IP Library Granted Patent US 10,716,005
Granted Patent B2
US 10,716,005 · App. 15/935,860 · Granted Jul 14, 2020

Managing applications across multiple management domains

Inventors: Mansu Kim (San Jose, CA); Suresh Kumar Batchu (Milpitas, CA)
Assignee: MOBILE IRON, INC.
H04W12/08G06F8/61G06F21/10G06F21/31G06F21/604G06F21/6218H04L63/102H04L63/20H04W12/0027H05K999/99
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,716,005
App. No.
15/935,860
Filed
Mar 26, 2018
Granted
Jul 14, 2020
Kind
B2
Art Unit
2436
USPC
726/1
Abstract

Techniques to manage applications, such as mobile apps, across multiple management domains are disclosed. In various embodiments, a set of one or more application management policies to be enforced with respect to a mobile device is received from a management entity to which a scope of authority to manage applications with respect to the mobile device has been delegated. A management agent on the mobile device is used to enforce the one or more application management policies with respect to applications and application data that are within the scope of authority delegated to the management entity.

Claims (32)

1. A system, comprising:

a processor configured to:

receive from a first management domain at a mobile device, an indication to remove an application installed on the mobile device, wherein the mobile device is configured to store data of the application that is associated with the first management domain; and

in response to receiving the indication to remove the application installed on the mobile device:

determine whether the application is associated with a plurality of management domains; and

in response to a determination that the application is associated with the plurality of management domains, secure on the mobile device the data of the application that is associated with the first management domain instead of removing the application from the mobile device, wherein the data of the application that is associated with the first management domain is secured as stored on the mobile device at least in part by encrypting the data of the application that is associated with the first management domain, encrypting the data of the application that is associated with the first management domain with a key removed from the mobile device, or encrypting the data of the application that is associated with the first management domain with a key discarded; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein a policy associated with the first management domain indicates that the application should be removed.

3. The system of claim 1 , wherein the processor is further configured to:

in response to a determination that the application is not associated with the plurality of management domains, remove from the mobile device the application and the data of the application that is associated with the first management domain.

4. The system of claim 1 , wherein the processor is further configured to return a result indicating that the application could not be removed and that the data of the application that is associated with the first management domain has been removed or secured.

5. The system of claim 4 , wherein information included in the result is filtered to limit access to data owned by the first management domain.

6. The system of claim 5 , wherein the information included in the result is filtered based on an information disclosure policy.

7. The system of claim 1 , wherein the first management domain's application lifecycle indicates that the application should be removed.

8. The system of claim 7 , wherein a mobile device management component is configured to provide the indication to the first management domain when the first management domain's application lifecycle is limited.

9. The system of claim 1 , wherein the indication is received from a device management server associated with the first management domain.

10. The system of claim 1 , wherein the processor is further configured to receive a definition of each of the plurality of management domains from a corresponding management entity.

11. The system of claim 10 , wherein each of the plurality of management domains has a corresponding scope of management authority with respect to the system.

12. The system of claim 10 , wherein the definition includes conflict resolution and/or precedence rules.

13. A method, comprising:

receiving from a first management domain at a mobile device an indication to remove an application installed on the mobile device, wherein the mobile device stores data of the application that is associated with the first management domain; and

in response to receiving the indication to remove the application installed on the mobile device:

determining whether the application is associated with a plurality of management domains; and

in response to determining that the application is associated with the plurality of management domains, securing on the mobile device the data of the application that is associated with the first management domain instead of removing the application from the mobile device, wherein the data of the application that is associated with the first management domain is secured as stored on the mobile device at least in part by encrypting the data of the application that is associated with the first management domain, encrypting the data of the application that is associated with the first management domain with a key removed from the mobile device, or encrypting the data of the application that is associated with the first management domain with a key discarded.

14. The method of claim 13 , further comprising returning a result indicating that the application could not be removed and that the data of the application that is associated with the first management domain has been removed or secured.

15. The method of claim 13 , wherein the first management domain's application lifecycle indicates that the application should be removed.

16. The method of claim 13 , wherein the indication is received from a device management server associated with the first management domain.

17. A computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving from a first management domain at a mobile device an indication to remove an application installed on the mobile device, wherein the mobile device stores data of the application that is associated with the first management domain; and

in response to receiving the indication to remove the application installed on the mobile device:

determining whether the application is associated with a plurality of management domains; and

in response to determining that the application is associated with the plurality of management domains, securing on the mobile device the data of the application that is associated with the first management domain instead of removing the application from the mobile device, wherein the data of the application that is associated with the first management domain is secured as stored on the mobile device at least in part by encrypting the data of the application that is associated with the first management domain, encrypting the data of the application that is associated with the first management domain with a key removed from the mobile device, or encrypting the data of the application that is associated with the first management domain with a key discarded.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
Continuity (4)
Continuation 15582310 · Apr 28, 2017
Continuation 14793022 · Jul 7, 2015
Provisional Application 62021615 · Jul 7, 2014
Related Publication 20180288619A1 · Oct 4, 2018