IP Library Granted Patent US 11,876,794
Granted Patent B2
US 11,876,794 · App. 17/201,196 · Granted Jan 16, 2024

Managed domains for remote content and configuration control on mobile information devices

Inventors: Alexander James Main (Ottawa, CA); Ron Vandergeest (Ottawa, CA); Paul Litva (Ottawa, CA)
Assignee: CIS MAXWELL, LLC
H04L63/083G06F21/53G06Q30/0267H04W12/086H04W12/37
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,794
App. No.
17/201,196
Granted
Jan 16, 2024
Kind
B2
Abstract

A technique is disclosed for remotely managing isolated domains on mobile devices. A request is received from the mobile device to instantiate a managed domain. A managed domain configuration is determined and comprises a security policy controlling access to content of the managed domain of the subscribing mobile device, a content specification identifying the content to be downloaded by the subscribing mobile device into the managed domain, and a content configuration identifying a configuration of the content on the subscribing mobile device. The managed domain configuration is sent to the subscribing mobile device to instantiate a secure, managed domain whose policy, content and content configuration is remotely controlled. The technique is useful for advertising and brand promotion on mobile devices as it simultaneously enables detailed control over the presentation of content by a curator while ensuring privacy and security protection of the other apps, accounts and data on the mobile device.

Claims (64)

1. A method performed on a mobile device for providing an externally managed domain on the mobile device, the mobile device comprising a processor, a memory, and a communications interface, the memory storing instructions executable by the processor to perform the method, the method comprising:

using the communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for the externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device;

creating the externally managed domain based on the managed domain configuration; and

controlling access to local resources on the mobile device associated with a personal isolated domain on the mobile device different from the externally managed domain by managed domain processes associated with the externally managed domain based at least in part on a personal isolated domain security policy associated with the personal isolated domain;

wherein the controlling access by the managed domain processes to the local resources is performed at least in part by a first service operating within a kernel of an operating system of the mobile device and at least in part by a second service operating in a middleware of the operating system outside of the kernel.

2. The method of claim 1 , wherein the managed domain configuration further comprises a managed domain content specification identifying the managed domain content for download by the mobile device into the externally managed domain and a managed domain content configuration specifying a configuration of the managed domain content on the mobile device, and creating the externally managed domain comprises provisioning the externally managed domain based on the managed domain configuration.

3. A method performed on a mobile device for providing an externally managed domain on the mobile device, the mobile device comprising a processor, a memory, and a communications interface, the memory storing instructions executable by the processor to perform the method, the method comprising:

using the communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for the externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device;

creating the externally managed domain based on the managed domain configuration; and

controlling access to the managed domain content by personal isolated domain processes associated with a personal isolated domain on the mobile device different from the externally managed domain based at least in part on the managed domain security policy;

wherein the controlling access by the personal isolated domain processes to the managed domain content is performed at least in part by a first service operating within a kernel of an operating system of the mobile device and at least in part by a second service operating in a middleware of the operating system outside of the kernel.

4. A method performed on a mobile device for providing an externally managed domain on the mobile device, the mobile device comprising a processor, a memory, and a communications interface, the memory storing instructions executable by the processor to perform the method, the method comprising:

using the communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for the externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device; and

creating the externally managed domain based on the managed domain configuration;

wherein the add domain request further comprises a current geographic location of the mobile device, and the managed domain configuration is based at least in part on the current geographic location.

5. The method of claim 4 , further comprising:

controlling access to the managed domain content by personal isolated domain processes associated with a personal isolated domain on the mobile device different from the externally managed domain based at least in part on the managed domain security policy.

6. The method of claim 5 , wherein controlling access to the managed domain content by the personal isolated domain processes comprises preventing access to the managed domain content by the personal isolated domain processes.

7. The method of claim 4 , further comprising:

controlling access to local resources on the mobile device associated with a personal isolated domain on the mobile device different from the externally managed domain by managed domain processes associated with the externally managed domain based at least in part on a personal isolated domain security policy associated with the personal isolated domain.

8. The method of claim 7 , wherein controlling access to the local resources by the managed domain processes comprises preventing access to the local resources by the managed domain processes.

9. The method of claim 7 , wherein controlling access by the managed domain processes to the local resources comprises controlling access by the managed domain processes process to the local resources based in part on the managed domain security policy.

10. The method of claim 7 , wherein the mobile device further comprises a user interface, the personal isolated domain security policy comprises local security settings, and the method further comprises operating the user interface to receive the local security settings.

11. The method of claim 10 , wherein the local security settings specify permissions or a level of trust associated with the externally managed domain.

12. The method of claim 7 , wherein the local resources comprise a particular resource comprising a contacts store, a calendar store, a data file, or a file directory, and the local security settings identify the particular resource.

13. The method of claim 5 , further comprising:

controlling access to local resources on the mobile device associated with the personal isolated domain by managed domain processes associated with the externally managed domain based at least in part on a personal isolated domain security policy associated with the personal isolated domain.

