13 , wherein the keystore comprises a smart card.
15 . An electronic mobile device, comprising:
a processor; and memory storing computer readable instructions that, when executed, manage an application based on authentication credentials by:
receiving, of an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files;
receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and
running, by a processor of the device, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files,
wherein said one or more policy files define a policy based on user credentials authenticated during a single sign-on process.
16 . The device of claim 15 , wherein the single sign-on process comprises:
receiving a single set of authentication credentials; sending the single set of authentication credentials to an authentication service; receiving confirmation from the authentication service that the authentication credentials are valid; and automatically providing access to one or more resources identified in the one or more policy files responsive to the validity of the authentication credentials.
17 . The device of claim 16 , further comprising restriction access to the one or more resources identified in the one or more policy files responsive to a determination of invalidity of the authentication credentials.
18 . The device of claim 16 , wherein the determination of validity of the authentication credentials is performed responsive to a request originating at the device for access to one of the one or more resources.
19 . The device of claim 15 , wherein the single sign-on process comprises requiring the electronic mobile device to properly sign an authentication message using a client certificate.
20 . The device of claim 19 , wherein the client certificate is retrieved from a remote keystore accessible by the electronic mobile device.Join the waitlist — get patent alerts
Track US2014096186A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.