IP Library Granted Patent US 9,396,346
Granted Patent B2
US 9,396,346 · App. 14/302,541 · Granted Jul 19, 2016

System and method for accessing and updating secured data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,396,346
App. No.
14/302,541
Granted
Jul 19, 2016
Kind
B2
Abstract

A method is provided for use on an electronic device having a display, a communication component, a memory, and a processor coupled to the display, the communication component, and the memory. The memory stores data in a first sandbox and data in a second sandbox, the first sandbox being a secure sandbox and having a shadow data component, the shadow data component storing a subset of the data stored in the first sandbox. The method comprises, in response to a request, providing the data stored in the first sandbox when the first sandbox is in an unlocked mode and providing the data stored in the shadow data component when the first sandbox is in a locked mode.

Claims (46)

1. An electronic device comprising:

a display;

a communication component;

a memory storing first data in a first sandbox and second data in a second sandbox, the first sandbox being a secure sandbox and having a shadow data component, the shadow data component storing a subset of the first data stored in the first sandbox; and

a processor coupled to the display, the communication component, and the memory, the processor being configured to:

in response to a request:

provide the first data stored in the first sandbox when the first sandbox is in an unlocked mode; and

provide the first data stored in the shadow data component when the first sandbox is in a locked mode.

2. The electronic device according to claim 1 , wherein the processor is further configured to:

receive from a server via the communication component information for updating the first data stored in the first sandbox;

update the first data stored in the first sandbox when the first sandbox is in the unlocked mode; and

update the first data stored in the shadow component.

3. The electronic device according to claim 1 , wherein the first sandbox further has an associated queue and the processor is further configured to:

receive from a server via the communication component information for updating the first data stored in the first sandbox;

store the information for updating the first data stored in the first sandbox in the queue when the first sandbox is in the locked mode; and

update the first data stored in the shadow data component.

4. The electronic device according to claim 3 , wherein the processor is further configured to:

update the first data stored in the first sandbox based on the information for updating the first data stored in the first sandbox stored in the queue when the first sandbox enters the unlocked mode.

5. The electronic device according to claim 1 , wherein both the first sandbox and the second sandbox are controlled exclusively by a single operating system, the first data stored in the first sandbox is encrypted, and the first data stored in the shadow data component is a redundant subset of the first data stored in the first sandbox.

6. The electronic device according to claim 1 , wherein the electronic device displays an update on the display using the first data stored in the shadow data component when the first sandbox is in the locked mode.

7. The electronic device according to claim 6 , wherein the update is selected from the group consisting of a calendar reminder, an email notification, and a contact list entry.

8. The electronic device according to claim 3 , wherein an element of the first data that is stored in both the first sandbox and the shadow data component is associated by a first identifier and an element of the first data that is stored in both the queue and the shadow data component is associated by a second identifier.

9. The electronic device according to claim 1 , wherein when the first sandbox is in the locked mode, all of the first data stored in the first sandbox is inaccessible except for first data stored in a start-up area of the first sandbox until access to the first sandbox is authenticated and wherein the shadow data component is stored in the start-up area.

10. A method for use on an electronic device having a display, a communication component, a memory storing first data in a first sandbox and second data in a second sandbox, the first sandbox being a secure sandbox and having a shadow data component, the shadow data component storing a subset of the first data stored in the first sandbox, and a processor coupled to the display, the communication component, and the memory, the method comprising:

in response to a request:

providing the first data stored in the first sandbox when the first sandbox is in an unlocked mode; and

providing the first data stored in the shadow data component when the first sandbox is in a locked mode.

11. The method according to claim 10 , further comprising:

receiving from a server via the communication component information for updating the first data stored in the first sandbox;

updating the first data stored in the first sandbox when the first sandbox is in the unlocked mode; and

updating the first data stored in the shadow component.

12. The method according to claim 10 , wherein the first sandbox further has an associated queue, the method further comprising:

receiving from a server via the communication component information for updating the first data stored in the first sandbox;

storing the information for updating the first data stored in the first sandbox in the queue when the first sandbox is in the locked mode; and

updating the first data stored in the shadow data component.

13. The method according to claim 12 , further comprising:

updating the first data stored in the first sandbox based on the information for updating the first data stored in the first sandbox stored in the queue when the first sandbox enters the unlocked mode.

14. The method according to claim 10 , wherein both the first sandbox and the second sandbox are controlled exclusively by a single operating system, the first data stored in the first sandbox is encrypted, and the first data stored in the shadow data component is a redundant subset of the first data stored in the first sandbox.

15. The method according to claim 10 , further comprising displaying an update on the display using the first data stored in the shadow data component when the first sandbox is in the locked mode.

16. The method according to claim 15 , wherein the update is selected from the group consisting of a calendar reminder, an email notification, and a contact list entry.

17. The method according to claim 12 , wherein an element of first data that is stored in both the first sandbox and the shadow data component is associated by a first identifier and an element of first data that is stored in both the queue and the shadow data component is associated by a second identifier.

18. The method according to claim 10 , wherein when the first sandbox is in the locked mode, all of the first data stored in the first sandbox is inaccessible except for first data stored in a start-up area of the first sandbox until access to the first sandbox is authenticated and wherein the shadow data component is stored in the start-up area.

19. A computer program product comprising a non-transitory computer readable medium having stored thereon computer executable instructions that when executed by a computer perform a method for use on the computer having a display, a communication component, a memory storing first data in a first sandbox and second data in a second sandbox, the first sandbox being a secure sandbox and having a shadow data component, the shadow data component storing a subset of the first data stored in the first sandbox, and a processor coupled to the display, the communication component, and the memory, the method comprising:

in response to a request:

providing the first data stored in the first sandbox when the first sandbox is in an unlocked mode; and

providing the first data stored in the shadow data component when the first sandbox is in a locked mode.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2020
From: 2236008 ONTARIO INC.
To: BLACKBERRY LIMITED
Reel/Frame 053313/0315 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2015
From: WILLIS, EDWARD SNOW; FALLOON, ALAN EDWARD; INGLIS, DAVID ALAN
To: QNX SOFTWARE SYSTEMS LIMITED
Reel/Frame 036191/0173 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2015
From: LESPINASSE, JEAN-PHILIPPE; LEROUX, FRANCOIS; JHAJ, JASVIR; ASOKAN, PRAVEENA; WIKKERINK, EARL JOHN; GEUE, ALAN; LAM, BENTON HEI-WAH; TRAVERS, CHRISTOPHER SCOTT; LOGAN, ADRIAN MICHAEL; CASSIDY, JOHN WILLIAM
To: BLACKBERRY LIMITED
Reel/Frame 036191/0551 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE CORPORATE IDENTIFIER INADVERTENTLY LISTED ON THE ASSIGNMENT AND COVERSHEET AS "LIMITED" PREVIOUSLY RECORDED ON REEL 035700 FRAME 0845. ASSIGNOR(S) HEREBY CONFIRMS THE IDENTIFIER SHOULD HAVE STATED "INC.". Recorded May 27, 2015
From: QNX SOFTWARE SYSTEMS LIMITED
To: 2236008 ONTARIO INC.
Reel/Frame 035785/0156 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2015
From: QNX SOFTWARE SYSTEMS LIMITED
To: 2236008 ONTARIO LIMITED
Reel/Frame 035700/0845 →