IP Library Granted Patent US 11,356,431
Granted Patent B2
US 11,356,431 · App. 16/673,758 · Granted Jun 7, 2022

Operating system integrated domain management

Inventors: Alexander James Main (Ottawa, CA); James Henry Allan Puderer (Ottawa, CA)
Assignee: CIS MAXWELL, LLC
H04L63/08G06F8/61G06F21/44G06F21/57G06F21/6218H04L9/3271H04L63/0428H04L63/06H04L63/102H04L63/20H04W12/06H04W12/08H04W12/086G06F9/4451G06F2221/034G06F2221/2105G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,356,431
App. No.
16/673,758
Granted
Jun 7, 2022
Kind
B2
Abstract

A computing device operating system providing a plurality of secure domains. A domain manager selectively creates a plurality of secure domains, and one of the secure domains is selected as a current domain. A domain policy service stores and enforces, for each secure domain, a policy comprising a rule set controlling access to files and applications associated with the domain. A package manager enforces, for each secure domain, installation of the applications associated with the domain. A domain message service provides communication between running processes associated with different ones of the secure domains. An activity manager selectively switches the current domain. Domain isolation is achieved while enabling a unified user interface providing concurrent access to the resources of multiple domains.

Claims (26)

1. A non-transitory computer-readable medium comprising instructions stored thereon that, when executed by a computer, perform the method of:

(a) for each secure domain:

(a1) associating resources of the secure domain with a unique domain identifier, the resources comprising at least one data file or at least one application; and

(a2) storing a policy in association with the unique domain identifier, the policy comprising a rule set for controlling access to the resources

(b) generating an event message associated with an originating process associated with a first one of the secure domains;

(c) determining that a target process associated with a second one of the secure domains is configured to respond to the event message;

(d) processing the event message based on the policy associated with the first domain and the policy associated with the second domain, to produce a processed event message; and

(e) passing or blocking the processed event message to the target process based on the policy associated with the first domain and the policy associated with the second domain.

2. A method performed by a processor of a computing device to provide a plurality of secure domains in an operating system of the computing device, the method comprising:

(a) for each secure domain:

(a1) associating resources of the secure domain with a unique domain identifier, the resources comprising at least one data file or at least one application; and

(a2) storing a policy in association with the unique domain identifier, the policy comprising a rule set for controlling access to the resources;

(b) generating an event message associated with an originating process associated with a first one of the secure domains;

(c) determining that a target process associated with a second one of the secure domains is configured to respond to the event message;

(d) processing the event message based on the policy associated with the first domain and the policy associated with the second domain, to produce a processed event message; and

(e) passing or blocking the processed event message to the target process based on the policy associated with the first domain and the policy associated with the second domain.

3. The method according to claim 2 , wherein the event message indicates a copy-and-paste action generated by the originating process, the policy associated with the first domain implements a first rule allowing passing of a clipboard buffer out of the first domain, and the policy associated with the second domain implements a second rule allowing passing of the clipboard buffer into the second domain, wherein the processed event message based on the clipboard buffer is passed to the target process.

4. The method according to claim 2 , wherein the event message indicates a copy-and-paste action generated by the originating process, the policy associated with the first domain implements a first rule preventing passing of a clipboard buffer out of the first domain, or the policy associated with the second domain implements a second rule preventing passing of the clipboard buffer into the second domain, wherein the processed event message based on the clipboard buffer is blocked from the target process.

5. The method according to claim 2 , wherein the event message comprises a message received notification generated by the originating process, the policy associated with the first domain implements a first rule implementing a filter of the message received notification, or the policy associated with the second domain implements a second rule implementing the filter of the message received notification, wherein the processed event message comprises a filtered message received notification, and wherein the filtered message received notification is passed to the target process.

6. The method according to claim 2 , wherein (a1) comprises storing metadata associating the resources with the unique domain identifier of the secure domain.

7. The method according to claim 5 , wherein the filter removes or obscures at least a sender identifier or a subject identifier of the message received notification.

8. The non-transitory computer-readable medium according to claim 1 , wherein the event message indicates a copy-and-paste action generated by the originating process, the policy associated with the first domain implements a first rule allowing passing of a clipboard buffer out of the first domain, and the policy associated with the second domain implements a second rule allowing passing of the clipboard buffer into the second domain, wherein the processed event message based on the clipboard buffer is passed to the target process.

9. The non-transitory computer-readable medium according to claim 1 , wherein the event message indicates a copy-and-paste action generated by the originating process, the policy associated with the first domain implements a first rule preventing passing of a clipboard buffer out of the first domain, or the policy associated with the second domain implements a second rule preventing passing of the clipboard buffer into the second domain, wherein the processed event message based on the clipboard buffer is blocked from the target process.

10. The non-transitory computer-readable medium according to claim 1 , wherein the event message comprises a message received notification generated by the originating process, the policy associated with the first domain implements a first rule implementing a filter of the message received notification, or the policy associated with the second domain implements a second rule implementing the filter of the message received notification, wherein the processed event message comprises a filtered message received notification, and wherein the filtered message received notification is passed to the target process.

11. The non-transitory computer-readable medium according to claim 1 , wherein (a1) comprises storing metadata associating the resources with the unique domain identifier of the secure domain.

12. The non-transitory computer-readable medium according to claim 10 , wherein the filter removes or obscures at least a sender identifier or a subject identifier of the message received notification.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Jun 10, 2026
From: PNC BANK, NATIONAL ASSOCIATION
To: CIS SECURE COMPUTING, INC.; CIS MAXWELL, LLC
Reel/Frame 074908/0231 →
SECURITY INTEREST Recorded Jun 8, 2026
From: CIS SECURE COMPUTING, INC.; CIS MAXWELL, LLC
To: WINGSPIRE CAPITAL LLC
Reel/Frame 074885/0883 →
SECURITY INTEREST Recorded Apr 23, 2021
From: CIS SECURE COMPUTING, INC.; CIS MAXWELL, LLC
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 056019/0267 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2020
From: GRAPHITE SOFTWARE CORPORATION
To: CIS MAXWELL, LLC
Reel/Frame 054267/0700 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2020
From: MAIN, ALEXANDER JAMES; PUDERER, JAMES HENRY ALLAN
To: GRAPHITE SOFTWARE CORPORATION
Reel/Frame 052571/0911 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2020
From: PUDERER, JAMES HENRY ALLAN; MUIR, JAMES ALEXANDER
To: GRAPHITE SOFTWARE CORPORATION
Reel/Frame 052572/0360 →
Continuity (4)
Continuation 14911647
Provisional Application 62026272 · Jul 18, 2014
Provisional Application 61864899 · Aug 12, 2013
Related Publication 20200244637A1 · Jul 30, 2020
Cited By (1)
US 12,393,665