IP Library Granted Patent US 10,044,757
Granted Patent B2
US 10,044,757 · App. 14/875,450 · Granted Aug 7, 2018

Secure execution of enterprise applications on mobile devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,757
App. No.
14/875,450
Granted
Aug 7, 2018
Kind
B2
Abstract

A system is disclosed that includes components and features for enabling enterprise users to securely access enterprise resources (documents, data, application servers, etc.) using their mobile devices. An enterprise can use some or all components of the system to, for example, securely but flexibly implement a BYOD (bring your own device) policy in which users can run both personal applications and secure enterprise applications on their mobile devices. The system may, for example, implement policies for controlling mobile device accesses to enterprise resources based on device attributes (e.g., what mobile applications are installed), user attributes (e.g., the user's position or department), behavioral attributes, and other criteria. Client-side code installed on the mobile devices may further enhance security by, for example, creating a secure container for locally storing enterprise data, creating a secure execution environment for running enterprise applications, and/or creating secure application tunnels for communicating with the enterprise system.

Claims (53)

1. A method comprising:

receiving, by a mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files defined independently of the managed application;

receiving, by the mobile device, the set of one or more policy files from the application server during a second communication different from the first communication, the set of one or more policy files being stored on the mobile device separately from the managed application;

receiving, by the mobile device, a custom secure sockets layer (SSL) library that is different from an SSL library of an operating system of the mobile device;

installing, by the mobile device, the custom SSL library on the mobile device;

determining a geographic location of the system;

running the managed application on the mobile device in accordance with policies defined in the set of one or more policy files that is stored on the mobile device separately from the managed application; and

determining, based on the policies defined in the set of one or more policy files that is stored on the mobile device separately from the managed application, that the geographic location of the system is within an unauthorized geographical zone,

wherein the policies defined in the set of one or more policy files, when applied to the managed application while the geographic location of the system is within the unauthorized geographical zone, cause the managed application to restrict a data-sharing feature otherwise made available on the mobile device while the geographic location of the system is not within the unauthorized geographical zone, and

wherein the policies defined in the set of one or more policy files cause the managed application to create a secure application tunnel using the custom SSL library on the mobile device in place of the SSL library of the operating system of the mobile device.

2. The method of claim 1 , wherein the policies defined in the set of one or more policy files, when applied to the managed application, cause the managed application to restrict, within the managed application, an otherwise unrestricted cut-and-paste feature exposed by an operating system of the mobile device.

3. The method of claim 1 , wherein the policies defined in the set of one or more policy files, when applied to the managed application, prevent a uniform resource locator (URL) dispatch from within the managed application.

4. The method of claim 1 , wherein the policies defined in the set of one or more policy files cause the managed application to prevent a user from using a dictation feature within the managed application.

5. The method of claim 1 , wherein the policies defined in the set of one or more policy files cause the managed application to be prevented from calling a remote procedure call.

6. The method of claim 1 , wherein the policies defined in the set of one or more policy files cause the managed application to be prevented from writing data to memory shared with an unmanaged application.

7. The method of claim 1 , comprising:

receiving, by the managed application on the mobile device, a key from an enterprise agent,

wherein the policies defined in the set of one or more policy files, when applied to the managed application, cause the managed application to use the key from the enterprise agent to encrypt data output by the managed application that an unmanaged application corresponding to the managed application stores in a non-encrypted format.

8. The method of claim 1 , comprising:

replacing an encryption library of the managed application with a new encryption library,

wherein the policies defined in the set of one or more policy files cause the managed application to use a different encryption level or encryption type than that used by an unmanaged application corresponding to the managed application, the different encryption level or encryption type using the new encryption library.

