IP Library Granted Patent US 8,806,570
Granted Patent B2
US 8,806,570 · App. 14/044,901 · Granted Aug 12, 2014

Policy-based application management

Inventors: Gary Barton (Boca Raton, FL); James Robert Walker (Deerfield Beach, FL); Nitin Desai (Coral Springs, FL); Zhongmin Lang (Parkland, FL)
Assignee: Citrix Systems, Inc.
H04L63/20H04W12/08G06F21/72G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,806,570
App. No.
14/044,901
Granted
Aug 12, 2014
Kind
B2
Abstract

Improved techniques for managing enterprise applications on mobile devices are described herein. Each enterprise mobile application running on the mobile device has an associated policy through which it interacts with its environment. The policy selectively blocks or allows activities involving the enterprise application in accordance with rules established by the enterprise. Together, the enterprise applications running on the mobile device form a set of managed applications. Managed applications are typically allowed to exchange data with other managed applications, but are blocked from exchanging data with other applications, such as the user's own personal applications. Policies may be defined to manage data sharing, mobile resource management, application specific information, networking and data access solutions, device cloud and transfer, dual mode application software, enterprise app store access, and virtualized application and resources, among other things.

Claims (35)

1. A method comprising:

receiving, by a processor of an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files defined independent of the managed application, wherein each policy file defines one or more access controls enforced by a mobile device management system on the electronic mobile device when the managed application is executing on the electronic mobile device;

receiving, by the processor, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and

running, by the processor, the managed application on the mobile device, the managed application limited by the access controls defined in the set of policy files and enforced by the mobile device management system,

wherein the set of one or more policy files, when applied to the managed application, cause the managed application to restrict a data sharing feature available to one or more unmanaged applications executing on the electronic mobile device.

2. The method of claim 1 , wherein the data sharing feature comprises an unrestricted cut and paste feature exposed by an operating system of the electronic mobile device.

3. The method of claim 1 , wherein the data sharing feature comprises a URL dispatch feature, and wherein the set of one or more policy files act to prevent the managed application from performing a URL dispatch.

4. The method of claim 1 , wherein the data sharing feature comprises a dictation feature, and wherein the set of one or more policy files act to prevent the managed application from permitting a user to use the dictation feature from within the managed application.

5. The method of claim 1 , wherein the data sharing feature comprises a content provider API, and wherein the set of one or more policy files act to prevent the managed application from calling the content provider API.

6. The method of claim 1 , wherein the data sharing feature comprises a remote procedure call, and wherein the set of one or more policy files act to prevent the managed application from calling the remote procedure call.

7. The method of claim 1 , wherein the data sharing feature comprises a memory sharing feature, and wherein the set of one or more policy files act to prevent the managed application from writing data to memory shared with an unmanaged application.

8. Non-transitory computer readable media storing

instructions that, when executed, cause a system to perform:

receiving, by a processor of an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files defined independent of the managed application, wherein each policy file defines one or more access controls enforced by a mobile device management system on the electronic mobile device when the managed application is executing on the electronic mobile device;

receiving, by the processor, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and

running, by the processor, the managed application on the mobile device, the managed application limited by the access controls defined in the set of policy files and enforced by the mobile device management system,

wherein the set of one or more policy files, when applied to the managed application, cause the managed application to restrict a data sharing feature available to one or more unmanaged applications executing on the electronic mobile device.

9. The computer readable media of claim 8 , wherein the data sharing feature comprises an unrestricted cut and paste feature exposed by an operating system of the electronic mobile device.

10. The computer readable media of claim 8 , wherein the data sharing feature comprises a URL dispatch feature, and wherein the set of one or more policy files act to prevent the managed application from performing a URL dispatch.

11. The computer readable media of claim 8 , wherein the data sharing feature comprises a dictation feature, and wherein the set of one or more policy files act to prevent the managed application from permitting a user to use the dictation feature from within the managed application.

12. The computer readable media of claim 8 , wherein the data sharing feature comprises a content provider API, and wherein the set of one or more policy files act to prevent the managed application from calling the content provider API.

13. The computer readable media of claim 8 , wherein the data sharing feature comprises a remote procedure call, and wherein the set of one or more policy files act to prevent the managed application from calling the remote procedure call.

14. The computer readable media of claim 8 , wherein the data sharing feature comprises a memory sharing feature, and wherein the set of one or more policy files act to prevent the managed application from writing data to memory shared with an unmanaged application.

15. An apparatus comprising:

a processor; and

memory storing computer readable instructions that, when executed by the processor, cause the apparatus to perform:

receiving, by a processor of an electronic mobile device, a managed application from an application server during a first communication, the managed application being constructed to operate in accordance with a set of one or more policy files defined independent of the managed application, wherein each policy file defines one or more access controls enforced by a mobile device management system on the electronic mobile device when the managed application is executing on the electronic mobile device;

receiving, by the processor, the set of one or more policy files from the application server during a second communication which is different than the first communication, the set of one or more policy files being stored on the electronic mobile device separately from the managed application; and

running, by the processor, the managed application on the mobile device, the managed application limited by the access controls defined in the set of policy files and enforced by the mobile device management system,

wherein the set of one or more policy files, when applied to the managed application, cause the managed application to restrict a data sharing feature available to one or more unmanaged applications executing on the electronic mobile device.

16. The apparatus of claim 15 , wherein the data sharing feature comprises an unrestricted cut and paste feature exposed by an operating system of the electronic mobile device.

17. The apparatus of claim 15 , wherein the data sharing feature comprises a URL dispatch feature, and wherein the set of one or more policy files act to prevent the managed application from performing a URL dispatch.

18. The apparatus of claim 15 , wherein the data sharing feature comprises a dictation feature, and wherein the set of one or more policy files act to prevent the managed application from permitting a user to use the dictation feature from within the managed application.

19. The apparatus of claim 15 , wherein the data sharing feature comprises a content provider API, and wherein the set of one or more policy files act to prevent the managed application from calling the content provider API.

20. The apparatus of claim 15 , wherein the data sharing feature comprises a remote procedure call, and wherein the set of one or more policy files act to prevent the managed application from calling the remote procedure call.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2013
From: BARTON, GARY; WALKER, JAMES R; DESAI, NITIN; LANG, ZHONGMIN
To: CITRIX SYSTEMS, INC
Reel/Frame 031550/0812 →
Continuity (11)
Continuation 14043902 · Oct 2, 2013
Continuation In Part 13886889 · May 3, 2013
Continuation In Part 13886765 · May 3, 2013
Provisional Application 61861736 · Aug 2, 2013
Provisional Application 61806577 · Mar 29, 2013
Provisional Application 61714469 · Oct 16, 2012
Provisional Application 61713762 · Oct 15, 2012
Provisional Application 61713718 · Oct 15, 2012
Provisional Application 61713763 · Oct 15, 2012
Provisional Application 61714293 · Oct 16, 2012
Related Publication 20140040977A1 · Feb 6, 2014