IP Library Granted Patent US 8,799,994
Granted Patent B2
US 8,799,994 · App. 14/044,928 · Granted Aug 5, 2014

Policy-based application management

Inventors: Gary Barton (Boca Raton, FL); James Robert Walker (Deerfield Beach, FL); Nitin Desai (Coral Springs, FL); Zhongmin Lang (Parkland, FL)
Assignee: Citrix Systems, Inc.
G06F21/72H04L51/08G06F21/629H04L67/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,799,994
App. No.
14/044,928
Granted
Aug 5, 2014
Kind
B2
Abstract

Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.

Claims (49)

1. A method of managing applications of an enterprise on a mobile device, comprising:

installing a set of managed applications of the enterprise on the mobile device, wherein one or more unmanaged applications are installed on the mobile device that are not part of the set of managed applications;

receiving a set of application policies, wherein each of the set of managed applications is associated with one or more policies of the set of application policies;

selectively allowing a first application of the set of managed applications to provide data to a second application installed on the mobile device, responsive to accessing a policy associated with the first application and reading an indication from the policy of the first application that the second application is a member of the set of managed applications; and

selectively blocking the first application from providing data to a third unmanaged application installed on the mobile device, responsive to accessing the policy of the first application and failing to read an indication from the policy of the first application that the third application is a member of the set of managed applications, wherein the third application is capable of receiving data from the first application,

wherein selectively allowing the first application of the set of managed applications to provide data to a second application installed on the mobile device includes displaying a list of managed applications including the second application and allowing the user to select an application from the list of managed applications, and

wherein selectively blocking the first application of the set of managed applications from providing data to the third application installed on the mobile device includes displaying a list of managed applications excluding the third application, such that the user does not have an option to select the third application.

2. The method of claim 1 , wherein the set of managed applications are divided into at least two groups, and wherein each managed application is restricted from sharing data with any application not a member of the same group.

3. The method of claim 1 , wherein each of the set of managed applications is constrained to interact with other applications and services on the mobile device through its respective one or more application policies.

4. The method of claim 1 ,

wherein the mobile device runs an operating system extension that allows users to open a file by selecting from a group of applications compatible with a file type of the file,

wherein selectively allowing the first application of the set of managed applications to provide data to the second application includes displaying, by operation of the operating system extension, those applications that are both compatible with a file type of the file and are also part of the managed set of applications, and

wherein selectively blocking the first application of the set of managed applications from providing data to the third application includes failing to display, by operation of the operating system extension, those applications that are not part of the managed set of applications.

5. The method of claim 4 , wherein the operating system extension is Open-In.

6. The method of claim 1 , further comprising:

displaying the third application in a list of selectable applications when the device is operating in an unmanaged mode.

7. One or more non-transitory computer readable media storing computer readable instructions that, when executed by an electronic mobile device, cause the device to perform application management by:

installing a set of managed applications of an enterprise on the mobile device;

installing one or more unmanaged applications on the mobile device that are not part of the set of managed applications;

receiving a set of application policies, wherein each of the set of managed applications is associated with one or more policies of the set of application policies;

selectively allowing a first application of the set of managed applications to provide data to a second application installed on the mobile device, responsive to accessing a policy associated with the first application and reading an indication from the policy of the first application that the second application is a member of the set of managed applications; and

selectively blocking the first application from providing data to a third unmanaged application installed on the mobile device, responsive to accessing the policy of the first application and failing to read an indication from the policy of the first application that the third application is a member of the set of managed applications, wherein the third application is capable of receiving data from the first application,

wherein selectively allowing the first application of the set of managed applications to provide data to a second application installed on the mobile device includes displaying a list of managed applications including the second application and allowing the user to select an application from the list of managed applications, and

wherein selectively blocking the first application of the set of managed applications from providing data to the third application installed on the mobile device includes displaying a list of managed applications excluding the third application, such that the user does not have an option to select the third application.