9. Non-transitory computer-readable media storing instructions that, when executed by one or more processors, cause a system to:

receive a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files defined independently of the managed application;

receive the set of one or more policy files from the application server during a second communication different from the first communication, the set of one or more policy files being stored on the system separately from the managed application;

receive a custom secure sockets layer (SSL) library that is different from an SSL library of an operating system of the system;

install the custom SSL library on the system;

determine that a password has been removed from the system; and

run the managed application in accordance with policies defined in the set of one or more policy files that is stored on the system separately from the managed application,

wherein the policies defined in the set of one or more policy files, when applied to the managed application, cause deletion of one or more files of the managed application responsive to determining that the password has been removed from the system for longer than a threshold period of time, and

wherein the policies defined in the set of one or more policy files cause the managed application to create a secure application tunnel using the custom SSL library on the system in place of the SSL library of the operating system of the system.

10. The non-transitory computer-readable media of claim 9 , wherein the policies defined in the set of one or more policy files, when applied to the managed application, cause the managed application to restrict, within the managed application, an otherwise unrestricted cut-and-paste feature exposed by an operating system of the system.

11. The non-transitory computer-readable media of claim 9 , wherein the policies defined in the set of one or more policy files, when applied to the managed application, prevent a uniform resource locator (URL) dispatch from within the managed application.

12. The non-transitory computer-readable media of claim 9 , wherein the policies defined in the set of one or more policy files cause the managed application to be prevented from calling a content provider application programming interface (API).

13. The non-transitory computer-readable media of claim 9 , wherein the policies defined in the set of one or more policy files cause the managed application to be prevented from calling a remote procedure call.

14. The non-transitory computer-readable media of claim 9 , wherein the policies defined in the set of one or more policy files cause the managed application to be prevented from writing data to memory shared with an unmanaged application.

15. A system comprising:

at least one processor; and

non-transitory memory storing computer-readable instructions that, when executed by the at least one processor, cause the system to:

receive a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files defined independently of the managed application;

receive the set of one or more policy files from the application server during a second communication different from the first communication, the set of one or more policy files being stored on the system separately from the managed application;

receive a custom secure sockets layer (SSL) library that is different from an SSL library of an operating system of the system;

install the custom SSL library on the system;

determine that a SIM card has been removed from the system; and

run the managed application in accordance with policies defined in the set of one or more policy files that is stored on the system separately from the managed application,

wherein the policies defined in the set of one or more policy files, when applied to the managed application, cause deletion of one or more files of the managed application responsive to the SIM card having been removed from the system for longer than a threshold period of time, and

wherein the policies defined in the set of one or more policy files cause the managed application to create a secure application tunnel using the custom SSL library on the system in place of the SSL library of the operating system of the system.

16. The system of claim 15 , wherein the policies defined in the set of one or more policy files, when applied to the managed application, cause the managed application to restrict, within the managed application, an otherwise unrestricted cut-and-paste feature exposed by an operating system of the system.

17. The system of claim 15 , wherein the policies defined in the set of one or more policy files, when applied to the managed application, prevent a uniform resource locator (URL) dispatch from within the managed application.

18. The system of claim 15 , wherein the policies defined in the set of one or more policy files cause the managed application to prevent a user from using a dictation feature within the managed application.

19. The system of claim 15 , wherein the policies defined in the set of one or more policy files cause the managed application to be prevented from calling a content provider API.

20. The system of claim 15 , wherein the non-transitory memory stores computer-readable instructions that, when executed by the at least one processor, cause the system to:

replace an encryption library of the managed application with a new encryption library,

wherein the policies defined in the set of one or more policy files cause the managed application to use a different encryption level or encryption type than that used by an unmanaged application corresponding to the managed application, the different encryption level or encryption type using the new encryption library.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2016
From: ZENPRISE, INC.
To: CITRIX SYSTEMS, INC.
Reel/Frame 037455/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2016
From: QURESHI, WAHEED; DEBENNING, THOMAS H.; DATOO, AHMED; ANDRE, OLIVIER; ABDULLAH, SHAFAQ
To: ZENPRISE, INC.
Reel/Frame 037455/0371 →
Cited By (6)
US 12,411,990 US 12,475,213 US 12,518,030 US 12,619,421 US 12,682,040 US 12,719,870