14. The method of claim 4 , wherein the externally managed domain is a first externally managed domain, the add domain request is a first add domain request, the messaging server is a first messaging server, the domain management service is a first domain management service, the managed domain configuration is a first managed domain configuration, the managed domain security policy is a first managed domain security policy, and the managed domain content is first managed domain content, the method further comprising:

using the communications interface to send a second add domain request to a second messaging server, the second add domain request comprising the device identifier of the mobile device;

using the communications interface to receive from a second domain management service different from the first domain management service a second managed domain configuration for a second externally managed domain, the second managed domain configuration comprising a second managed domain security policy operable by the processor to control access to second managed domain content in the second externally managed domain on the mobile device;

creating the second externally managed domain based on the second managed domain configuration;

controlling access to local resources on the mobile device associated with a personal isolated domain on the mobile device different from the first externally managed domain and the second externally managed domain by either first managed domain processes associated with the first externally managed domain or second managed domain processes associated with the second externally managed domain based at least in part on a personal isolated domain security policy associated with the personal isolated domain.

15. A method performed on a mobile device for providing an externally managed domain on the mobile device, the mobile device comprising a processor, a memory, and a communications interface, the memory storing instructions executable by the processor to perform the method, the method comprising:

using the communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for the externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device;

creating the externally managed domain based on the managed domain configuration;

wherein the managed domain configuration further comprises a managed domain content specification identifying the managed domain content for download by the mobile device into the externally managed domain and a managed domain content configuration specifying a configuration of the managed domain content on the mobile device, and creating the externally managed domain comprises provisioning the externally managed domain based on the managed domain configuration;

the add domain request further comprises a current geographic location of the mobile device; and

the managed domain configuration is based at least in part on the current geographic location, wherein the managed domain content specification comprises an identification of content to be downloaded and installed in the externally managed domain based on the current geographic location of the mobile device.

16. The method of claim 15 , wherein provisioning the externally managed domain comprises storing the managed domain security policy, using the communications interface to download the managed domain content into the externally managed domain based on the managed domain content specification, and configuring the managed domain content in the externally managed domain based on the managed domain content configuration.

17. A method performed on a mobile device for providing an externally managed domain on the mobile device, the mobile device comprising a processor, a memory, and a communications interface, the memory storing instructions executable by the processor to perform the method, the method comprising:

using the communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for the externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device;

creating the externally managed domain based on the managed domain configuration;

wherein the externally managed domain is a first externally managed domain, the add domain request is a first add domain request, the messaging server is a first messaging server, the domain management service is a first domain management service, the managed domain configuration is a first managed domain configuration, the managed domain security policy is a first managed domain security policy, and the managed domain content is first managed domain content, the method further comprising:

using the communications interface to send a second add domain request to a second messaging server, the second add domain request comprising the device identifier of the mobile device;

using the communications interface to receive from a second domain management service different from the first domain management service a second managed domain configuration for a second externally managed domain, the second managed domain configuration comprising a second managed domain security policy operable by the processor to control access to second managed domain content in the second externally managed domain on the mobile device;

creating the second externally managed domain based on the second managed domain configuration;

controlling access to local resources on the mobile device associated with a personal isolated domain on the mobile device different from the first externally managed domain and the second externally managed domain by either first managed domain processes associated with the first externally managed domain or second managed domain processes associated with the second externally managed domain based at least in part on a personal isolated domain security policy associated with the personal isolated domain;

the first add domain request further comprises a first current geographic location of the mobile device, and the first managed domain configuration is based at least in part on the first geographic location; and

the second add domain request further comprises a second current geographic location of the mobile device, and the second managed domain configuration is based at least in part on the second geographic location.

18. A tangible non-transitory computer-readable medium comprising instructions stored thereon that, when executed by a processor of a mobile device, perform the following processes:

using a communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for an externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device; and

creating the externally managed domain based on the managed domain configuration;

wherein the add domain request further comprises a current geographic location of the mobile device, and the managed domain configuration is based at least in part on the current geographic location.

19. A mobile device comprising a processor, a memory, and a communications interface, the memory storing instructions executable by the processor to perform the following processes:

using the communications interface to send an add domain request to a messaging server, the add domain request comprising a device identifier of the mobile device;

using the communications interface to receive from a domain management service a managed domain configuration for an externally managed domain, the managed domain configuration comprising a managed domain security policy operable by the processor to control access to managed domain content in the externally managed domain on the mobile device; and

creating the externally managed domain based on the managed domain configuration;

wherein the add domain request further comprises a current geographic location of the mobile device, and the managed domain configuration is based at least in part on the current geographic location.

Assignments (1)
SECURITY INTEREST Recorded Jun 8, 2026
From: CIS SECURE COMPUTING, INC.; CIS MAXWELL, LLC
To: WINGSPIRE CAPITAL LLC
Reel/Frame 074885/0883 →
Continuity (4)
Continuation 16298631 · Mar 11, 2019
Continuation 15037944
Provisional Application 61907082 · Nov 21, 2013
Related Publication 20210336942A1 · Oct 28, 2021