IP Library Granted Patent US 10,044,685
Granted Patent B2
US 10,044,685 · App. 15/065,910 · Granted Aug 7, 2018

Securing enterprise data on mobile devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,685
App. No.
15/065,910
Granted
Aug 7, 2018
Kind
B2
Abstract

Embodiments include method, systems and computer program products for securing enterprise data in a mobile computing environment. Aspects include receiving, by an application disposed on a mobile computing device, a request to access the enterprise data stored on the mobile computing device in an encrypted format and determining whether the mobile computing device is in communication with an enterprise network. Based on determining that the mobile computing device is in communication with the enterprise network, aspects include transmitting a decryption request to an encryption application disposed on the enterprise network, receiving the enterprise data in an unencrypted format from the enterprise network and granting access to the enterprise data in an unencrypted format to the application. Based on a determination that the mobile computing device is not communication with the enterprise network, aspects also include denying the request to access the enterprise data.

Claims (18)

1. A computer-implemented method for securing enterprise data in a mobile computing environment, the method comprising:

receiving, by an application disposed on a mobile computing device, a request to access the enterprise data stored on the mobile computing device in an encrypted format;

determining whether the mobile computing device is in communication with an enterprise network, wherein the determination that the mobile computing device is in communication with the enterprise network requires that the mobile computing device to be in communication with the enterprise network via a secure enterprise W-Fi network;

based on determining that the mobile computing device is in communication with the enterprise network:

transmitting a decryption request to an encryption application disposed on the enterprise network, wherein transmitting the decryption request to the encryption application disposed on the enterprise network includes transmitting the enterprise data in the encrypted format;

receiving the enterprise data in an unencrypted format from the enterprise network; and

granting access to the enterprise data in an unencrypted format to the application disposed on the mobile computing device;

based on a determination that the mobile computing device is not communication with the enterprise network, denying the request to access the enterprise data.

2. The computer-implemented method of claim 1 , wherein an encryption key utilized by the encryption application is only stored on the enterprise network.

3. The computer-implemented method of claim 1 , wherein the determination that the mobile computing device is in communication with the enterprise network comprises determining a type of a communications network the mobile computing device is connected to.

4. The computer-implemented method of claim 3 , wherein the type of the communications network includes a public communications network and a private communications network.

5. The computer-implemented method of claim 1 , further comprising:

updating the enterprise data in a decrypted format by the application to create an updated enterprise data;

receiving, by the application disposed on the mobile computing device, a request to store the updated enterprise data in the encrypted format;

based on determining that the mobile computing device is in communication with the enterprise network:

transmitting an encryption request to the encryption application disposed on the enterprise network;

receiving the updated enterprise data in the encrypted format from the enterprise network; and

storing the updated enterprise data in the encrypted format on the mobile computing device.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 055078/0982 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 2ND INVENTOR NAME AND EXECUTION DATE OF HIS SIGNATURE. PREVIOUSLY RECORDED AT REEL: 037948 FRAME: 0610. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Oct 29, 2018
From: ABDIRASHID, MOHAMMAD; DE GILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 048134/0099 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2016
From: ABDIRASHID, MOHAMMAD; DEGILIO, FRANK J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037948/0610 →