IP Library Granted Patent US 10,284,602
Granted Patent B2
US 10,284,602 · App. 15/714,722 · Granted May 7, 2019

Integrating policies from a plurality of disparate management agents

Inventors: Juan V. Esteve Balducci (Sammamish, WA); Michael K. Higashi (Issaquah, WA); David Paul Limont (Seattle, WA); John Allen Atwood (Duvall, WA); Burhan Ateeq (Seattle, WA); Patrick Tousignant (Bellevue, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,284,602
App. No.
15/714,722
Granted
May 7, 2019
Kind
B2
Abstract

Described herein are embodiments for managing policies of a mobile device. In embodiments, a mobile device receives policy containers from a plurality of disparate management agents. Each policy container has one or more policies. Each policy corresponds to a particular category that governs various aspects of the device. The policies described herein may be device wide policies corresponding to various features on the device. The policies may also be data specific policies which dictate how data is stored on and transferred to and from the device. Once the policies are received, a determination is made as to which policy in each category is the most secure policy. The most secure policy for each category is merged to create a global policy that is applied to the mobile device.

Claims (79)

1. A system, comprising:

at least one processor; and

a memory storing instructions, which, when executed by the at least one processor, perform a method for managing policy settings of a mobile device, comprising:

receiving a first policy container from a first management agent, wherein the first policy container comprises a first policy corresponding to a policy category;

receiving a second policy container from a second management agent, wherein the second policy container comprises a second policy, wherein the second policy corresponds to the policy category;

merging the first policy container and the second policy container to generate a global management policy comprising a most secure policy for the policy category determined based on a comparison of the first policy and the second policy;

storing policy data, wherein the policy data comprises an indication of an association between an issuing management agent and the most secure policy, wherein the issuing management agent is one of the first management agent and the second management agent;

receiving an indication of a modified relationship with at least one of the first management agent and the second management agent;

generating an updated global management policy based on the stored association between the issuing management and the most secure policy; and

applying the same updated global management policy to the mobile device when the mobile device connects to the first management agent and when the mobile device connects to the second management agent.

2. The system of claim 1 , wherein the comparison of the first policy and the second policy comprises:

generating security ratings for the first policy and the second policy; and

comparing the security ratings for the first policy and the second policy.

3. The system of claim 1 , wherein the modified relationship is one or more selected from a group consisting of:

severing a relationship;

initiating a new relationship;

renewing a relationship; and

updating of a management agent.

4. The system of claim 1 , wherein generating the updated global management policy comprises:

determining that a relationship between the issuing management agent and the mobile device is severed;

performing an evaluation of the stored association between the issuing management agent and the most secure policy;

determining a new most secure policy based on the evaluation; and

generating the updated global management policy comprising the new most secure policy.

5. The system of claim 1 , wherein the indication of the modified relationship indicates a new relationship with a third management agent.

6. The system of claim 5 , wherein generating the updated global management policy comprises:

receiving a third policy container from the third management agent, wherein the third policy container comprises a third policy corresponding to the policy category;

determining the third policy is more secure than the most secure policy;

generating the updated global management policy comprising the third policy as a new most secure policy; and

updating stored policy data to comprise an association between the third management agent and the new most secure policy.

7. The system of claim 6 , wherein updated stored policy data further comprises removing the association between the issuing management agent and the most secure policy.

8. A method for managing policy settings of a mobile device, comprising:

receiving a first policy container from a first management agent, wherein the first policy container comprises a first policy corresponding to a policy category;

receiving a second policy container from a second management agent, wherein the second policy container comprises a second policy, wherein the second policy corresponds to the policy category;

merging the first policy container and the second policy container to generate a global management policy comprising a most secure policy for the policy category determined based on a comparison of the first policy and the second policy;

applying the global management policy to the mobile device, wherein the global management policy is applied to the mobile device when the mobile device is connected to the first management agent and the global management policy is applied to the mobile device when the mobile device is connected to the second management agent;

generating a global policy display comprising one or more policies applied to the mobile device and an associated management agent for each of the one or more policies, wherein the global policy display indicates the most secure policy is associated with the issuing management agent; and

presenting the generated global policy display on the mobile device.

