IP Library Granted Patent US 11,483,390
Granted Patent B2
US 11,483,390 · App. 16/411,712 · Granted Oct 25, 2022

Remote data securement on mobile devices

Inventors: Chase Bradley (Atlanta, GA); Kevin Jones (Atlanta, GA)
Assignee: AirWatch LLC
H04L67/125G06F21/45H04L63/102H04L63/20H04W12/084
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,390
App. No.
16/411,712
Granted
Oct 25, 2022
Kind
B2
Abstract

A client device includes an operating system that lacks an application native to the operating system for remotely effecting a complete data wipe of a storage device of the client device. The client device determines a status of the client device violates a compliance rule associated with operation of the client device. In response to determining that the client device violates the compliance rule, the client device sends the status to a server. The client device initiates execution of an operating system kernel call to remotely effect a complete data wipe of a storage device of the client device.

Claims (43)

1. A method, comprising:

determining, by a client device, that a status of the client device violates a compliance rule associated with operation of the client device, the client device comprising an operating system that lacks an application native to the operating system for remotely effecting a complete data wipe of a storage device of the client device;

in response to determining that the client device violates the compliance rule, sending, by the client device, the status to a server;

removing, by the client device, access to enterprise resources accessible via the server; and

initiating, by the client device, execution of a local command on the client device in response to retrieving a command from a command queue, the local command comprising a routine for restricting access to a hard disk storage device of the client device without user interaction by removing a boot signature from a master boot record of the hard disk storage device of the client device.

2. The method of claim 1 , wherein the local command comprises:

a routine for issuing a control code to a driver of the storage device of the client device.

3. The method of claim 1 , further comprising:

storing, by the client device, the compliance rule on the client device.

4. The method of claim 1 , wherein the client device includes an agent application configured to receive the command.

5. The method of claim 1 , wherein the client device executes an agent application that initiates execution of the local command.

6. The method of claim 1 , further comprising:

retrieving, by the client device, instruction code from a restricted access data store in the client device.

7. The method of claim 6 , wherein determining that the client device violates the compliance rule comprises detecting an unauthorized attempt to access the restricted access data store in the client device.

8. A system, comprising:

at least one computing device; and

an application executed by the at least one computing device, the application causing the at least one computing device to at least:

determine that a status of a client device violates a compliance rule associated with operation of the client device, the client device comprising an operating system that lacks an application native to the operating system for remotely effecting a complete data wipe of a storage device of the client device;

in response to determining that the client device violates the compliance rule, send the status to a server;

remove access to enterprise resources accessible via the server; and

initiate execution of a local command on the client device in response to retrieving a command from a command queue, the local command comprising a routine for restricting access to a hard disk storage device of the client device without user interaction by removing a boot signature from a master boot record of the hard disk storage device of the client device.

9. The system of claim 8 , wherein the local command comprises:

a routine for issuing a control code to a driver of the storage device of the client device.

10. The system of claim 8 , wherein the application further causes the at least one computing device to at least:

store the compliance rule on the client device.

11. The system of claim 8 , wherein the client device includes an agent application configured to receive the command.

12. The system of claim 8 , wherein the client device executes an agent application that initiates execution of the local command.

13. The system of claim 8 , wherein determining that the client device violates the compliance rule comprises detecting an unauthorized attempt to access a restricted access data store in the client device.

14. The system of claim 8 , wherein the application further causes the at least one computing device to at least:

retrieve instruction code from a restricted access data store on the client device.

15. A non-transitory computer-readable medium embodying a program executable in at least one computing device, the program, when executed by the at least one computing device causes the at least one computing device to perform the operations of:

determine that a status of a client device violates a compliance rule associated with operation of the client device, the client device comprising an operating system that lacks an application native to the operating system for remotely effecting a complete data wipe of a storage device of the client device;

in response to determining that the client device violates the compliance rule, send the status to a server;

remove access to enterprise resources accessible via the server; and

initiate execution of a local command on the client device in response to retrieving a command from a command queue, the local command comprising a routine for restricting access to a hard disk storage device of the client device without user interaction by removing a boot signature from a master boot record of the hard disk storage device of the client device.

16. The non-transitory computer-readable medium of claim 15 , wherein the local command comprises:

a routine for issuing a control code to a driver of the storage device of the client device.

17. The non-transitory computer-readable medium of claim 15 , wherein the program, when executed, further causes the at least one computing device to:

store the compliance rule on the client device.

18. The non-transitory computer-readable medium of claim 15 , wherein the client device includes an agent application configured to receive the command.

19. The non-transitory computer-readable medium of claim 15 , wherein the client device executes an agent application that initiates execution of the local command.

20. The non-transitory computer-readable medium of claim 15 , wherein the program, when executed, further causes the at least one computing device to:

retrieve instruction code from a restricted access data store on the client device.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (2)
Continuation 15175230 · Jun 7, 2016
Related Publication 20190268419A1 · Aug 29, 2019