IP Library Granted Patent US 10,038,551
Granted Patent B2
US 10,038,551 · App. 14/953,351 · Granted Jul 31, 2018

Securing enterprise data on mobile devices

Inventors: Mohammad Abdirashid (Highland, NY); Frank J. Degilio (Poughkeepsie, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L9/0816H04L67/2842H04L63/0272H04L63/0428H04W12/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,038,551
App. No.
14/953,351
Granted
Jul 31, 2018
Kind
B2
Abstract

Embodiments include method, systems and computer program products for securing enterprise data in a mobile computing environment. Aspects include receiving a request to access the enterprise data stored on the mobile computing device in an encrypted format and determining whether a decryption key is stored in a cache memory of the mobile computing device. Based on determining that the decryption key is not stored in a cache memory of the mobile computing device, aspects include transmitting a request to an enterprise network for the decryption key and receiving the decryption key and storing the decryption key in the cache memory. Aspects also include decrypting the enterprise data using the decryption key and deleting the decryption key from the cache memory based on a determination that the decryption key has not been accessed for a period of time greater than a threshold time.

Claims (47)

1. A computer program product for securing enterprise data in a mobile computing environment, the computer program product comprising:

a non-transitory storage medium readable by a processing circuit and storing instructions for execution by the processing circuit for performing a method comprising:

receiving a request to access an enterprise data stored on a mobile computing device in an encrypted format;

determining whether a decryption key is stored in a cache memory of the mobile computing device;

based on determining that the decryption key is not stored in a cache memory of the mobile computing device:

transmitting a request to an enterprise network for the decryption key; and

receiving the decryption key and storing the decryption key in the cache memory;

decrypting the enterprise data using the decryption key;

deleting the decryption key from the cache memory based on a determination that the decryption key has not been accessed for a period of time greater than a threshold time; and

deleting the decryption key from the cache memory based on a determination that the mobile computing device has lost communication with the enterprise network.

2. The computer program product of claim 1 , wherein the mobile computing device is configured to only store the decryption key in the cache memory.

3. The computer program product of claim 1 , the method further comprising denying the request to access the enterprise data based on a determination that the decryption key was not received from the enterprise network and that the decryption key is not stored in the cache memory.

4. The computer program product of claim 1 , the method further comprising providing access to the enterprise data in a decrypted format to an application on the mobile computing device.

5. The computer program product of claim 4 , the method further comprising:

updating the enterprise data in the decrypted format by the application to create updated enterprise data;

receiving a request to store the updated enterprise data in an encrypted format;

determining whether an encryption key is stored in a cache memory of the mobile computing device;

based on determining that the encryption key is not stored in a cache memory of the mobile computing device:

transmitting a request to the enterprise network for the encryption key; and

receiving the encryption key and storing the encryption key in the cache memory;

encrypting the enterprise data using the encryption key; and

deleting the encryption key from the cache memory based on a determination that the encryption key has not been accessed for the period of time greater than a threshold time.

6. The computer program product of claim 5 , wherein the mobile computing device is configured to only store the encryption key in the cache memory.

7. The computer program product of claim 5 , the method further comprising denying the request to store the updated enterprise data in the encrypted format based on a determination that the encryption key was not received from the enterprise network and that the encryption key is not stored in the cache memory.

8. A mobile computing device for securely accessing enterprise data, comprising:

a processor in communication with one or more types of memory, the processor configured to:

receive a request to access an enterprise data stored on the mobile computing device in an encrypted format;

determine whether a decryption key is stored in a cache memory of the mobile computing device;

based on determining that the decryption key is not stored in a cache memory of the mobile computing device:

transmit a request to an enterprise network for the decryption key; and

receive the decryption key and store the decryption key in the cache memory;

decrypt the enterprise data using the decryption key;

delete the decryption key from the cache memory based on a determination that the decryption key has not been accessed for a period of time greater than a threshold time; and

delete the decryption key from the cache memory based on a determination that the mobile computing device has lost communication with the enterprise network.

9. The mobile computing device of claim 8 , wherein the processor is further configured to deny the request to access the enterprise data based on a determination that the decryption key was not received from the enterprise network and that the decryption key is not stored in the cache memory.

10. The mobile computing device of claim 8 wherein the processor is further configured to provide access to the enterprise data in a decrypted format to an application on the mobile computing device.

11. The mobile computing device of claim 10 , wherein the processor is further configured to:

update the enterprise data in the decrypted format by the application to create updated enterprise data;

receive a request to store the updated enterprise data in an encrypted format;

determine whether an encryption key is stored in a cache memory of the mobile computing device;

based on determining that the encryption key is not stored in a cache memory of the mobile computing device:

transmit a request to the enterprise network for the encryption key; and

receive the encryption key and store the encryption key in the cache memory;

encrypt the enterprise data using the encryption key; and

delete the encryption key from the cache memory based on a determination that the encryption key has not been accessed for the period of time greater than a threshold time.

12. The mobile computing device of claim 11 , wherein the mobile computing device is configured to only store the encryption key and the decryption key in the cache memory.

13. The mobile computing device of claim 11 , wherein the processor is further configured to deny the request to store the updated enterprise data in the encrypted format based on a determination that the encryption key was not received from the enterprise network and that the encryption key is not stored in the cache memory.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 055078/0982 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF INVENTORFRANK J. DE GILIO NAME AND THE EXECUTION DATE OF HISSIGNATURE PREVIOUSLY RECORDED ON REEL 037161 FRAME 0619. ASSIGNOR(S) HEREBY CONFIRMS THE SPELLING OF FRANK J. DE GILIO WITH AN EXECUTION DATE OF 10-24-18. Recorded Oct 29, 2018
From: DE GILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047900/0968 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING NAME AND EXECUTION DATE PREVIOUSLY RECORDED AT REEL: 037161 FRAME: 0619. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 29, 2018
From: ABDIRASHID, MOHAMMAD; DE GILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047996/0694 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2015
From: ABDIRASHID, MOHAMMAD; DEGILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037161/0619 →
Continuity (1)
Related Publication 20170155505A1 · Jun 1, 2017