IP Library Granted Patent US 9,659,169
Granted Patent B2
US 9,659,169 · App. 14/566,045 · Granted May 23, 2017

Dividing a data processing device into separate security domains

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,659,169
App. No.
14/566,045
Granted
May 23, 2017
Kind
B2
Abstract

This invention creates separation between personal applications and corporate applications on a data processing device, so that both types of applications can run simultaneously while complying with all required policies. This enables employees to use their personal devices for work purposes, or work devices for personal purposes. The separation is created by dividing the data processing device into two or more “domains”, each with its own policies. These policies may be configured by the device owner, an IT department, or other data or application owner.

Claims (36)

1. A method for operating a computer data processing device having an operating system in two or more data security domains, comprising:

providing in data memory associated with said computer data processing device at least one external policy defining at least one computer data processing device application and data domain;

associating said at least one computer data processing device application and data with said at least one domain;

providing at least one persistent control mechanism over said computer data processing device application and data associated with said at least one application, said persistent control mechanism being subject to policies defined for said at least one domain, said policies being application-specific, user-specific, or data-specific, and said persistent control mechanism being separate from said operating system and said persistent control mechanism being configured to intercept requests from said computer data processing device application to said operating system; and

providing at least one mechanism for fine-grained policy-based control over operations by and between, said computer data processing device application and data.

2. The method of claim 1 , further comprising replacing or modifying a reference to a system call using said persistent control mechanism to redirect said system call to at least one replacement function.

3. The method of claim 2 , further comprising providing said persistent control mechanism in the form of a secured service manager service that replaces the operating system service manager service.

4. The method of claim 3 , further comprising providing at least one secured service using said secured service manager service.

5. The method of claim 4 , wherein said data processing device uses messaging queues or event queues, said messaging queues or event queues including one or more specific events, and said method further comprises intercepting requests by said persistent control mechanism.

6. The method of claim 5 , further comprising registering at least one specific event, mediating said at least one specific event, and forwarding said at least one specific event for additional processing.

7. The method of claim 1 , further comprising providing access to a network for said persistent control mechanism.

8. The method of claim 1 , further comprising determining that an application instance is associated with a restricted domain, causing said operating system establish a secured process in its own name space for mounted file systems, and mounting a secured file system that encrypts all information stored thereon.

9. A computer data processing device having an operating system in two or more data security domains, comprising:

data memory associated with said computer data processing device including at least one external policy defining at least one computer data processing device application and data domain;

computer processor instructions effective to associate said computer data processing device application and data with said at least one domain;

computer processor instructions effective for providing at least one persistent control mechanism over said computer data processing device application and data associated with said at least one application, said persistent control mechanism being subject to policies defined for said at least one domain, said policies being application-specific, user-specific, or data-specific, and said persistent control mechanism being separate from said operating system and said persistent control mechanism being configured to intercept requests from said computer data processing device application to said operating system; and

computer processor instructions effective for providing at least one mechanism for fine-grained policy-based control over operations by and between, said computer data processing device application and data.

10. The computer data processing device of claim 9 , further comprising computer processor instructions effective for replacing or modifying a reference to a system call using said persistent control mechanism to redirect said system call to at least one replacement function.

11. The computer data processing device of claim 10 , further comprising computer processor instructions effective for providing said persistent control mechanism in the form of a secured service manager service that replaces the operating system service manager service.

12. The computer data processing device of claim 11 , further comprising computer processor instructions effective for providing at least one secured service using said secured service manager service.

13. The computer data processing device of claim 12 , wherein said data processing device uses messaging queues or event queues, said messaging queues or event queues including one or more specific events, and computer data processing device further comprises computer processor instructions effective for intercepting requests by said persistent control mechanism.

14. The computer data processing device of claim 13 , further comprising computer processor instructions effective for registering at least one specific event, mediating said at least one specific event, and forwarding said at least one specific event for additional processing.

15. The computer data processing device of claim 9 , further comprising computer processor instructions effective for providing access to a network for said persistent control mechanism.

16. The computer data processing device of claim 9 , further comprising computer processor instructions effective for determining that an application instance is associated with a restricted domain, causing said operating system to establish a secured process in its own name space for mounted file systems, and mounting a secured file system that encrypts all information stored thereon.

17. A non-transitory computer-readable medium containing a computer program product for operating a computer data processing device, said computer program product being configured to enable said computer data processing device to operate securely in two or more data security domains, and said computer program product being configured to enable said computer data processing device to perform actions comprising:

receiving in data memory associated with said computer data processing device at least one external policy defining at least one computer data processing device application and data domain;

associating said computer data processing device application and data with said at least one domain;

providing at least one persistent control mechanism over said computer data processing device application and data associated with said at least one application, said persistent control mechanism being subject to policies defined for said at least one domain, said policies being application-specific, user-specific, or data-specific, and said persistent control mechanism being separate from said operating system and said persistent control mechanism being configured to intercept requests from said computer data processing device application to said operating system; and

providing at least one mechanism for fine-grained policy-based control over operations by and between, said computer data processing device application and data.

18. The non-transitory computer readable medium of claim 17 , being further configured to enable said computer data processing device to perform actions comprising replacing or modifying a reference to a system call using said persistent control mechanism to redirect said system call to at least one replacement function.

19. The non-transitory computer readable medium of claim 18 , being further configured to enable said computer data processing device to perform actions comprising providing said persistent control mechanism in the form of a secured service manager service that replaces the operating system service manager service.

20. The non-transitory computer readable medium of claim 19 , being further configured to enable said computer data processing device to perform actions comprising providing at least one secured service using said secured service manager service.

21. The non-transitory computer readable medium of claim 20 , wherein said data processing device uses messaging queues or event queues, said messaging queues or event queues including one or more specific events, and said non-transitory computer readable medium further comprises computer program instructions configured to enable said computer data processing device to intercept requests by said persistent control mechanism.

22. The non-transitory computer readable medium of claim 21 , being further configured to enable said computer data processing device to perform actions comprising registering at least one specific event, mediating said at least one specific event, and forwarding said at least one specific event for additional processing.

23. The non-transitory computer readable medium of claim 17 , being further configured to enable said computer data processing device to perform actions comprising providing access to a network for said persistent control mechanism.

24. The non-transitory computer readable medium of claim 17 , being further configured to enable said computer data processing device to perform actions comprising determining that an application instance is associated with a restricted domain, causing said operating system establish a secured process in its own name space for mounted file systems, and mounting a secured file system that encrypts all information stored thereon.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: CELLSEC, INC.
To: PULSE SECURE, LLC.
Reel/Frame 060903/0497 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Mar 17, 2017
From: CELLSEC, INC.
To: GOLDSCHLAG, DAVID; WEISS, YOAV; ACCEL XI L.P.; ACCEL STRATEGIC PARTNERS; ACCEL INVESTORS 2012 L.L.C.; SVIC NO. 22 NEW TECHNOLOGY BUSINESS INVESTMENT L.L.P.; THE MOSS YAMANOUCHI FAMILY TRUST; TRANSPLAN ENTERPRISES; GLASER INVESTMENTS; MARKER LANTERN III LTD.
Reel/Frame 041619/0122 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2017
From: WEISS, YOAV; GOLDSCHLAG, DAVID; GINTER, KARL; BARTMAN, MICHAEL
To: CELLSEC, INC.
Reel/Frame 040958/0836 →