Policy-Based Application Management
Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.
1 . A method of managing interacting devices, comprising:
receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files;
receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and
running, by the processor, the managed application on the electronic mobile device, the managed application operating in accordance with the set of one or more policy files,
wherein said one or more policy files define one or more conditions under which the electronic mobile device can transfer execution of a process to a second device.
2 . The method of claim 1 , wherein the process is instantiated by the electronic mobile device and is to be executed by the second decide.
3 . The method of claim 1 , wherein the one or more conditions comprise one of the electronic mobile device and the second device being within a predetermined geographic location.
4 . The method of claim 1 , wherein the managed application is a real-time commination application and the process comprises receiving user input for use by the real-time commination application.
5 . The method of claim 1 , wherein the one or more conditions comprise that the second device be proximately located to the electronic mobile device, that the second device be authenticated to the electronic mobile device, and that the second device be allowed to receive the process, based on information in the one or more policy files.
6 . The method of claim 1 , wherein said one or more policy files define one or more conditions under which the electronic mobile device can transfer execution of a process to a third device, wherein said conditions applicable to the third device are different from the conditions applicable to the second device.
7 . The method of claim 1 , wherein the one or more conditions comprise both devices being enrolled in an enterprise mobility management (EMM) service.
8 . One or more non-transitory computer readable media storing computer instructions that, when executed, manage interacting devices by:
receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files;
receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and
running, by the processor, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files,
wherein said one or more policy files define one or more conditions under which the electronic mobile device can transfer execution of a process to a second device.
9 . The computer readable media of claim 8 , wherein the process is instantiated by the electronic mobile device and is to be executed by the second decide.
10 . The computer readable media of claim 8 , wherein the one or more conditions comprise one of the electronic mobile device and the second device being within a predetermined geographic location.
11 . The computer readable media of claim 8 , wherein the process comprises a videocamera service associated with an online meeting application, and wherein the electronic mobile device executes a screen sharing service associated with the online meeting application.
12 . The computer readable media of claim 8 , wherein the one or more conditions comprise that the second device be proximately located to the electronic mobile device, that the second device be authenticated to the electronic mobile device, and that the second device be allowed to receive the process, based on information in the one or more policy files.
13 . The computer readable media of claim 8 , wherein said one or more policy files define one or more conditions under which the electronic mobile device can transfer execution of a process to a third device, wherein said conditions applicable to the third device are different from the conditions applicable to the second device.
14 . The computer readable media of claim 8 , wherein the second device is a printer.
15 . One or more non-transitory computer readable media storing computer instructions that, when executed, manage interacting devices by:
receiving, by an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files;
receiving, by the device, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and
running, by the processor, the managed application on the mobile device, the managed application operating in accordance with the set of one or more policy files,
wherein said one or more policy files define one or more conditions under which the electronic mobile device can transfer execution of a process to a second device.
16 . The computer readable media of claim 15 , wherein the process is instantiated by the electronic mobile device and is to be executed by the second decide.
17 . The computer readable media of claim 15 , wherein the one or more conditions comprise one of the electronic mobile device and the second device being within a predetermined geographic location.
18 . The computer readable media of claim 15 , wherein the process comprises a videocamera service associated with an online meeting application, and wherein the electronic mobile device executes a screen sharing service associated with the online meeting application.
19 . The computer readable media of claim 15 , wherein the one or more conditions comprise that the second device be proximately located to the electronic mobile device, that the second device be authenticated to the electronic mobile device, and that the second device be allowed to receive the process, based on information in the one or more policy files.
20 . The computer readable media of claim 15 , wherein said one or more policy files define one or more conditions under which the electronic mobile device can transfer execution of a process to a third device, wherein said conditions applicable to the third device are different from the conditions applicable to the second device.