IP Library Granted Patent US 10,432,672
Granted Patent B2
US 10,432,672 · App. 15/926,010 · Granted Oct 1, 2019

Detection of offline attempts to circumvent security policies

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,432,672
App. No.
15/926,010
Granted
Oct 1, 2019
Kind
B2
Abstract

Disclosed are approaches for detecting attempts to circumvent security policies on a client device. A deletion of a user account on a computing device is detected, wherein the deletion is initiated locally on the computing device and the user account is associated with an enrollment of the computing device with a management service. Data stored in a memory of the computing device that is subject to a policy received from the management service is identified. The data is deleted from the memory of the computing device. The policy is then deleted from the memory of the computing device.

Claims (34)

1. A system, comprising:

a computing device comprising a processor and a memory;

a first application comprising machine-readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least:

monitor a second application to detect a deletion of a user account initiated locally on the computing device, wherein the user account is associated with an enrollment of the computing device with a management service;

identify data subject to a policy received from the management service;

delete the data from the memory of the computing device; and

delete a value for a setting of the computing device, wherein the value for the setting was previously set to place the computing device in compliance with the policy.

2. The system of claim 1 , wherein the first application further causes the computing device to unenroll the computing device from the management service.

3. The system of claim 1 , wherein the first application further causes the computing device to at least report the deletion of the user account to the management service.

4. The system of claim 1 , wherein the first application further causes the computing device to at least uninstall the first application from the computing device.

5. The system of claim 1 , wherein the first application further causes the computing device to at least delete the policy from the memory of the computing device.

6. The system of claim 1 , wherein the data comprises a third application installed on the computing device to place the computing device in compliance with the policy.

7. The system of claim 1 , wherein causing the computing device to delete the data from the memory of the computing device comprises causing the computing device to overwrite the data in the memory of the computing device with a stream of bits, wherein each bit in the stream of bits is set to the same value.

8. A method, comprising:

monitoring an application executing in a computing device to detect a deletion of a user account on a computing device by the application, wherein the deletion is initiated locally on the computing device and the user account is associated with an enrollment of the computing device with a management service;

identifying data stored in a memory of the computing device that is subject to a policy received from the management service;

deleting the data from the memory of the computing device; and

deleting a value for a setting of the computing device, wherein the value for the setting was previously set to place the computing device in compliance with the policy.

9. The method of claim 8 , further comprising reporting the deletion of the user account to the management service.

10. The method of claim 8 , further comprising unenrolling the computing device from the management service.

11. The method of claim 8 , further comprising deleting the policy from the memory of the computing device.

12. The method of claim 8 , wherein the data comprises a second application installed on the computing device to place the computing device in compliance with the policy.

13. The method of claim 8 , wherein deleting the data from the memory of the computing device comprises overwriting the data in the memory of the computing device with a stream of bits, wherein each bit in the stream of bits is set to the same value.

14. A non-transitory computer readable medium comprising machine readable instructions that, when executed by a processor of a computing device, cause the computing device to at least:

monitor an application to detect a deletion of a user account on the computing device initiated with the application, wherein the deletion is initiated locally on the computing device and the user account is associated with an enrollment of the computing device with a management service;

identify data stored in a memory of the computing device that is subject to a policy received from the management service;

delete the data from the memory of the computing device; and

delete a value for a setting of the computing device, wherein the value for the setting was previously set to place the computing device in compliance with the policy.

15. The non-transitory computer readable medium of claim 14 , wherein the machine readable instructions further cause the computing device to at least unenroll the computing device from the management service.

16. The non-transitory computer readable medium of claim 14 , wherein the machine readable instructions further cause the computing device to at least delete the policy from the memory of the computing device.

17. The non-transitory computer readable medium of claim 14 , wherein the machine readable instructions further cause the computing device to at least report the deletion of the user account to the management service.

18. The non-transitory computer readable medium of claim 14 , wherein the machine readable instructions further cause the computing device to at least remove the machine readable instructions from the computing device.

19. The non-transitory computer readable medium of claim 14 , wherein the data comprises a second application installed on the computing device to place the computing device in compliance with the policy.

20. The non-transitory computer readable medium of claim 14 , wherein causing the computing device to delete the data from the memory of the computing device comprises causing the computing device to overwrite the data in the memory of the computing device with a stream of bits, wherein each bit in the stream of bits is set to the same value.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →