IP Library Granted Patent US 10,735,964
Granted Patent B2
US 10,735,964 · App. 15/218,776 · Granted Aug 4, 2020

Associating services to perimeters

Inventors: Christopher Lyle Bender (Kitchener, CA); Graham Russell (Cambridge, CA); Natalie Michelle Silvanovich (Waterloo, CA)
Assignee: BlackBerry Limited
H04W12/08H04L63/0209H04L63/102H04L67/12H04W12/0806H04W76/14H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,735,964
App. No.
15/218,776
Granted
Aug 4, 2020
Kind
B2
Abstract

In some implementations, a method includes receiving, from a user of a first device, a request to enable access, through a second device, to a server resource account of an enterprise. The first device includes a first enterprise perimeter including an internal resource and a first enterprise identifier and configured to prevent external resources from accessing the internal resource. A request is wirelessly transmit, to the second device, to the second device for a second enterprise identifier assigned to a second enterprise perimeter included in the second device. Whether to grant access to the internal resource is determined based on a first enterprise identifier assigned to the first device and a second enterprise identifier assigned to the second device.

Claims (56)

1. A method, comprising:

receiving, by a first device, from an internal application executing on the first device, a request to enable the first device to access a server resource account of an enterprise through a direct wireless connection with a second device and cellular network access between the second device and a cellular network, wherein the first device includes a first set of resources and resources external to the first set of resources, the first set of resources associated with the internal application for accessing the server resource account and a first enterprise identifier;

wirelessly transmitting, to the second device, a request to the second device for a second enterprise identifier assigned to a second set of resources included in the second device and associated with the cellular network access between the second device and the cellular network;

receiving, at the first device and from the second device, the second enterprise identifier; and

determining, at the first device, whether to grant access to the internal application for accessing the server resource account through the direct wireless connection with the second device and the cellular network access of the second set of resources based on the first enterprise identifier assigned to the first device and the second enterprise identifier assigned to the second device, wherein determining whether to grant access comprises:

comparing the first enterprise identifier to the second enterprise identifier; and

based on the first enterprise identifier not matching the second enterprise identifier, generating a separate set of resources including resources for an unknown user to access an enterprise service.

2. The method of claim 1 , further comprising:

transmitting a request to access the server resource account of the enterprise;

receiving information granting access to the server resource account and the first enterprise identifier; and

generating the first set of resources including resources for accessing the server resource account and the first enterprise identifier.

3. The method of claim 1 , wherein the first enterprise identifier comprises a first email address, and the second enterprise identifier comprises a second email address.

4. The method of claim 1 , further comprising:

identifying a first user identifier associated with the first device;

transmitting, to the second device, a request to the second device for a second user identifier associated with the second device; and

wherein determining whether to grant access to the internal application is based on the first enterprise identifier, the first user identifier, the second enterprise identifier, and the second user identifier.

5. The method of claim 1 , wherein the first set of resources is configured to prevent resources external to the first set of resources from accessing resources associated with the first set of resources.

6. The method of claim 1 , wherein the direct wireless connection comprises a wireless local area network (WLAN) connection and the second device is connected with the cellular network via a cellular radio access technology.

7. The method of claim 1 , wherein the enterprise service comprises at least one of a data file or an application.

8. A first device, comprising:

a memory; and

one or more hardware processors communicatively coupled with the memory and configured to:

receive, by the first device, from an internal application executing on the first device, a request to enable the first device to access a server resource account of an enterprise through a direct wireless connection with a second device and cellular network access between the second device and a cellular network, wherein the first device includes a first set of resources and resources external to the first set of resources, the first set of resources associated with the internal application for accessing the server resource account and a first enterprise identifier;

wirelessly transmit, to the second device, a request to the second device for a second enterprise identifier assigned to a second set of resources included in the second device and associated with the cellular network access between the second device and the cellular network;

receive, at the first device and from the second device, the second enterprise identifier; and

determine, at the first device, whether to grant access to the internal application for accessing the server resource account through the direct wireless connection with the second device and the cellular network access of the second set of resources based on the first enterprise identifier assigned to the first device and the second enterprise identifier assigned to the second device, wherein the one or more hardware processors are configured to determine whether to grant access comprises the one or more hardware processors configured to:

compare the first enterprise identifier to the second enterprise identifier; and

based on the first enterprise identifier not matching the second enterprise identifier, generate a separate set of resources including resources for an unknown user to access an enterprise service.

