IP Library Granted Patent US 10,028,135
Granted Patent B2
US 10,028,135 · App. 15/065,909 · Granted Jul 17, 2018

Securing enterprise data on mobile devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,028,135
App. No.
15/065,909
Granted
Jul 17, 2018
Kind
B2
Abstract

Embodiments include method, systems and computer program products for securing enterprise data in a mobile computing environment. Aspects include receiving a request to access the enterprise data stored on the mobile computing device in an encrypted format and determining whether a decryption key is stored in a cache memory of the mobile computing device. Based on determining that the decryption key is not stored in a cache memory of the mobile computing device, aspects include transmitting a request to an enterprise network for the decryption key and receiving the decryption key and storing the decryption key in the cache memory. Aspects also include decrypting the enterprise data using the decryption key and deleting the decryption key from the cache memory based on a determination that the decryption key has not been accessed for a period of time greater than a threshold time.

Claims (23)

1. A computer-implemented method for securing enterprise data in a mobile computing environment, the method comprising:

receiving, by a processor, a request to access an enterprise data stored on a mobile computing device in an encrypted format;

determining whether a decryption key is stored in a cache memory of the mobile computing device;

based on determining that the decryption key is not stored in a cache memory of the mobile computing device:

transmitting a request to an enterprise network for the decryption key; and

receiving the decryption key and storing the decryption key in the cache memory;

decrypting the enterprise data using the decryption key;

deleting the decryption key from the cache memory based on a determination that the decryption key has not been accessed for a period of time greater than a threshold time; and

deleting the decryption key from the cache memory based on a determination that the mobile computing device has lost communication with the enterprise network.

2. The computer-implemented method of claim 1 , wherein the mobile computing device is configured to only store the decryption key in the cache memory.

3. The computer-implemented method of claim 1 , further comprising denying the request to access the enterprise data based on a determination that the decryption key was not received from the enterprise network and that the decryption key is not stored in the cache memory.

4. The computer-implemented method of claim 1 , further comprising providing access to the enterprise data in a decrypted format to an application on the mobile computing device.

5. The computer-implemented method of claim 4 , further comprising:

updating the enterprise data in the decrypted format by the application to create updated enterprise data;

receiving a request to store the updated enterprise data in an encrypted format;

determining whether an encryption key is stored in a cache memory of the mobile computing device;

based on determining that the encryption key is not stored in a cache memory of the mobile computing device:

transmitting a request to the enterprise network for the encryption key; and

receiving the encryption key and storing the encryption key in the cache memory;

encrypting the enterprise data using the encryption key; and

deleting the encryption key from the cache memory based on a determination that the encryption key has not been accessed for the period of time greater than a threshold time.

6. The computer-implemented method of claim 5 , wherein the mobile computing device is configured to only store the encryption key in the cache memory.

7. The computer-implemented method of claim 5 , further comprising denying the request to store the updated enterprise data in the encrypted format based on a determination that the encryption key was not received from the enterprise network and that the encryption key is not stored in the cache memory.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 055078/0982 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SPELLING OF INVENTOR FRANK J. DE GILIO NAME AND THE EXECUTION DATE OF HIS SIGNATURE PREVIOUSLY RECORDED ON REEL 037947 FRAME 0966. ASSIGNOR(S) HEREBY CONFIRMS THE SPELLING OF FRANK J. DE GILIO WITH AN EXECUTION DATE OF 10-24-18. Recorded Oct 29, 2018
From: DE GILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047347/0147 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY PREVIOUSLY RECORDED AT REEL: 037947 FRAME: 0966. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 29, 2018
From: ABDIRASHID, MOHAMMAD; DE GILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 048005/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2016
From: ABDIRASHID, MOHAMMAD; DEGILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037947/0966 →