IP Library Granted Patent US 9,621,587
Granted Patent B2
US 9,621,587 · App. 14/228,473 · Granted Apr 11, 2017

Method of customizing a standardized IT policy

Inventors: Phillip Roberts (Waterloo, CA); Ronald J.J. Hanson (Mount Forest, CA); Rudy Eugene Rawlins (Scarborough, CA)
Assignee: BlackBerry Limited
H04L63/20G06F21/31H04L41/0893H04L63/102H04L63/104H04W8/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,621,587
App. No.
14/228,473
Granted
Apr 11, 2017
Kind
B2
Abstract

A system and method are described herein for standardizing an IT policy that is used to configure devices operating on a network. An IT policy can be generated that applies to a group of users or to one or more special users without having to define and store a new IT policy for each special user. This can be achieved by specifying global and per-user IT policy rules and merging these rules as needed to produce IT policy data.

Claims (44)

1. A method of providing a policy to configure devices associated with a group of users, the policy being customizable on a per-user basis and constituting a set of rules that limit functionality of at least one application residing on the devices, the method comprising:

storing policy rules that are applicable to all users within the group of users;

responsive to detecting a change in the policy rules, determining whether there exists at least one user within the group of users for which per-user policy rules are stored, the per-user policy rules being applicable to the at least one user and set separately from the policy rules; and

in the event that the at least one user exists:

generating user policy data for the at least one user by merging the policy rules and the per-user policy rules;

determining whether a difference exists between the user policy data and stored last policy data that was previously sent to a device associated with the at least one user; and

in the event that the difference exists, sending the user policy data to the device for limiting the functionality of the at least one application.

2. The method of claim 1 , further comprising

determining whether the difference exists by comparing the user policy data with the stored last policy data that was previously sent to the device.

3. The method of claim 1 , further comprising saving settings for the policy rules in a first data structure and saving settings for per-user policy rules in a second data structure, the saving being performed before the generating.

4. The method of claim 1 , further comprising assigning a priority order to multiple groups of users, the priority order facilitating resolution of conflicting settings for policy rules or per-user policy rules when the at least one user is assigned to more than one group of users.

5. The method of claim 1 , further comprising sending a notification to the at least one application residing on the device associated with the at least one user that received the user policy data when the at least one application is affected by the user policy data.

6. The method of claim 1 , further comprising after the sending:

authenticating the user policy data at the device; and

applying the user policy data to the device if the user policy data is authentic.

7. The method of claim 1 , wherein the method further comprises receiving an acknowledgement from the device associated with the at least one user to confirm that the user policy data is received and applied.

8. The method of claim 7 , wherein the method further comprises writing a status of the user policy data to a policy table in the data store when the acknowledgement is received.

9. A non-transitory computer readable medium embodying program code executable by a processor for providing a policy to configure devices associated with a group of users, the policy being customizable on a per-user basis and constituting a set of rules that limit functionality of at least one application residing on the devices, the code comprising instructions for:

storing policy rules that are applicable to all users within the group of users;

responsive to detecting a change in the policy rules, determining whether there exists at least one user within the group of users for which per-user policy rules are stored, the per-user policy rules being applicable to the at least one user and set separately from the policy rules; and

in the event that the at least one user exists:

generating user policy data for the at least one user by merging the policy rules and the per-user policy rules;

determining whether a difference exists between the user policy data and stored last policy data that was previously sent to a device associated with the at least one user; and

in the event that the difference exists, sending the user policy data to the device for limiting the functionality of the at least one application.

10. The non-transitory computer readable medium of claim 9 , wherein the code further comprises instructions for

determining whether the difference exists by comparing the user policy data with the stored last policy data that was previously sent to the device.

11. The non-transitory computer readable medium of claim 9 , wherein the code further comprises instructions for saving settings for the policy rules in a first data structure and settings for per-user policy rules in a second data structure, the saving being done after the generating.

12. The non-transitory computer readable medium of claim 9 , wherein the code further comprises instructions for assigning a priority order to multiple groups of users, the priority order facilitating resolution of conflicts for policy rules or per-user policy rules when the at least one user is assigned to more than one group of users.

13. A server for providing a policy to configure devices associated with a group of users, the policy being customizable on a per-user basis and constituting a set of rules that limit functionality of at least one application residing on the devices, the server comprising:

a processor adapted to generate policy data;

a network interface coupled to the processor and being adapted to allow the server to communicate with the network; and

a memory unit coupled to the processor, the memory unit being adapted to store applications and data related to the policy,

wherein, the processor is configured:

to store policy rules that are applicable to all users within the group of users;

responsive to detecting a change in the policy rules, to determine whether there exists at least one user within the group of users for which per-user policy rules are stored, the per-user policy rules being applicable to the at least one user and set separately from the policy rules; and

in the event that the at least one user exists:

to generate user policy data for the at least one user by merging the policy rules and the per-user policy rules;

to determine whether a difference exists between the user policy data and stored last policy data that was previously sent to a device associated with the at least one user; and

in the event that the difference exists, to send the user policy data to the device for limiting the functionality of the at least one application.

14. The server of claim 13 , wherein the processor is configured to determine whether the difference exists by comparing the user policy data with the stored last policy data that was previously sent to the device.

15. The server of claim 13 , wherein the processor is configured to save settings for the policy rules in a first data structure and settings for per-user policy rules in a second data structure, the saving being done after the generating.

16. The server of claim 13 , wherein the processor is configured to assign a priority order to multiple groups of users, the priority order facilitating resolution of conflicting settings for policy rules or per-user policy rules when the at least one user is assigned to more than one group of users.

17. The server of claim 13 , wherein the processor is configured to send a notification to the at least one application residing on the device associated with the at least one user that received the user policy data when the at least one application is affected by the user policy data.

18. The server of claim 13 , wherein the server is configured to write a status of the user policy data to a policy table in the data store after receiving an acknowledgement from the device associated with the at least one user that the user policy data has been received and applied.

Assignments (4)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064269/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Nov 3, 2014
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 034150/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2014
From: ROBERTS, PHILLIP; RAWLINS, RUDY; HANSON, RON
To: RESEARCH IN MOTION LIMITED
Reel/Frame 032548/0791 →
Continuity (3)
Continuation 13612048 · Sep 12, 2012
Continuation 11362481 · Feb 27, 2006
Related Publication 20140215554A1 · Jul 31, 2014