IP Library Granted Patent US 8,931,042
Granted Patent B1
US 8,931,042 · App. 13/316,426 · Granted Jan 6, 2015

Dividing a data processing device into separate security domains

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,931,042
App. No.
13/316,426
Granted
Jan 6, 2015
Kind
B1
Abstract

This invention creates separation between personal applications and corporate applications on a data processing device, so that both types of applications can run simultaneously while complying with all required policies. This enables employees to use their personal devices for work purposes, or work devices for personal purposes. The separation is created by dividing the data processing device into two or more “domains”, each with its own policies. These policies may be configured by the device owner, an IT department, or other data or application owner.

Claims (30)

1. A method for operating a computer data processing device having an operating system in two or more data security domains, comprising:

providing in data memory associated with said computer data processing device at least one external policy defining at least one computer data processing device appli- cation and data domain;

associating computer data processing device application and data with said at least one domain;

providing at least one persistent control mechanism over said computer data pro- cessing device application and data associated with said at least one domain, said persistent control mechanism being subject to policies defined for said at least one domain, said persistent control mechanism being separate from said operating sys- tem and said persistent control mechanism being configured to intercept requests from said computer data processing device application to said operating system; and

providing at least one mechanism for fine-grained policy-based control over operations by, and between, said computer data processing device application and data.

2. The method of claim 1 , further comprising physically separating computer data processing application and data in first domain from computer data processing application and data in a second domain.

3. The method of claim 2 , further comprising mediating communications between said computer data processing application in said first domain from said computer data processing applications in said second domain.

4. The method of claim 3 , wherein applications in said first domain cannot communicate with applications in said second domain.

5. The method of claim 3 , wherein said mediating is provided dynamically in response to said providing said external policy.

6. The method of claim 1 , further comprising assigning said domain dynamically using at least one domain determinant selected from the group consisting of: a pre-calculated determinant, a determinant stored with said computer data processing device application, a determinant store with said policy, and a determinant created when a request for a domain is received by the operating system of said computer data processing device.

7. A computer data processing device having an operating system and configured to operate securely in two or more data security domains, comprising:

data memory associated with said computer data processing device holding at least one external policy defining at least one computer data processing device application and data domain;

computer processor instructions effective to associate said computer data processing device application and data with said at least one domain;

computer processor instructions for receiving at least one persistent control mechanism over said computer data processing device application and data associated with said at least one domain, said persistent control mechanism being subject to policies defined for said at least one domain, said persistent control mechanism being separate from said operating system and said persistent control mechanism being configured to intercept requests from said computer data processing device application to said operating system; and

computer processor instructions for providing at least one mechanism for fine-grained policy-based control over operations by, and between, said computer data processing device application and data.

8. The computer data processing device of claim 7 , further comprising physically separating computer data processing application and data in a first domain from computer data processing application and data in a second domain.

9. The computer data processing device of claim 8 , further comprising mediating communications between said computer data processing application in said first domain from said computer data processing applications in said second domain.

10. The computer data processing device of claim 9 , wherein applications in said first domain cannot communicate with applications in said second domain.

11. The computer data processing device of claim 9 , wherein said mediating is provided dynamically in response to: said providing said external policy.

12. The computer data processing device of claim 7 , further comprising assigning said domain dynamically using at least one domain determinant selected from the group consisting of: a pre-calculated determinant, a determinant stored with said computer data processing device application, a determinant store with said policy, and a determinant created when a request for a domain is received the operating system of said computer data processing device.

13. A non-transitory computer-readable medium containing a computer program product for operating a computer data processing device having an operating system, said computer program product being configured to enable said computer data processing device to operate securely in two or more data security domains, said computer program product being configured to enable said computer data processing device to perform actions comprising:

receiving in data memory associated with said computer data processing device at least one external policy defining at least one computer data processing device application and data domain;

associating computer data processing device application and data with said at least one domain;

providing at least one persistent control mechanism over said computer data processing device application and data associated with said at least one domain, said persistent control mechanism being subject to policies defined for said at least one domain, said persistent control mechanism being separate from said operating system and said persistent control mechanism being configured to intercept requests from said computer data processing device application to said operating system; and

providing at least one mechanism for fine-grained policy-based control over operations by, and between, said computer data processing device application and data.

14. The non-transitory computer readable medium of claim 13 , wherein said computer program product is further configured to enable said computer data processing device to separate physically computer data processing application and data in a first domain from computer data processing application and data in a second domain.

15. The non-transitory computer readable medium of claim 14 , wherein said computer program product is further configured to enable said computer data processing device to mediate communications between said computer data processing application in said first domain from said computer data processing applications in said second domain.

16. The non-transitory computer readable medium of claim 15 , wherein said computer program product is further configured to enable said computer data processing device to prevent applications in said first domain from communicating with applications in said second domain.

17. The non-transitory computer readable medium of claim 15 , wherein said computer program product is further configured to enable said computer data processing device to mediate said communications dynamically in response to said providing said external policy.

18. The non-transitory computer readable medium of claim 13 , wherein said computer program product is further configured to enable said computer data processing device to assign said domain dynamically using at least one domain determinant selected from the group consisting of: a pre-calculated determinant, a determinant stored with said computer data processing device application, a determinant store with said policy, and a determinant created when a request for a domain is received by the operating system of said computer data processing device.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: CELLSEC, INC.
To: PULSE SECURE, LLC.
Reel/Frame 060903/0497 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Mar 17, 2017
From: CELLSEC, INC.
To: GOLDSCHLAG, DAVID; WEISS, YOAV; ACCEL XI L.P.; ACCEL STRATEGIC PARTNERS; ACCEL INVESTORS 2012 L.L.C.; SVIC NO. 22 NEW TECHNOLOGY BUSINESS INVESTMENT L.L.P.; THE MOSS YAMANOUCHI FAMILY TRUST; TRANSPLAN ENTERPRISES; GLASER INVESTMENTS; MARKER LANTERN III LTD.
Reel/Frame 041619/0122 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2016
From: GOLDSCHLAG, DAVID; WEISS, YOAV; GINTER, KARL; BARTMAN, MICHAEL
To: CELLSEC, INC.
Reel/Frame 040118/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2016
From: WEISS, YOAV; GINTER, KARL; GOLDSCHLAG, DAVID; BARTMAN, MICHAEL
To: CELLSEC, INC.
Reel/Frame 038843/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2013
From: WEISS, YOAV, MR.; GOLDSCHLAG, DAVID, MR.; GINTER, KARL, MR.; BARTMAN, MICHAEL, MR.
To: CELLSEC, INC.
Reel/Frame 030584/0614 →