IP Library Granted Patent US 10,848,435
Granted Patent B2
US 10,848,435 · App. 14/290,264 · Granted Nov 24, 2020

Method and system for administering multiple domain management authorities on a mobile device

Inventors: Sivakumar Nagarajan (Ottawa, CA); Daniel Jonas Major (Ottawa, CA); Kevin Goodman (Nepean, CA)
Assignee: BlackBerry Limited
H04L47/80H04L41/5054H04L67/16H04W12/0027H04W12/08H04W12/00502H04W12/00503
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,848,435
App. No.
14/290,264
Granted
Nov 24, 2020
Kind
B2
Abstract

A method for administering multiple management agents on a mobile device, the method receiving, at a policy manager on the mobile device, a policy from each of the multiple management agents; determining a current state of the mobile device; and consolidating the policies based on rules within the policy manager and the current state of the mobile device.

Claims (47)

1. A method for administering multiple management agents on a mobile device comprising two or more domains, the method comprising:

receiving, at a policy manager on the mobile device, a policy from each of the multiple management agents on the mobile device, the policies controlling at least one of: access to shared services on the mobile device; security on the mobile device; or permissions for functionality of the mobile device;

establishing, by the policy manager, a hierarchy of trust designating, for each management agent, a respective level of trust of the management agent, the respective level of trust of the management agent being a function of a vendor that provided the management agent, wherein the is known to the policy manager and is associated with a level of trust;

determining which one or more of the domains are currently active;

consolidating, by the policy manager on the device, the policies based on rules within the policy manager and as a function of which one or more of the domains are currently active and the hierarchy of trust, thereby generating a consolidated policy; and

applying the consolidated policy on the mobile device, thereby controlling at least one of: access to shared services on the mobile device; security on the mobile device; or permissions for functionality of the mobile device;

wherein each of the management agents is an entity on the mobile device which receives policies from a corresponding external management authority.

2. The method of claim 1 , wherein the consolidating comprises creating an aggregate restriction set based on restriction sets in the policies of each of the multiple management agents.

3. The method of claim 2 , wherein the aggregated restriction set controls the access to shared services on the mobile device, the security on the mobile device, and the permissions for functionality of the mobile device.

4. The method of claim 2 , further comprising updating the aggregated restriction set responsive to one of the two or more domains becoming active.

5. The method of claim 4 , wherein the consolidating the policies is further based on at least one of: time of day, location of the mobile device, the network serving the mobile device, or regulation changes for the mobile device.

6. The method of claim 1 , wherein consolidating the policies allows a management agent full control of a domain it is associated with, but limited control of the shared services or functionality outside of the domain the management agent is associated with.

7. The method of claim 1 , wherein a policy for a management agent applies both to a domain associated with the management agent, as well as to other domains.

8. The method of claim 1 , further comprising updating the consolidated policy upon addition of a new management agent.

9. A mobile device having a plurality of domains, the domains comprising concurrently operative operating systems, the mobile device comprising:

a processor; and

memory,

wherein the mobile device is configured to:

receive, at a policy manager on the mobile device, a policy from each of multiple management agents on the mobile device, the policies controlling at least one of: access to shared services on the mobile device; security on the mobile device; or permissions for functionality of the mobile device;

establish, by the policy manager, a hierarchy of trust designating, for each management agent, a respective level of trust of the management agent, the respective level of trust of the management agent being a function of a vendor that provided the management agent, wherein the vendor is known to the policy manager and is associated with a level of trust;

determine which one or more of the domains are currently active;

consolidate, by the policy manager, the policies based on rules within the policy manager and as a function of which one or more of the domains are currently active and the hierarchy of trust, thereby generating a consolidated policy; and

apply the consolidated policy on the mobile device;

wherein each of the management agents is an entity on the mobile device which receives policies from a corresponding external management authority.

10. The mobile device of claim 9 , wherein the mobile device is configured to consolidate by creating an aggregate restriction set based on restriction sets in the policies of each of the multiple management agents.

