IP Library Granted Patent US 9,280,377
Granted Patent B2
US 9,280,377 · App. 13/886,889 · Granted Mar 8, 2016

Application with multiple operation modes

Inventors: Zhongmin Lang (Parkland, FL); Gary Barton (Boca Raton, FL)
Assignee: Citrix Systems, Inc.
G06F9/4555G06F11/3051H04L63/102H04L63/105H04L63/107H04L63/20H04W12/08G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,280,377
App. No.
13/886,889
Granted
Mar 8, 2016
Kind
B2
Abstract

A method and system for operating an application with multiple modes are described. A plurality of applications may be presented to a user on a mobile device and one of the displayed applications may be selected. The selected application may have one or more contexts that are determined based on one or more operational parameters. For example, a context for the selected application may be that the application is configured to access an enterprise account. Based on the context, the selected application may be run on the mobile device in one of a plurality of operations modes. The operation modes may comprise managed, unmanaged, and partially managed modes, among others.

Claims (83)

1. A method comprising:

presenting, to a user, an interface comprising a plurality of applications on a computing device;

receiving, from the user, a selection for one of the plurality of applications;

determining a context for the selected application based on one or more operational parameters of the computing device executing the selected one of the plurality of applications, wherein determining the context comprises:

analyzing an account used within the selected application;

analyzing a location for the computing device;

monitoring whether a predetermined application is running on the computing device;

analyzing one or more network connections for the computing device; and

analyzing one or more settings for the computing device;

comparing the determined context with one or more policies for the selected application, wherein the one or more policies for the selected application differ from one or more policies for a second application, wherein each policy defines one or more access controls set for the selected application, wherein the one or more access controls are enforced by a management system on the computing device when the selected application is executing on the computing device, and wherein the comparison comprises:

comparing the account used within the selected application to one or more account policies for the selected application;

comparing the location for the computing device to one or more location policies for the selected application;

comparing the monitored predetermined application to one or more application policies for the selected application;

comparing the one or more detected network connections to one or more network connection policies for the selected application; and

comparing the one or more analyzed settings to one or more settings policies for the selected application;

determining one of a plurality of operation modes for the selected application based on the comparison of the determined context with the one or more policies for the selected application, wherein the plurality of operation modes comprises at least an unmanaged mode and a managed mode; and

running the selected application in the determined operation mode on the computing device.

2. A method according to claim 1 ,

wherein when the account used within the selected application is an enterprise account, the determined one of the plurality of operation modes for the selected application is the managed mode.

3. A method according to claim 1 ,

wherein when the location for the computing device is on company premises, the determined one of the plurality of operation modes for the selected application is the managed mode, and

wherein data communicated from the computing device to the selected application running in the managed mode is encrypted.

4. A method according to claim 1 ,

wherein when the predetermined application is monitored to be running on the computing device, the determined one of the plurality of operation modes for the selected application is the managed mode.

5. A method according to claim 1 , wherein the context comprises a predetermined default operation mode for the selected application.

6. A method according to claim 1 , further comprising:

monitoring, while the selected application is running, an updated context for the selected application; and

switching from the determined operation mode for the selected application to a different one of the plurality of operation modes based on the monitoring.

7. A method according to claim 6 , wherein the updated context comprises one or more of a received indication from the user, an accessed account, an accessed document that comprises a secure document, a detected launch of a predetermined application, a change in a network connection for the computing device, and a monitored location for the computing device running the selected application.

8. A method according to claim 1 , wherein running the selected application in the managed mode comprises one or more of encrypting communication for the selected application, encrypting data saved by the selected application, allowing the selected application to access secure documents, allowing the selected application to access secure resources, and allowing the selected application to access a secure portal.