8. The computer readable media of claim 7 , wherein the set of managed applications are divided into at least two groups, and wherein each managed application is restricted from sharing data with any application not a member of the same group.

9. The computer readable media of claim 7 , wherein each of the set of managed applications is constrained to interact with other applications and services on the mobile device through its respective one or more application policies.

10. The computer readable media of claim 7 ,

wherein the mobile device runs an operating system extension that allows users to open a file by selecting from a group of applications compatible with a file type of the file,

wherein selectively allowing the first application of the set of managed applications to provide data to the second application includes displaying, by operation of the operating system extension, those applications that are both compatible with a file type of the file and are also part of the managed set of applications, and

wherein selectively blocking the first application of the set of managed applications from providing data to the third application includes failing to display, by operation of the operating system extension, those applications that are not part of the managed set of applications.

11. The computer readable media of claim 10 , wherein the operating system extension is Open-In.

12. The computer readable media of claim 7 , wherein the instructions further cause the device to display the third application in a list of selectable applications when the device is operating in an unmanaged mode.

13. An electronic mobile device, comprising:

a processor; and

memory storing computer readable instructions that, when executed by the device, cause the device to perform application management by:

installing a set of managed applications of an enterprise on the mobile device;

installing one or more unmanaged applications on the mobile device that are not part of the set of managed applications;

receiving a set of application policies, wherein each of the set of managed applications is associated with one or more policies of the set of application policies;

selectively allowing a first application of the set of managed applications to provide data to a second application installed on the mobile device, responsive to accessing a policy associated with the first application and reading an indication from the policy of the first application that the second application is a member of the set of managed applications; and

selectively blocking the first application from providing data to a third unmanaged application installed on the mobile device, responsive to accessing the policy of the first application and failing to read an indication from the policy of the first application that the third application is a member of the set of managed applications, wherein the third application is capable of receiving data from the first application,

wherein selectively allowing the first application of the set of managed applications to provide data to a second application installed on the mobile device includes displaying a list of managed applications including the second application and allowing the user to select an application from the list of managed applications and

wherein selectively blocking the first application of the set of managed applications from providing data to the third application installed on the mobile device includes displaying a list of managed applications excluding the third application, such that the user does not have an option to select the third application.

14. The device of claim 13 , wherein the set of managed applications are divided into at least two groups, and wherein each managed application is restricted from sharing data with any application not a member of the same group.

15. The device of claim 13 , wherein each of the set of managed applications is constrained to interact with other applications and services on the mobile device through its respective one or more application policies.

16. The device of claim 13 ,

wherein the mobile device runs an operating system extension that allows users to open a file by selecting from a group of applications compatible with a file type of the file,

wherein selectively allowing the first application of the set of managed applications to provide data to the second application includes displaying, by operation of the operating system extension, those applications that are both compatible with a file type of the file and are also part of the managed set of applications, and

wherein selectively blocking the first application of the set of managed applications from providing data to the third application includes failing to display, by operation of the operating system extension, those applications that are not part of the managed set of applications.

17. The device of claim 13 , wherein the computer readable instructions further cause the device to perform displaying the third application in a list of selectable applications when the device is operating in an unmanaged mode.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2013
From: BARTON, GARY; WALKER, JAMES R; DESAI, NITIN; LANG, ZHONGMIN
To: CITRIX SYSTEMS, INC
Reel/Frame 031550/0833 →
Continuity (11)
Continuation 14043902 · Oct 2, 2013
Continuation In Part 13886889 · May 3, 2013
Continuation In Part 13886765 · May 3, 2013
Provisional Application 61861736 · Aug 2, 2013
Provisional Application 61806577 · Mar 29, 2013
Provisional Application 61714469 · Oct 16, 2012
Provisional Application 61713762 · Oct 15, 2012
Provisional Application 61713718 · Oct 15, 2012
Provisional Application 61713763 · Oct 15, 2012
Provisional Application 61714293 · Oct 16, 2012
Related Publication 20140033271A1 · Jan 30, 2014