11. The mobile device of claim 10 , wherein the aggregated restriction set controls the access to shared services on the mobile device, the security on the mobile device, and the permissions for functionality of the mobile device.

12. The mobile device of claim 10 , wherein the mobile device is further configured to update the aggregated restriction set responsive to one of the two or more domains becoming active.

13. The mobile device of claim 12 , wherein the consolidating the policies is further based on at least one of: time of day, location of the mobile device, the network serving the mobile device, or regulation changes for the mobile device.

14. The mobile device of claim 9 , wherein consolidating the policies allows a management agent full control of a domain it is associated with, but limited control of the shared services or functionality outside of the domain the management agent is associated with.

15. The mobile device of claim 9 , wherein a policy for a management agent applies both to a domain associated with the management agent, as well as to other domains.

16. The mobile device of claim 9 , wherein the mobile device is further configured to update the consolidated policy upon addition of a new management agent.

17. A non-transitory computer readable medium having processor executable instructions stored thereon that, when executed by a processor of a mobile device having a plurality of domains, the domains comprising concurrently operative operating systems, cause the mobile device to:

receive, at a policy manager on the mobile device, a policy from each of multiple management agents on the mobile device, the policies controlling at least one of: access to shared services on the mobile device; security on the mobile device; or permissions for functionality of the mobile device;

establish, by the policy manager, a hierarchy of trust designating, for each management agent, a respective level of trust of the management agent, the respective level of trust of the management agent being a function of a vendor that provided the management agent, wherein the vendor is known to the policy manager and is associated with a level of trust;

determine which one or more of the domains are currently active;

consolidate, by the policy manager, the policies based on rules within the policy manager and as a function of which one or more of the domains are currently active and the hierarchy of trust, thereby generating a consolidated policy; and

apply the consolidated policy on the mobile device;

wherein each of the management agents is an entity on the mobile device which receives policies from a corresponding external management authority.

18. The method of claim 1 , Wherein consolidating the policies as a function of the hierarchy of trust comprises:

detecting a conflict between the policies of first and second management agents of the multiple management agents, the level of trust of the first management agent being higher than the level of trust of the second management agent; and

as a result of detecting the conflict, removing the policies of the second management agent.

19. The mobile device of claim 9 , wherein consolidating policies as a function of the hierarchy of trust comprises:

detecting a conflict between the policies of first and second management agents of the multiple management agents, the level of trust of the first management agent being higher than the level of trust of the second management agent; and

as a result of detecting the conflict, removing the policies of the second management agent.

20. The non-transitory computer readable medium of claim 17 , wherein consolidating the policies as a function of the hierarchy of trust comprises:

detecting a conflict between the policies of first and second management agents of the multiple management agents, the level of trust of the first management agent being higher than the level of trust of the second management agent; and

as a result of detecting the conflict, removing the policies of the second management agent.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2020
From: 2236008 ONTARIO INC.
To: BLACKBERRY LIMITED
Reel/Frame 053313/0315 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE CORPORATE IDENTIFIER INADVERTENTLY LISTED ON THE ASSIGNMENT AND COVERSHEET AS "LIMITED" PREVIOUSLY RECORDED ON REEL 035700 FRAME 0845. ASSIGNOR(S) HEREBY CONFIRMS THE IDENTIFIER SHOULD HAVE STATED "INC.". Recorded May 27, 2015
From: QNX SOFTWARE SYSTEMS LIMITED
To: 2236008 ONTARIO INC.
Reel/Frame 035785/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2015
From: QNX SOFTWARE SYSTEMS LIMITED
To: 2236008 ONTARIO LIMITED
Reel/Frame 035700/0845 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2014
From: NAGARAJAN, SIVAKUMAR; MAJOR, DANIEL JONAS; GOODMAN, KEVIN DENNIS
To: QNX SOFTWARE SYSTEMS LIMITED
Reel/Frame 033584/0321 →