9. A method according to claim 1 , wherein the plurality of operation modes further comprises a partially managed mode.

10. A computing device comprising:

a processor, wherein the computing device is configured to at least:

present, to a user, an interface comprising a plurality of applications on the computing device;

receive, from the user, a selection for one of the plurality of applications;

determine a context for the selected application based on or more operational parameters of the computing device executing the selected one of the plurality of applications, wherein determining the context comprises;

analyze an account used within the selected application;

analyze a location for the computing device;

monitor whether a predetermined application is running on the computing device;

analyze one or more network connections for the computing device; and

analyze one or more settings for the computing device;

compare the determined context with one or more policies for the selected application, wherein the one or more policies for the selected application differ from one or more policies for a second application, wherein each policy defines one or more access controls set for the selected application, wherein the one or more access controls are enforced by a management system on the computing device when the selected application is executing on the computing device, and wherein the comparison comprises:

compare the account used within the selected application to one or more account policies for the selected application;

compare the location for the computing device to one or more location policies for the selected application;

compare the monitored predetermined application to one or more application policies for the selected application;

compare the one or more detected network connections to one or more network connection policies for the selected application; and

compare the one or more analyzed settings to one or more settings policies for the selected application;

determine one of a plurality of operation modes for the selected application based on the comparison of the determined context with the one or more policies for the selected application, wherein the plurality of operation modes comprises at least an unmanaged mode and a managed mode; and

run the selected application in the determined operation mode on the computing device.

11. A computing device of claim 10 ,

wherein when the account used within the selected application is an enterprise account, the determined one of the plurality of operation modes for the selected application is the managed mode.

12. A computing device of claim 10 ,

wherein when the location for the computing device is on company premises, the determined one of the plurality of operation modes for the selected application is the managed mode, and

wherein data communicated from the computing device to the selected application running in the managed mode is encrypted.

13. A computing device according to claim 10 ,

wherein when the predetermined application is monitored to be running on the computing device, the determined one of the plurality of operation modes for the selected application is the managed mode.

14. A computing device according to claim 10 , wherein the computing device is further configured to at least:

monitor, while the selected application is running, an updated context for the selected application; and

switch from the determined operation mode for the selected application to a different one of the plurality of operation modes based on the monitoring.

15. A computing device according to claim 14 , wherein the updated context comprises one or more of a received indication from the user, an accessed account, an accessed document that comprises a secure document, a detected launch of a predetermined application, a change in a network connection for the computing device, and a monitored location for the computing device running the selected application.

16. A computing device according to claim 10 , wherein running the selected application in the managed mode comprises one or more of encrypting communication for the selected application, encrypting data saved by the selected application, allowing the selected application to access secure documents, allowing the selected application to access secure resources, and allowing the selected application to access a secure portal.

17. A computing device according to claim 10 , wherein the plurality of operation modes further comprises a partially managed mode.

18. One or more non-transitory computer-readable storage media storing computer-executable instructions that, when executed by one or more processors of a data processing system, cause the system to perform:

presenting, to a user, an interface comprising a plurality of applications on a computing device;

receiving, from the user, a selection for one of the plurality of applications;

determining a context for the selected application based on one or more operational parameters of the computing device executing the selected one of the plurality of applications, wherein determining the context comprises:

analyzing an account used within the selected application;

analyzing a location for the computing device;

monitoring whether a predetermined application is running on the computing device;

analyzing one or more network connections for the computing device; and

analyzing one or more settings for the computing device;

comparing the determined context with one or more policies for the selected application, wherein the one or more policies for the selected application differ from one or more policies for a second application, wherein each policy defines one or more access controls set for the selected application, wherein the one or more access controls are enforced by a management system on the computing device when the selected application is executing on the computing device, and wherein the comparison comprises:

comparing the account used within the selected application to one or more account policies for the selected application;

comparing the location for the computing device to one or more location policies for the selected application;

comparing the monitored predetermined application to one or more application policies for the selected application;

comparing the one or more detected network connections to one or more network connection policies for the selected application; and

comparing the one or more analyzed settings to one or more settings policies for the selected application;

determining one of a plurality of operation modes for the selected application based on the comparison of the determined context with the one or more policies for the selected application, wherein the plurality of operation modes comprises at least an unmanaged mode and a managed mode; and

running the selected application in the determined operation mode on the computing device.

19. A method according to claim 1 , wherein the one or more policies define the operation mode corresponding to the context for the selected application,

wherein the one or more policies are stored and managed by a policy manager.

20. A computing device according to claim 10 , wherein the one or more policies define the operation mode corresponding to the context for the selected application,

wherein the one or more policies are stored and managed by a policy manager.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2013
From: LANG, ZHONGMIN; BARTON, GARY
To: CITRIX SYSTEMS, INC.
Reel/Frame 031128/0171 →
Continuity (2)
Provisional Application 61806577 · Mar 29, 2013
Related Publication 20140330990A1 · Nov 6, 2014