US2019354705A1PendingUtilityA1

Multiple containers assigned to an application

Assignee: APPLE INCPriority: Jun 7, 2013Filed: Jul 30, 2019Published: Nov 21, 2019
Est. expiryJun 7, 2033(~6.9 yrs left)· nominal 20-yr term from priority
G06F 21/53G06F 21/62G06F 21/6245
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosed technology addresses the need in the art for assigning multiple containers to a single application. A container can be a specified area of a file system that an assigned application can access to store data, while other applications are restricted access to the container. In some instances, it may be beneficial for multiple applications to share some data, while still maintaining other data in a secure location, thus an application can be assigned to multiple containers, a personal container that can only be accessed by the applications, and a shared container that can be accessed by multiple applications. Further, an application can be assigned an alternate container, in addition to the personal container. The alternate container can be used when an alternate user is using the client device, thus restricting the alternate user from accessing any sensitive data stored in the personal container.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 receiving, by a processor, a command to execute an application on a client device, the application being configured to run in a sand-boxed environment;   determining, by the processor, whether the client device is running in a first mode or a second mode, the first mode being associated with a first container representing a first specified portion of memory on the client device and the second mode being associated with a second container representing a second specified portion of memory on the client device, wherein the first specified portion of memory is different than the second specified portion of memory, and   upon a determination that the client device is running in the first mode, granting the application access to the first specified portion of memory represented by the first container, wherein the application is restricted from accessing the second specified portion of memory while the client device is running in the first mode.   
     
     
         2 . The method of  claim 1 , further comprising:
 upon a determination that the client device is running in the second mode, granting the application access to the second specified portion of memory represented by the second container, wherein the application is restricted from accessing the first specified portion of memory while the client device is running in the first mode.   
     
     
         3 . The method of  claim 2 , wherein the first mode is a primary mode indicating that a primary user associated with the client device is accessing the client device and the first container is a primary container used to store data associated with the primary user. 
     
     
         4 . The method of  claim 3 , wherein the second mode is an alternate mode indicating that an alternate user, different that the primary user, is accessing the client device and the second container is an alternate container used to store data associated with the alternate user. 
     
     
         5 . The method of  claim 4 , further comprising: deleting data stored in the second container. 
     
     
         6 . The method of  claim 5 , wherein the deleting is performed upon a determination that the client device changed from the second mode to the first mode. 
     
     
         7 . A non-transitory computer-readable medium containing instructions that, when executed by a client device, cause the client device to: receive a command to execute an application on the client device, the application being configured to run in a sand-boxed environment;
 determine whether the client device is running in a first mode or a second mode, the first mode being associated with a first container representing a first specified portion of memory on the client device and the second mode being associated with a second container representing a second specified portion of memory on the client device, wherein the first specified portion of memory is different than the second specified portion of memory; and   upon a determination that the client device is running in the first mode, grant the application access to the first specified portion of memory represented by the first container, wherein the application is restricted from accessing the second specified portion of memory while the client device is running in the first mode.   
     
     
         8 . The non-transitory computer-readable medium of  claim 7 , wherein the instructions further causes the client device to:
 upon a determination that the client device is running in the second mode, grant the application access to the second specified portion of memory represented by the second container, wherein the application is restricted from accessing the first specified portion of memory while the client device is running in the first mode.   
     
     
         9 . The non-transitory computer-readable medium of  claim 8 , wherein the first mode is a primary mode indicating that a primary user associated with the client device is accessing the client device and the first container is a primary container used to store data associated with the primary user. 
     
     
         10 . The non-transitory computer-readable medium of  claim 9 , wherein the second mode is an alternate mode indicating that an alternate user, different that the primary user, is accessing the client device and the second container is an alternate container used to store data associated with the alternate user. 
     
     
         11 . The non-transitory computer-readable medium of  claim 10 , wherein the instructions further cause the client device to: delete data stored in the second container. 
     
     
         12 . The non-transitory computer-readable medium of  claim 11 , wherein the deleting is performed upon a determination that the client device changed from the second mode to the first mode. 
     
     
         13 . A data processing system in a client device, the data processing system comprising:
 a processing system;   a memory coupled to the processing system, the memory including a non-transitory computer-readable medium containing instructions that, when executed by the processing system, cause the processing system to:   receive a command to execute an application on the client device, the application being configured to run in a sand-boxed environment;   determine whether the client device is running in a first mode or a second mode, the first mode being associated with a first container representing a first specified portion of memory on the client device and the second mode being associated with a second container representing a second specified portion of memory on the client device, wherein the first specified portion of memory is different than the second specified portion of memory; and   upon a determination that the client device is running in the first mode, grant the application access to the first specified portion of memory represented by the first container, wherein the application is restricted from accessing the second specified portion of memory while the client device is running in the first mode.   
     
     
         14 . The data processing system of  claim 13 , wherein the instructions further causes the processing system to:
 upon a determination that the client device is running in the second mode, grant the application access to the second specified portion of memory represented by the second container, wherein the application is restricted from accessing the first specified portion of memory while the client device is running in the first mode.   
     
     
         15 . The data processing system of  claim 14 , wherein the first mode is a primary mode indicating that a primary user associated with the client device is accessing the client device and the first container is a primary container used to store data associated with the primary user. 
     
     
         16 . The data processing system of  claim 15 , wherein the second mode is an alternate mode indicating that an alternate user, different that the primary user, is accessing the client device and the second container is an alternate container used to store data associated with the alternate user. 
     
     
         17 . The data processing system of  claim 16 , wherein the instructions further cause the processing system to: delete data stored in the second container. 
     
     
         18 . The data processing system of  claim 17 , wherein the deleting is performed upon a determination that the client device changed from the second mode to the first mode.

Join the waitlist — get patent alerts

Track US2019354705A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.