IP Library Granted Patent US 9,665,731
Granted Patent B2
US 9,665,731 · App. 15/136,608 · Granted May 30, 2017

Preventing content data leak on mobile devices

Inventors: Suresh Kumar Batchu (Milpitas, CA); Mansu Kim (Cupertino, CA); Joshua Sirota (Los Altos, CA)
Assignee: MOBILE IRON, INC.
G06F21/6209G06F21/602G06F21/606H04L9/0819H04L63/0471H04W12/04H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,665,731
App. No.
15/136,608
Filed
Apr 22, 2016
Granted
May 30, 2017
Kind
B2
Art Unit
2433
USPC
713/150
Abstract

Preventing enterprise or other protected content data from “leaking” from being under secure management on a device, for example by virtue of being viewed using an untrusted app on the device, is disclosed. An indication is received that a content to be provided to a first mobile application on a mobile device is to be protected against unauthorized access at the mobile device using unauthorized applications other than the first mobile application. The content is encrypted while in transit to the mobile device, using a key associated with a second mobile application authorized to be used to access the content at the mobile device.

Claims (33)

1. A method of protecting content data, comprising:

receiving at a node an indication that content to be provided to a first mobile application on a mobile device from a content provider is to be protected against unauthorized access at the mobile device;

determining, by the node, whether the mobile device is authorized to receive the content;

in the event the mobile device is authorized to receive the content, encrypting the content using a key associated with a second mobile application on the mobile device authorized to be used to access the content at the mobile device, wherein the second mobile application is configured to allow a user to view and/or edit the content; and

in the event the mobile device is not authorized to receive the content, performing protective measures to the content in a communication message prior to delivering the communication message to the mobile device.

2. The method of claim 1 , wherein the key is associated with one or more of the following: a user of the mobile device, a mobile application on the mobile device, the content, and the mobile device.

3. The method of claim 1 , further comprising generating the key and providing the key to a security node configured to encrypt the content in transit to the mobile device and to the second mobile application.

4. The method of claim 3 , wherein the key is provided to the second mobile application via a management agent installed on the mobile device.

5. The method of claim 1 , wherein the second mobile application is configured to use the key to decrypt the content at the mobile device.

6. The method of claim 1 , wherein the second mobile application is configured to store the content persistently at the mobile device only in encrypted form.

7. The method of claim 1 , further comprising associating the content with a secure content type.

8. The method of claim 7 , wherein the second mobile application is configured to register itself to be used to access content of the secure content type.

9. The method of claim 7 , wherein the secure content type comprises one or more of a file extension and a MIME type.

10. The method of claim 1 , further comprising configuring the second mobile application to use the key to provide authorized access to the content.

11. The method of claim 1 , wherein the content comprises one or more of an email attachment, a document, a file, and a stored content object.

12. The method of claim 1 , wherein the content comprises an email message and encrypting the content includes selectively encrypting one or more of a message header, a message body, and at least a selected subset of email attachments comprising the email message.

13. The method of claim 1 , wherein the key associated with a second mobile application is encrypted prior to being sent to the mobile device and a Common Access Card or other physical article must be connected to the mobile device to enable the second mobile application to access and use the key to decrypt the content at the mobile device.

14. The method of claim 1 , wherein the protective measures include stripping the content from the communication message.

15. The method of claim 1 , wherein the protective measures include replacing the content in the communication message.

16. The method of claim 1 , wherein in the event the mobile device is not authorized to receive the content the first mobile application provides an indication that access is not permitted.

17. The method of claim 1 , further comprising including in or with the content a tag or other metadata indicating one or more of an action authorized to be performed with respect to the content at the mobile device using the second mobile application and an action not authorized to be performed with respect to the content at the mobile device using the second mobile application.

18. The method of claim 17 , wherein the second mobile application is configured to sue the tag or other metadata to determine at the mobile device, in response to a request to perform a requested action, whether the requested action is permitted to be performed with respect to the content at the mobile device.

19. A system comprising:

a communication interface configured to receive an indication that content to be provided to a first mobile application on a mobile device from a content provider is to be protected against unauthorized access at the mobile device; and

a processor coupled to the communication interface and configured to:

determine whether the mobile device is authorized to receive the content;

in the event the mobile device is authorized to receive the content, encrypt the content using a key associated with a second mobile application on the mobile device authorized to be used to access the content at the mobile device, wherein the second mobile application is configured to allow a user to view and/or edit the content; and

in the event the mobile device is not authorized to receive the content, perform protective measures to the content in a communication message prior to delivering the communication message to the mobile device.

20. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving at a node an indication that content to be provided to a first mobile application on a mobile device from a content provider is to be protected against unauthorized access at the mobile device;

determining, by the node, whether the mobile device is authorized to receive the content;

in the event the mobile device is authorized to receive the content, encrypting the content using a key associated with a second mobile application on the mobile device authorized to be used to access the content at the mobile device, wherein the second mobile application is configured to allow a user to view and/or edit the content; and

in the event the mobile device is not authorized to receive the content, performing protective measures to the content in a communication message prior to delivering the communication message to the mobile device.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
Continuity (3)
Continuation 13946218 · Jul 19, 2013
Provisional Application 61673694 · Jul 19, 2012
Related Publication 20160292440A1 · Oct 6, 2016