IP Library Granted Patent US 8,539,561
Granted Patent B2
US 8,539,561 · App. 12/862,335 · Granted Sep 17, 2013

Systems and methods to control device endpoint behavior using personae and policies

Inventors: Akhilesh Gupta (Stanford, CA); Anupam Joshi (New Delhi, IN); Gopal S. Pingali (Bangalore, IN)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,539,561
App. No.
12/862,335
Granted
Sep 17, 2013
Kind
B2
Abstract

The creation of multiple personae in mobile devices. Access to personae is controlled based on the persona that is currently active. The creation or existence of different personae helps prevent data leakage or loss, in that any or all of the following characteristics, by way of example, may be manifested: business data and applications are firewalled from applications or other items associated with personal use; connectivity of the device is controlled; resources (such cameras, GPS, other sensors, etc.) on the device are controlled; data are protected even if removable storage or the device itself are lost.

Claims (37)

1. A method comprising:

utilizing a processor to execute computer code configured to perform the steps of:

defining a plurality of personae for a device, each persona according variable access responsive to different access criteria;

applying a policy for each persona, each policy defining conditions for the different access criteria;

defining a sandbox for each persona based on the policy of each persona, each sandbox comprising a security mechanism for separating running programs; and

according access to device resources responsive to access criteria;

said according of access comprising mounting at least one data file relative to at least one of the personae.

2. The method according to claim 1 , wherein said defining comprises defining personae based on usage contexts.

3. The method according to claim 2 , wherein said defining personae based on usage contexts comprises defining an enterprise persona.

4. The method according to claim 3 , wherein said defining personae based on usage contexts comprises defining a personal persona.

5. The method according to claim 1 , wherein said defining comprises defining personae based on geographical location.

6. The method according to claim 1 , wherein said according of access is triggered automatically.

7. The method according to claim 6 , wherein said according of access is triggered responsive to secure authentication by a user.

8. The method according to claim 7 , further comprising providing a key to the device responsive to secure authentication by a user and thereafter according the user access to predetermined data.

9. The method according to claim 1 , wherein the device comprises a mobile device.

10. An apparatus comprising:

one or more processors; and

a computer readable storage medium having computer readable program code embodied therewith and executable by the one or more processors, the computer readable program code comprising:

computer readable program code configured to define a plurality of personae for a device, each persona according variable access responsive to different access criteria;

computer readable program code configured to apply a policy for each persona, each policy defining conditions for the different access criteria;

computer readable program code configured to define a sandbox for each persona based on the policy of each persona, each sandbox comprising a security mechanism for separating running programs; and

computer readable program code configured to accord access to device resources responsive to access criteria, via mounting at least one data file relative to at least one of the personae.

11. The apparatus according to claim 10 , wherein the device comprises a mobile device.

12. A computer program product comprising:

a non-transitory computer readable storage medium having computer readable program code embodied therewith, the computer readable program code comprising:

computer readable program code configured to define a plurality of personae for a device, each persona according variable access responsive to different access criteria;

computer readable program code configured to apply a policy for each persona, each policy defining conditions for the different access criteria;

computer readable program code configured to define a sandbox for each persona based on the policy of each persona, each sandbox comprising a security mechanism for separating running programs; and

computer readable program code configured to accord access to device resources responsive to access criteria, via mounting at least one data file relative to at least one of the personae.

13. The computer program product according to claim 12 , wherein said computer readable program code is configured to define personae based on usage contexts.

14. The computer program product according to claim 13 , wherein said computer readable program code is configured to define an enterprise persona.

15. The computer program product according to claim 14 , wherein said computer readable program code is configured to define a personal persona.

16. The computer program product according to claim 12 , wherein said computer readable program code is configured to define personae based on geographical location.

17. The computer program product according to claim 12 , wherein said computer readable program code is configured to accord access via an automatic trigger.

18. The computer program product according to claim 17 , wherein said computer readable program code is configured to accord access automatically responsive to secure authentication by a user.

19. The computer program product according to claim 18 , wherein said computer readable program code is further configured to provide a key to the device responsive to secure authentication by a user and thereafter accord the user access to predetermined data.

20. The computer program product according to claim 12 , wherein the device comprises a mobile device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2022
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: SERVICENOW, INC.
Reel/Frame 058711/0689 →
CORRECTIVE ASSIGNMENT TO CORRECT THE LAST INVENTOR NAME PREVIOUSLY RECORDED AT REEL: 024923 FRAME: 0189. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 22, 2018
From: GUPTA, AKHILESH; JOSHI, ANUPAM; PINGALI, GOPAL S.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047389/0296 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2010
From: GUPTA, AKHILESH; JOSHI, ANUPAM; PINGALI, GOPA S.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 024923/0189 →
Continuity (1)
Related Publication 20120054853A1 · Mar 1, 2012