IP Library Granted Patent US 10,171,502
Granted Patent B2
US 10,171,502 · App. 14/718,727 · Granted Jan 1, 2019

Managed applications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,171,502
App. No.
14/718,727
Granted
Jan 1, 2019
Kind
B2
Abstract

Embodiments relate to a system that includes a computing device and a managed application executable by the computing device. The managed application initiates an execution of a target application. The managed application obtains a request from the target application to perform an action. The managed application determines whether the action is permitted by a compliance rule.

Claims (50)

1. A method, comprising:

receiving, by a computing device, a managed application package generated by an enterprise computing environment, the managed application package comprising a managed application, a target application, and target application resources for the target application;

executing, by the computing device, the managed application according to the managed application package, the managed application comprising a target application loader;

initiating, by the target application loader of the managed application, an execution of the target application in the computing device according to the managed application package;

intercepting, by the target application loader, a request from the target application for access to the target application resources and returning a path to a storage location on the computing device for the target application resources in response to the request; and

determining, by the managed application, whether the execution of the target application complies with a compliance rule specified remotely by the enterprise computing environment.

2. The method of claim 1 , further comprising:

intercepting, by the managed application, a request from the target application for process information; and

returning, by the managed application, a target application object to the target application responsive to the request from the target application.

3. The method of claim 1 , wherein:

executing the managed application comprises loading the target application loader of the managed application and a compliance rule enforcer of the managed application; and

the compliance rule enforcer determines whether the execution of the target application complies with the compliance rule.

4. The method of claim 1 , wherein initiating the execution of the target application in the computing device comprises:

requesting, by the target application loader of the managed application, to load a plurality of executables of the target application into memory of the computing device.

5. The method of claim 1 , wherein determining whether the execution of the target application complies with the compliance rule comprises:

obtaining, by the managed application, a request from the target application to perform an action; and

determining whether the action is permitted by the compliance rule.

6. The method of claim 5 , further comprising discarding, by the managed application, the request upon determining that the action is not permitted by the compliance rule.

7. The method of claim 5 , further comprising, forwarding, by the managed application, the request to an operating system of the computing device upon determining that the action is permitted by the compliance rule.

8. A non-transitory computer-readable medium storing a plurality of computer instructions executable by a computing device, the plurality of computer instructions being configured to cause the computing device to at least:

receive a managed application package generated by an enterprise computing environment, the managed application package comprising a managed application, a target application, and target application resources for the target application;

execute the managed application according to the managed application package, the managed application comprising a target application loader;

initiate, by the target application loader of the managed application, an execution of the target application in the computing device according to the managed application package;

intercept, by the target application loader, a request from the target application for access to the target application resources and return a path to a storage location on the computing device for the target application resources in response to the request;

identify, by the managed application, a request for an action to be performed by the target application; and

determine, by the managed application, whether the action requested to be performed by the target application is permitted by a compliance rule specified remotely by the enterprise computing environment.

9. The non-transitory computer-readable medium of claim 8 , wherein the plurality of computer instructions are further configured to cause the computing device to at least discard the request upon determining that the action is not permitted by the compliance rule.

10. The non-transitory computer-readable medium of claim 8 , wherein the plurality of computer instructions are further configured to cause the computing device to at least return an object to the target application upon determining that the action is not permitted by the compliance rule, wherein the object indicates a failure of the action.

11. The non-transitory computer-readable medium of claim 10 , wherein the plurality of computer instructions are further configured to cause the computing device to at least forward the request upon determining that the action is permitted by the compliance rule.

12. The non-transitory computer-readable medium of claim 8 , wherein the plurality of computer instructions are further configured to cause the computing device to at least:

intercept a request from the target application for process information; and

return a target application object to the target application responsive to the request from the target application.

13. The non-transitory computer-readable medium of claim 8 , wherein the plurality of computer instructions are further configured to cause the computing device to at least:

request, by the target application loader of the managed application, to load a plurality of executables of the target application into memory of the computing device intercept a request by the target application for a private target application resource; and

return a path to a storage location of a package for the target application.

14. A system, comprising:

a memory device to store a managed application package generated by an enterprise computing environment, the managed application package comprising a managed application, a target application, and target application resources for the target application; and

a computing device configured, through execution of the managed application, to at least:

initiate, by a target application loader of the managed application, an execution of the target application in the computing device according to the managed application package;

intercept, by the target application loader, a request from the target application for access to the target application resources and return a path to a storage location on the computing device for the target application resources in response to the request;

obtain a request from the target application to perform an action; and

determine whether the action is permitted by a compliance rule specified remotely by the enterprise computing environment.

15. The system of claim 14 , wherein the managed application is further configured to cause the computing device to at least discard the request upon determining that the action is not permitted by the compliance rule.

16. The system of claim 14 , wherein the managed application is further configured to cause the computing device to discard the request by at least returning a failure object to the target application.

17. The system of claim 14 , wherein the managed application is further configured to cause the computing device to at least forward the request upon determining that the action is permitted by the compliance rule.

18. The system of claim 14 , wherein the managed application is further configured to cause the computing device to at least:

intercept a request from the target application for process information; and

return an object for the target application responsive to the request from the target application.

19. The system of claim 14 , wherein the managed application further comprises a compliance rule enforcer to determine whether the action is permitted by the compliance rule.

20. The system of claim 19 , wherein the managed application package further includes loader resources for the target application loader and enforcer resources for the compliance rule enforcer.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2015
From: XUAN, CHAOTING; STUNTEBECK, ERICH
To: AIRWATCH LLC
Reel/Frame 035692/0601 →