IP Library › Granted Patent US 12,574,373
Granted Patent B2
US 12,574,373 · App. 16/862,957 · Granted Mar 10, 2026

Remotely configuring communication restrictions

Inventors: Reed E. Olsen (San Jose, CA); Todd R. Fernandez (Mountain View, CA); Jeffrey D. Harris (Berkeley, CA); Albert R. Howard (Sunnyvale, CA); Paul W. Salzman (Palo Alto, CA); Bryce D. Wolfson (San Jose, CA); Christopher G. Skogen (Los Altos Hills, CA); David A. Steinberg (San Francisco, CA); Nolan A. Astrein (San Francisco, CA)
Assignee: Apple Inc.
H04L63/0876H04L63/0428H04L63/102H04L63/108H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,373
App. No.
16/862,957
Granted
Mar 10, 2026
Kind
B2
Abstract

In some implementations, a controller device can implement communication restriction configurations on a managed device operated by a first user with a first account identifier, the configurations designed to limit a feature or functionality of the managed device. For example, the controller device can remotely cause the managed device to limit the communication capabilities of the first device. For example, the first device receives a message including the configuration. The managed device determines that the communication restriction configuration is created by a second user of the controller device. The first device identifies a second account identifier for the controller device. The first device determines that the second account identifier represents a member of a family group that includes the first account identifier. The managed device then automatically configures itself based on the first communication restriction configuration, including restricting access to one or more communication features of the managed device.

Claims (92)

1 . A method implemented by a management application on a managed device associated with a first account identifier corresponding to a first user, the method comprising:

receiving, at the managed device, a first message including a first communication restriction configuration for managing the managed device from a controller device, the first configuration defined by a second user of the controller device, the second user corresponding to a second user account, wherein the communication restriction configuration is encrypted such that only the controller device and the managed device can access the communication restriction configuration;

identifying, based on the first message, the second account identifier associated with the controller device;

determining that the second account identifier is a member of a trusted group of account identifiers that includes the first account identifier; and

in response to the determination, automatically configuring the managed device based on the first communication restriction configuration and a contacts database, including restricting access to one or more communication features of the managed device,

wherein configuring the managed device based on the first communication restriction configuration comprises restricting the first user from configuring the contacts database on the managed device,

wherein the contacts database defines account identifiers associated with user devices with which the managed device is allowed to communicate.

2 . The method of claim 1 , further comprising:

identifying that the first communication restriction configuration authorizes a first communication feature and deauthorizes a second communication feature;

allowing access to the first communication feature; and

preventing access to the second communication feature.

3 . The method of claim 2 , wherein the first communication feature corresponds to a first application installed on the managed device and the second communication feature corresponds to a second application installed on the managed device.

4 . The method of claim 2 , wherein the first communication feature corresponds to a first application feature of a first application installed on the managed device and the second communication feature corresponds to a second application feature of the first application.

5 . The method of claim 1 , further comprising:

receiving, at the managed device, a first communication from a third device associated with a third account identifier;

based on the first communication restriction configuration and the third account identifier, determining that the managed device is configured to prevent communication with the third device; and

suppressing the first communication with the third device.

6 . The method of claim 1 , further comprising:

determining that the first communication restriction configuration restricts communication with a third device associated with a third account identifier during a first time period;

detecting an active communication session involving the managed device and the third device; and

determining that a current time is within the first time period; and

terminating the active communication session with the third device.

7 . The method of claim 1 , further comprising:

receiving the first communication restriction configuration including a first communication restriction setting and a second communication restriction setting;

determining, by the managed device, an age of the first user of the managed device;

when the age is less than a threshold value, configuring the managed device based on the first communication restriction setting and the second communication restriction setting; and

when the age is greater than or equal to the threshold value, configuring the managed device based on the first communication restriction setting while disregarding the second communication restriction setting.

8 . The method of claim 1 , further comprising:

receiving, at the managed device, user input to add a new contact to the contacts database while access to the one or more communication features is restricted; and

responsive to the user input to add the new contact to the contacts database, displaying, by the managed device, a message denying addition of the new contact.

9 . A non-transitory computer readable medium storing a program for execution by at least one processor of a managed device associated with a first account identifier corresponding to a first user, the program comprising sets of instructions for:

receiving, at the managed device, a first message including a first communication restriction configuration for managing the managed device from a controller device, the first configuration defined by a second user of the controller device, the second user corresponding to a second user account, wherein the communication restriction configuration is encrypted such that only the controller device and the managed device can access the communication restriction configuration;

identifying, based on the first message, the second account identifier associated with the controller device;

determining that the second account identifier is a member of a trusted group of account identifiers that includes the first account identifier; and

in response to the determination, automatically configuring the managed device based on the first communication restriction configuration and a contacts database, including restricting access to one or more communication features of the managed device,

wherein configuring the managed device based on the first communication restriction configuration comprises restricting the first user from configuring the contacts database on the managed device,

wherein the contacts database defines account identifiers associated with user devices with which the managed device is allowed to communicate.

10 . The non-transitory computer readable medium of claim 9 , wherein the program further comprises sets of instructions for:

identifying that the first communication restriction configuration authorizes a first communication feature and deauthorizes a second communication feature;

allowing access to the first communication feature; and

preventing access to the second communication feature.

11 . The non-transitory computer readable medium of claim 10 , wherein the first communication feature corresponds to a first application installed on the managed device and the second communication feature corresponds to a second application installed on the managed device.

