Configuring and providing profiles that manage execution of mobile applications
Abstract
Various aspects of the disclosure relate to configuring and providing policies that manage execution of mobile applications. In some embodiments, a user interface may be generated that allows an IT administrator or other operator to set, change and/or add to policy settings. The policy settings can be formatted into a policy file and be made available for download to a mobile device, such as via an application store or to be pushed to the mobile device as part of a data push service. The mobile device, based on the various settings included in the policy file, may perform various actions to enforce the security constraints that are represented by the policy. The various settings that can be included in a policy are numerous and some examples and variations thereof are described in connection with the example embodiments discussed herein.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method, comprising:
displaying, by one or more computing devices, a user interface that displays one or more policy settings for a managed application that is to be made available for download to a mobile device, wherein each of the one or more policy settings provides a constraint to be enforced by the mobile device prior to the managed application being provided access to at least one resource that is accessible through an access gateway; receiving input via the user interface that creates or modifies a selective wipe setting of the one or more policy settings, wherein the selective wipe setting specifies one or more conditions that cause the mobile device delete data from the mobile device; producing a policy file for the managed application that includes the selective wipe setting; and providing the policy file such that the policy file is available for download to the mobile device.
2 . The method of claim 1 , wherein the policy file is an Extensible Markup Language (XML) file or a JavaScript Object Notation (JSON) file, and wherein the policy file includes one or more key/value pairs organized as a dictionary, wherein one key/value pair of the one or more key/value pairs corresponds to selective wipe setting.
3 . The method of claim 1 , wherein the selective wipe setting includes a setting group or category identifier; a setting name; a setting type; a range of possible setting values; a default setting value; a setting friendly name string; a setting unit display string; and a help text string.
4 . The method of claim 1 , wherein the selective wipe setting includes data specifying that information stored in a secure data container of the mobile device is to be deleted when the mobile device is outside a specified geographic restriction, when a user attempts to jailbreak the mobile device, install an application on the mobile device that is blacklisted, uninstall the managed application, switch the application from a managed mode to an unmanaged mode, or according to a specified deletion schedule;
wherein the secure data container is a logical interface into which read or write operations from the mobile application are redirected and in which data is in an encrypted form, and includes a file system and an access manager that governs access to the file system.
5 . The method of claim 1 , wherein the user interface is configured to accept input specifying that information stored in a secure data container of the mobile device is to be deleted when the mobile device is outside a specified geographic restriction, when a user attempts to jailbreak the mobile device, install an application on the mobile device that is blacklisted, uninstall the managed application, switch the application from a managed mode to an unmanaged mode, and according to a specified deletion schedule.
6 . The method of claim 1 , wherein the selective wipe setting includes data specifying an identifier or a resource name of a secure data container of the mobile device that is to be deleted when selectively wiping the mobile device.
7 . The method of claim 1 , further comprising:
receiving a message indicating that a selective wipe is to be performed by the mobile device; responsive to receiving the message, determining whether to update policy information stored by the mobile device; and based on said determining whether to update policy information stored by the mobile device, transmitting an acknowledgement that the policy information is up to date or transmitting an update to the policy information.
8 . The method of claim 1 , wherein the providing the policy file includes publishing the policy file to an application store that also publishes the managed application.
9 . The method of claim 1 , wherein providing the policy file includes pushing the policy file to the mobile device based on the mobile device being registered with a push service.
10 . An apparatus, comprising:
at least one processor; and memory storing executable instructions configured to, when executed by the at least one processor, cause the apparatus to:
display a user interface that displays one or more policy settings for a managed application that is to be made available for download to a mobile device, wherein each of the one or more policy settings provides a constraint to be enforced by the mobile device prior to the managed application being provided access to at least one resource that is accessible through an access gateway;
receive input via the user interface that creates or modifies a selective wipe setting of the one or more policy settings, wherein the selective wipe setting specifies one or more conditions that cause the mobile device delete data from the mobile device;
produce a policy file for the managed application that includes the selective wipe setting; and
provide the policy file such that the policy file is available for download to the mobile device.
11 . The apparatus of claim 10 , wherein the policy file is an Extensible Markup Language (XML) file or a JavaScript Object Notation (JSON) file, and wherein the policy file includes one or more key/value pairs organized as a dictionary, wherein one key/value pair of the one or more key/value pairs corresponds to selective wipe setting.
12 . The apparatus of claim 10 , wherein the selective wipe setting includes a setting group or category identifier; a setting name; a setting type; a range of possible setting values; a default setting value; a setting friendly name string; a setting unit display string; and a help text string.
13 . The apparatus of claim 10 , wherein the user interface is configured to accept input specifying that information stored in a secure data container of the mobile device is to be deleted when the mobile device is outside a specified geographic restriction, when a user attempts to jailbreak the mobile device, install an application on the mobile device that is blacklisted, uninstall the managed application, switch the application from a managed mode to an unmanaged mode, and according to a specified deletion schedule.
14 . The apparatus of claim 10 , wherein the selective wipe setting includes data specifying an identifier or a resource name of a secure data container of the mobile device that is to be deleted when selectively wiping the mobile device.
15 . The apparatus of claim 10 , wherein the executable instructions are configured to, when executed by the at least one processor, further cause the apparatus to:
receive a message indicating that a selective wipe is to be performed by the mobile device; responsive to receiving the message, determine whether to update policy information stored by the mobile device; and based on said determining whether to update policy information stored by the mobile device, transmit an acknowledgement that the policy information is up to date or transmit an update to the policy information.
16 . The apparatus of claim 10 , wherein the providing the policy file includes publishing the policy file to an application store that also publishes the managed application.
17 . The apparatus of claim 10 , wherein providing the policy file includes pushing the policy file to the mobile device based on the mobile device being registered with a push service.
18 . One or more non-transitory computer-readable media storing instructions configured to, when executed, cause at least one computing device to:
display a user interface that displays one or more policy settings for a managed application that is to be made available for download to a mobile device, wherein each of the one or more policy settings provides a constraint to be enforced by the mobile device prior to the managed application being provided access to at least one resource that is accessible through an access gateway; receive input via the user interface that creates or modifies a selective wipe setting of the one or more policy settings, wherein the selective wipe setting specifies one or more conditions that cause the mobile device delete data from the mobile device; produce a policy file for the managed application that includes the selective wipe setting; and provide the policy file such that the policy file is available for download to the mobile device.
19 . The one or more non-transitory computer-readable media of claim 18 , wherein the policy file is an Extensible Markup Language (XML) file or a JavaScript Object Notation (JSON) file, and wherein the policy file includes one or more key/value pairs organized as a dictionary, wherein each key/value pair of the one or more key/value pairs corresponds to one of the one or more modified policy settings.
20 . The one or more non-transitory computer-readable media of claim 18 , wherein the instructions are configured to, when executed, further cause said at least one computing device to:
receive additional input specifying one or more additional policy settings, wherein said one or more additional policy settings includes an additional selective wipe setting that specifies a constraint different from the one or more constraints that are specified by the selective wipe setting; produce an additional policy file for the managed application that includes the one or more additional policy settings, wherein the additional policy file is assigned to a first user role; and provide said additional policy file for download in accordance with a requesting user that is assigned the first user role; wherein the policy file is assigned to a second user role different from the first user role.Join the waitlist — get patent alerts
Track US2014109176A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.