IP Library Granted Patent US 11,489,801
Granted Patent B2
US 11,489,801 · App. 15/846,675 · Granted Nov 1, 2022

Systems and methods for controlling email access

Inventors: Alan Dabbiere (McLean, VA); Erich Stuntebeck (Johns Creek, GA); Jonathan Blake Brannon (Mableton, GA)
Assignee: AIRWATCH LLC
H04L51/212G06F21/6218H04L63/10H04L67/52G06F2221/2107H04W4/023H04W4/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,801
App. No.
15/846,675
Granted
Nov 1, 2022
Kind
B2
Abstract

Various examples for remotely controlling access to email resources are provided. In one example, one or more computing devices can be configured to provide, through an access control service, at least one user interface that enables creation of resource rules configured for use by the access control service in enforcement of one or more client devices in association with email resources. In response to input received through the at least one user interface of the access control service, the one or more computing devices can generate a resource rule that directs a client application on a client device to open an attachment of one of the email resources in an authorized secure container application.

Claims (36)

1. A system for remotely controlling access to an email resource, comprising:

at least one computing device comprising at least one hardware processor; and

program instructions stored in memory that, when executed by the at least one hardware processor, direct the at least one computing device to:

provide, through an access control service, at least one user interface that enables creation of at least one resource rule for enforcement on at least one client device in association with a plurality of email resources comprising a plurality of email messages;

in response to input received through the at least one user interface, generate the at least one resource rule on the at least computing device;

embed the at least one resource rule within one of the plurality of email messages; and

direct, based at least in part on the at least one resource rule being embedded within the one of the plurality of email messages, a client application executable on the at least one client device to open an attachment of the one of the plurality of email messages in an authorized secure container application executable on the at least one client device.

2. The system of claim 1 , further comprising program instructions that, when executed, direct the at least one computing device to, in response to the at least one resource rule being generated, modify the one of the plurality of email resources-such that the one of the plurality of email resources can only be opened in the authorized secure container application.

3. The system of claim 2 , wherein the one of the plurality of email resources is modified by encrypting at least a portion of the email resource using a cryptographic key, wherein the cryptographic key is provided to the authorized secure container application from the access control service.

4. The system of claim 2 , wherein the one of the plurality of email resources is modified by removing at least a portion of the one of the plurality of email resources prior to encryption.

5. The system of claim 1 , wherein the authorized secure container application is configured to disable at least one of: a cut function, a copy function, a paste function, a screen capture function, a share function, and a print function on the at least one client device.

6. The system of claim 1 , wherein the client application is directed based at least in part on the at least one resource rule to open the attachment of the one of the plurality of email resources in the authorized secure container application in response to receiving the at least one resource rule on the at least one client device from the access control service.

7. The system of claim 1 , wherein the authorized secure container application is configured to prevent at least one unauthorized application executable by the client device from accessing data within a data store associated with the secure container application.

8. A non-transitory computer-readable medium for remotely controlling access to an email resource embodying program code executable by at least one computing device that, when executed by the at least one computing device, causes the at least one computing device to:

provide, through an access control service, at least one user interface that enables creation of at least one resource rule for enforcement on at least one client device in association with a plurality of email resources comprising a plurality of email messages;

in response to input received through the at least one user interface, generate the at least one resource rule on the at least computing device;

embed the at least one resource rule within one of the plurality of email messages; and

direct, based at least in part on the at least one resource rule being embedded within the one of the plurality of email messages, a client application executable on the at least one client device to open an attachment of the one of the plurality of email messages in an authorized secure container application executable on the at least one client device.

9. The non-transitory computer-readable medium of claim 8 , further comprising program code that, when executed, causes the at least one computing device to, in response to the at least one resource rule being generated, modify the one of the plurality of email resources such that the one of the plurality of email resources can only be opened in the authorized secure container application.

10. The non-transitory computer-readable medium of claim 9 , wherein the one of the plurality of email resources is modified by encrypting at least a portion of the email resource using a cryptographic key, wherein the cryptographic key is provided to the authorized secure container application from the access control service.

11. The non-transitory computer-readable medium of claim 9 , wherein the one of the plurality of email resources is modified by removing at least a portion of the one of the plurality of email resources prior to encryption.

12. The non-transitory computer-readable medium of claim 8 , wherein the authorized secure container application is configured to disable at least one of: a cut function, a copy function, a paste function, a screen capture function, a share function, and a print function on the at least one client device.

13. The non-transitory computer-readable medium of claim 8 , wherein the client application is directed based at least in part on the at least one resource rule to open the attachment of the one of the plurality of email resources in the authorized secure container application in response to receiving the at least one resource rule on the at least one client device from the access control service.

14. The non-transitory computer-readable medium of claim 8 , wherein the authorized secure container application is configured to prevent at least one unauthorized application executable by the client device from accessing data within a data store associated with the secure container application.

15. A method for remotely controlling access to an email resource comprising:

providing, through an access control service, at least one user interface that enables creation of at least one resource rule for enforcement on at least one client device in association with a plurality of email resources comprising a plurality of email messages;

generating, in response to input received through the at least one user interface, the at least one resource rule on the at least computing device;

embedding the at least one resource rule within one of the plurality of email messages; and

directing, based at least in part on the at least one resource rule being embedded within the one of the plurality of email messages, a client application executable on the at least one client device to open an attachment of the one of the plurality of email messages in an authorized secure container application executable on the at least one client device.

16. The method of claim 15 , further comprising, in response to the at least one resource rule being generated, modifying the one of the plurality of email resources such that the one of the plurality of email resources can only be opened in the authorized secure container application.

17. The method of claim 16 , wherein the one of the plurality of email resources is modified by:

removing a first portion of the one of the plurality of email resources prior to encryption; and

encrypting a second portion of the email resource using a cryptographic key, wherein the cryptographic key is provided to the authorized secure container application from the access control service.

18. The method of claim 15 , wherein the authorized secure container application is configured to disable at least one of: a cut function, a copy function, a paste function, a screen capture function, a share function, and a print function on the at least one client device.

19. The method of claim 15 , wherein the client application is directed based at least in part on the at least one resource rule to open the attachment of the one of the plurality of email resources in the authorized secure container application in response to receiving the at least one resource rule on the at least one client device from the access control service.

20. The method of claim 15 , wherein the authorized secure container application is configured to prevent at least one unauthorized application executable by the client device from accessing data within a data store associated with the secure container application.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (3)
Continuation 14585309 · Dec 30, 2014
Continuation 13706499 · Dec 6, 2012
Related Publication 20180123994A1 · May 3, 2018