9. The method of claim 8 , further comprising:

storing policy data, wherein the policy data comprises an indication of an association between an issuing management agent and the most secure policy, wherein the issuing management agent is one of the first management agent and the second management agent.

10. The method of claim 9 , wherein the global policy display is generated based at least in part on the stored policy data.

11. The method of claim 8 , wherein the comparison of the first policy and the second policy comprises:

generating security ratings for the first policy and the second policy; and

comparing the security ratings for the first policy and the second policy.

12. The method of claim 8 , further comprising:

receiving an indication of a modified relationship with at least one of the first management agent and the second management agent; and

updating the generated global policy display as a result of the received indication.

13. The method of claim 8 , further comprising:

receiving a third policy container from a third management agent, wherein the third policy container comprises a third policy corresponding to the policy category;

determining the third policy is more secure than the most secure policy;

generating the updated global management policy comprising the third policy as a new most secure policy; and

updating the global policy display to indicate the new most secure policy, wherein the updated global policy display comprises an indication that the new most secure policy is associated with the third management agent.

14. A method for managing policy settings of a mobile device, comprising:

receiving a first policy container from a first management agent, wherein the first policy container comprises a first policy corresponding to a policy category;

receiving a second policy container from a second management agent, wherein the second policy container comprises a second policy, wherein the second policy corresponds to the policy category;

merging the first policy container and the second policy container to generate a global management policy comprising a most secure policy for the policy category determined based on a comparison of the first policy and the second policy;

storing policy data, wherein the policy data comprises an indication of an association between an issuing management agent and the most secure policy, wherein the issuing management agent is one of the first management agent and the second management agent;

receiving an indication of a modified relationship with at least one of the first management agent and the second management agent;

generating an updated global management policy based on the stored association between the issuing management and the most secure policy; and

applying the same updated global management policy to the mobile device when the mobile device connects to the first management agent and when the mobile device connects to the second management agent.

15. The system of claim 14 , wherein the comparison of the first policy and the second policy comprises:

generating security ratings for the first policy and the second policy; and

comparing the security ratings for the first policy and the second policy.

16. The system of claim 14 , wherein the modified relationship is one or more selected from a group consisting of:

severing a relationship;

initiating a new relationship;

renewing a relationship; and

updating of a management agent.

17. The system of claim 14 , wherein generating the updated global management policy comprises:

determining that a relationship between the issuing management agent and the mobile device is severed;

performing an evaluation of the stored association between the issuing management agent and the most secure policy;

determining a new most secure policy based on the evaluation; and

generating the updated global management policy comprising the new most secure policy.

18. The system of claim 14 , wherein the indication of the modified relationship indicates a new relationship with a third management agent.

19. The system of claim 18 , wherein generating the updated global management policy comprises:

receiving a third policy container from the third management agent, wherein the third policy container comprises a third policy corresponding to the policy category;

determining the third policy is more secure than the most secure policy;

generating the updated global management policy comprising the third policy as a new most secure policy; and

updating stored policy data to comprise an association between the third management agent and the new most secure policy.

20. The system of claim 19 , wherein updated stored policy data further comprises removing the association between the issuing management agent and the most secure policy.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2019
From: ESTEVE BALDUCCI, JUAN V.; HIGASHI, MICHAEL K.; LIMONT, DAVID PAUL; ATWOOD, JOHN ALLEN; ATEEQ, BURHAN; TOUSIGNANT, PATRICK
To: MICROSOFT CORPORATION
Reel/Frame 048462/0789 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2019
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 048462/0904 →
Continuity (3)
Continuation 14546262 · Nov 18, 2014
Continuation 12334232 · Dec 12, 2008
Related Publication 20180027024A1 · Jan 25, 2018