9. The first device of claim 8 , the one or more hardware processors being further configured to:

transmit a request to access the server resource account of the enterprise;

receive information granting access to the server resource account and the first enterprise identifier; and

generate the first set of resources including resources for accessing the server resource account and the first enterprise identifier.

10. The first device of claim 8 , wherein the first enterprise identifier comprises a first email address, and the second enterprise identifier comprises a second email address.

11. The first device of claim 8 , the one or more hardware processors being further configured to:

identify a first user identifier associated with the first device;

transmit, to the second device, a request to the second device for a second user identifier associated with the second device; and

wherein determining whether to grant access to the internal application is based on the first enterprise identifier, the first user identifier, the second enterprise identifier, and the second user identifier.

12. The first device of claim 8 , wherein the first set of resources is configured to prevent resources external to the first set of resources from accessing resources associated with the first set of resources.

13. The first device of claim 8 , wherein the direct wireless connection comprises a wireless local area network (WLAN) connection and the second device is connected with the cellular network via a cellular radio access technology.

14. The first device of claim 8 , wherein the enterprise service comprises at least one of a data file or an application.

15. A computer program product encoded on a non-transitory storage medium, the product comprising computer readable instructions for causing one or more processors to perform operations comprising:

receiving, by a first device, from an internal application executing on the first device, a request to enable the first device to access a server resource account of an enterprise through a direct wireless connection with a second device and cellular network access between the second device and a cellular network, wherein the first device includes a first set of resources and resources external to the first set of resources, the first set of resources associated with the internal application for accessing the server resource account and a first enterprise identifier;

wirelessly transmitting, to the second device, a request to the second device for a second enterprise identifier assigned to a second set of resources included in the second device and associated with the cellular network access between the second device and the cellular network;

receiving, at the first device and from the second device, the second enterprise identifier; and

determining, at the first device, whether to grant access to the internal application for accessing the server resource account through the direct wireless connection with the second device and the cellular network access of the second set of resources based on the first enterprise identifier assigned to the first device and the second enterprise identifier assigned to the second device, wherein the determining whether to grant access comprises:

comparing the first enterprise identifier to the second enterprise identifier; and

based on the first enterprise identifier not matching the second enterprise identifier, generating a separate set of resources including resources for an unknown user to access an enterprise service.

16. The computer program product of claim 15 , the operations further comprising:

instructions for causing one or more processors to further perform operations comprising:

transmitting a request to access the server resource account of the enterprise;

receiving information granting access to the server resource account and the first enterprise identifier; and

generating the first set of resources including resources for accessing the server resource account and the first enterprise identifier.

17. The computer program product of claim 15 , the operations further comprising:

identifying a first user identifier associated with the first device;

transmitting, to the second device, a request to the second device for a second user identifier associated with the second device; and

wherein determining whether to grant access to the internal application is based on the first enterprise identifier, the first user identifier, the second enterprise identifier, and the second user identifier.

Assignments (6)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded May 9, 2017
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 042429/0085 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTIES PREVIOUSLY RECORDED AT REEL: 041518 FRAME: 0802. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 14, 2017
From: BENDER, CHRISTOPHER LYLE; RUSSELL, GRAHAM; SILVANOVICH, NATALIE
To: RESEARCH IN MOTION LIMITED
Reel/Frame 042006/0755 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2017
From: BENDER, CHRISTOPHER LYLE; RUSSELL, GRAHAM; SILVANOVICH, NATALIE
To: RESEARCH IN MOTION LIMITED
Reel/Frame 041518/0160 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2017
From: ADAMS, NEIL P.; LITTLE, HERBERT A.; KIRKUP, MICHAEL G.
To: RESEARCH IN MOTION LIMITED
Reel/Frame 041518/0802 →
Continuity (3)
Continuation 14880319 · Oct 12, 2015
Continuation 13275097 · Oct 17, 2011
Related Publication 20160337862A1 · Nov 17, 2016