IP Library Granted Patent US 11,138,309
Granted Patent B2
US 11,138,309 · App. 16/296,708 · Granted Oct 5, 2021

System and method for controlling inter-application association through contextual policy control

Inventors: Stuart Schaefer (Marblehead, MA); John Sheehan (Somerville, MA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F21/53G06F9/44505G06F9/545G06F21/62G06F21/6281G06F2209/542
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,138,309
App. No.
16/296,708
Granted
Oct 5, 2021
Kind
B2
Abstract

A method for controlling the interoperation of a plurality of software applications and resources includes intercepting communications from a first application to a second application or resource, directing the communication to a context management system, generating a candidate list of contexts for the communication, evaluating the candidate list according to at least one policy defined for these contexts to identify the resultant action and namespace for the communication, and performing the action as defined by the policies within the identified namespace. The method further includes tracking one or more versions of the second application, as well as tracking an evolution of application and/or resource names. The method further includes identifying one or more operations associated with a context on the candidate list, and executing the identified operations prior to a further communication.

Claims (19)

1. A system in which resources can be configured to be private to a software application or shared among multiple software applications, comprising:

a processor;

a memory communicatively coupled to the processor to configure the processor at least to:

execute an operating system (OS);

execute a first software application ( 402 ) and a second software applications ( 403 );

generate first, second, and third resource sets ( 404 , 405 , 406 ), wherein each resource set includes one or more resources, wherein the resources in each of the resource sets are stored in separate namespace container objects; and

generate an OS guard ( 100 , 401 ) for controlling the interoperation of the software applications and resources, the OS guard comprising a core ( 102 ) for managing applications and their context, a process manager ( 120 ) configured to inform the core of process events, and a virtual environment manager including a plurality of virtualization subsystems;

wherein the system is configured to operate in the following modes: (a) a first mode in which the first application ( 402 ) is able to use a first resource set ( 404 ) configured for use only by the first application; (b) a second mode in which the first application ( 402 ) is able to read a second resource set ( 406 ) configured for the second application ( 403 ); and (c) a third mode in which both the first and second applications are able to read from and write to a third, shared resource set ( 405 ) configured for access by both the first and second applications.

2. The system of claim 1 , wherein each namespace container object is further configured to allow storage of resources to be done in a localized and independent fashion, appropriate for each combination, and to be dynamically put into the correct namespace container object.

3. The system of claim 2 , wherein the resources can be persisted in the namespace container objects or in metadata required to recreate an appropriate resource or named object.

4. The system of claim 1 , wherein the OS guard is configured to be employed with an operating system that includes an underlying system registry, and wherein the OS guard is further configured to provide a virtual registry to the applications but prevent modification to the underlying system registry.

5. The system of claim 4 , wherein the plurality of software applications are configured to access keys from the underlying system registry by issuing a query, and wherein OS guard is configured to respond to the query with the key and its value if known by the OS guard, or to pass the query to underlying system registry if not known by the OS guard; and wherein, if an attempt is made to modify the value of the key by a requesting application, the OS Guard is configured to allow the modification to occur to itself only.

6. The system of claim 5 , wherein the keys that the OS guard uses are specified in three sections, including as commands to modify an existing key, delete the presence of a key, or add a new key to the virtual registry.

7. The system of claim 6 , wherein the OS guard is further configured to load a first data file containing basic registry entries for each application, a second data file containing user preferences, and a third data file containing keys that include policy items a user is not allowed to override; wherein the first, second, and third data files are loaded on top of each other with duplicate items in each file overriding items in the file before it.

8. The system of claim 1 , wherein the process manager is further configured to provide an abstraction layer for managing a process space and handling thread processing.

9. The system of claim 8 , wherein the process manager is further configured to group processes together into application bundles (applications), such that an application bundle comprises a group of processes that share virtual resources with each other.

10. The system of claim 1 , further comprising a loader ( 116 ) configured to allow virtual environments to be transferred into and out of a running system.

11. The system of claim 10 , wherein each of the virtualization subsystems is configured to serialize its configuration for the loader, and wherein the loader is configured for staged loading/unloading and combining results of individual stages into a single environment description.

12. The system of claim 1 , wherein the plurality of virtualization subsystems include a configuration manager ( 104 ); a file manager ( 106 ); a shared object manager ( 108 ); and a device manager ( 110 ).

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NO. 7602354 PREVIOUSLY RECORDED AT REEL: 059820 FRAME: 0448. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER . Recorded May 11, 2022
From: SOFTRICITY, INC.
To: MICROSOFT CORPORATION
Reel/Frame 059938/0357 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT NUMBER FROM 7602354 TO 11138309 PREVIOUSLY RECORDED AT REEL: 059708 FRAME: 0195. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 3, 2022
From: SCHAFFER, STUART; SHEEHAN, JOHN
To: SOFTRICITY, INC.
Reel/Frame 059847/0406 →
MERGER Recorded Apr 28, 2022
From: SOFTRICITY, INC.
To: MICROSOFT CORPORATION
Reel/Frame 059820/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2022
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 060378/0001 →
Continuity (4)
Continuation 13154323 · Jun 6, 2011
Division 11191595 · Jul 28, 2005
Provisional Application 60598234 · Aug 3, 2004
Related Publication 20190205529A1 · Jul 4, 2019