12 . The non-transitory computer readable medium of claim 10 , wherein the first communication feature corresponds to a first application feature of a first application installed on the managed device and the second communication feature corresponds to a second application feature of the first application.

13 . The non-transitory computer readable medium of claim 9 , wherein the program further comprises sets of instructions for:

receiving, at the managed device, a first communication from a third device associated with a third account identifier;

based on the first communication restriction configuration and the third account identifier, determining that the managed device is configured to prevent communication with the third device; and

suppressing the first communication with the third device.

14 . The non-transitory computer readable medium of claim 9 , wherein the program further comprises sets of instructions for:

determining that the first communication restriction configuration restricts communication with a third device associated with a third account identifier during a first time period;

detecting an active communication session involving the managed device and the third device; and

determining that a current time is within the first time period; and

terminating the active communication session with the third device.

15 . The non-transitory computer readable medium of claim 9 , wherein the program further comprises sets of instructions for:

receiving the first communication restriction configuration including a first communication restriction setting and a second communication restriction setting;

determining, by the managed device, an age of the first user of the managed device;

when the age is less than a threshold value, configuring the managed device based on the first communication restriction setting and the second communication restriction setting; and

when the age is greater than or equal to the threshold value, configuring the managed device based on the first communication restriction setting while disregarding the second communication restriction setting.

16 . The non-transitory computer readable medium of claim 9 , wherein the program further comprises sets of instructions for:

receiving, at the managed device, user input to add a new contact to the contacts database while access to the one or more communication features is restricted; and

responsive to the user input to add the new contact to the contacts database, displaying, by the managed device, a message denying addition of the new contact.

17 . A managed device comprising:

a set of processing units;

a non-transitory computer readable medium storing a program for execution by the set of processing units, the program comprising sets of instructions for:

receiving, at the managed device, a first message including a first communication restriction configuration for managing the managed device from a controller device, the first configuration defined by a second user of the controller device, the second user corresponding to a second user account, wherein the communication restriction configuration is encrypted such that only the controller device and the managed device can access the communication restriction configuration;

identifying, based on the first message, the second account identifier associated with the controller device;

determining that the second account identifier is a member of a trusted group of account identifiers that includes the first account identifier; and

in response to the determination, automatically configuring the managed device based on the first communication restriction configuration, including restricting access to one or more communication features of the managed device,

wherein configuring the managed device based on the first communication restriction configuration comprises restricting the first user from configuring a contacts database on the managed device, and

wherein the contacts database defines account identifiers associated with user devices with which the managed device is allowed to communicate.

18 . The device of claim 17 , wherein the program further comprises sets of instructions for:

identifying that the first communication restriction configuration authorizes a first communication feature and deauthorizes a second communication feature;

allowing access to the first communication feature; and

preventing access to the second communication feature.

19 . The device of claim 18 , wherein the first communication feature corresponds to a first application installed on the managed device and the second communication feature corresponds to a second application installed on the managed device.

20 . The device of claim 18 , wherein the first communication feature corresponds to a first application feature of a first application installed on the managed device and the second communication feature corresponds to a second application feature of the first application.

21 . The device of claim 17 , wherein the program further comprises sets of instructions for:

receiving, at the managed device, a first communication from a third device associated with a third account identifier;

based on the first communication restriction configuration and the third account identifier, determining that the managed device is configured to prevent communication with the third device; and

suppressing the first communication with the third device.

22 . The device of claim 17 , wherein the program further comprises sets of instructions for:

determining that the first communication restriction configuration restricts communication with a third device associated with a third account identifier during a first time period;

detecting an active communication session involving the managed device and the third device; and

determining that a current time is within the first time period; and

terminating the active communication session with the third device.

23 . The device of claim 17 , wherein the program further comprises sets of instructions for:

receiving the first communication restriction configuration including a first communication restriction setting and a second communication restriction setting;

determining, by the managed device, an age of the first user of the managed device;

when the age is less than a threshold value, configuring the managed device based on the first communication restriction setting and the second communication restriction setting; and

when the age is greater than or equal to the threshold value, configuring the managed device based on the first communication restriction setting while disregarding the second communication restriction setting.

24 . The device of claim 17 , wherein the program further comprises sets of instructions for:

receiving, at the managed device, user input to add a new contact to the contacts database while access to the one or more communication features is restricted; and

responsive to the user input to add the new contact to the contacts database, displaying, by the managed device, a message denying addition of the new contact.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2020
From: HOWARD, ALBERT R.; WOLFSON, BRYCE D.; SKOGEN, CHRISTOPHER G.; ASTREIN, NOLAN A.; SALZMAN, PAUL W.; OLSEN, REED E.; STEINBERG, DAVID A.; HARRIS, JEFFREY D.; FERNANDEZ, TODD R.
To: APPLE INC.
Reel/Frame 052539/0001 →
Continuity (3)
Provisional Application 62855737 · May 31, 2019
Provisional Application 62843938 · May 6, 2019
Related Publication 20200358765A1 · Nov 12, 2020
References Cited (6)
US 8611928B1 · Bill · 2013 [cited by examiner]
US 20110237221A1 · Prakash · 2011 [cited by examiner]
US 20130017806A1 · Sprigg · 2013 [cited by examiner]
US 20180048514A1 · Arunachalam · 2018 [cited by examiner]
US 20180337889A1 · Panchapakesan · 2018 [cited by examiner]
US 20210281481A1 · Richards · 2021 [cited by examiner]