System Of Multiple Domains And Domain Ownership
Abstract
Methods and instrumentalities are disclosed that enable one or more domains on one or more devices to be owned or controlled by one or more different local or remote owners, while providing a level of system-wide management of those domains. Each domain may have a different owner, and each owner may specify policies for operation of its domain and for operation of its domain in relation to the platform on which the domain resides, and other domains. A system-wide domain manager may be resident on one of the domains. The system-wide domain manager may enforce the policies of the domain on which it is resident, and it may coordinate the enforcement of the other domains by their respective policies in relation to the domain in which the system-wide domain manager resides. Additionally, the system-wide domain manager may coordinate interaction among the other domains in accordance with their respective policies.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A device comprising:
a plurality of domains that are isolated from each other; a system wide domain manager (SDM) that resides in one of the plurality of domains; and at least one secure domain of the plurality of domains that is isolated from the other domains such that specific computing resources of the at least one secure domain cannot be accessed by other domains, the at least one secure domain owned by a remote owner that is different than an owner of the SDM, the remote owner capable of specifying a policy for operations of the at least one secure domain, wherein the SDM is configured to supervise a download of a profile in the at least one secure domain owned by the remote owner, such that 1) if the policy is included in the profile, the device is configured to perform a check of the policy against policy information held by the SDM to determine whether the download of the profile can proceed, and 2) if the download of the profile is authorized, the device is configured to determine whether user consent is required to download the profile.
22 . The device as recited in claim 21 , wherein the device is further configured to, when user consent is required to download the profile, seek the user consent to download the profile.
23 . The device as recited in claims 21 , wherein the device is further configured to obtain the policy information held by the SDM from a preconfigured file comprising a system-wide domain policy (SDP).
24 . The device as recited in claim 23 , wherein policies associated with the plurality of domains are permitted or denied in accordance with the SDP.
25 . The device as recited in claim 21 , wherein the SDM is further configured to enforce policies such that a first domain of the plurality of domains that is owned by a first remote owner is not setup while a second domain owned by a different remote owner than the first remote owner is active.
26 . The device as recited in claim 21 , wherein the SDM is further configured to enforce policies such that, when a first domain of the plurality of domains that is owned by a first remote owner becomes active, other domains of the plurality of domains owned by a different remote owner than the first remote owner cannot become active.
27 . The device as recited in claim 21 , wherein the SDM is further configured to enforce policies such that user consent is obtained for authorizing when a new domain of the plurality of domains is made active.Join the waitlist — get patent alerts
Track US2018152841A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.