IP Library Granted Patent US 9,848,001
Granted Patent B2
US 9,848,001 · App. 14/929,103 · Granted Dec 19, 2017

Secure access to mobile applications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,848,001
App. No.
14/929,103
Granted
Dec 19, 2017
Kind
B2
Abstract

Securing access to one or more applications in an enterprise zone (e.g., a set of protected applications) is disclosed. A last activity time associated with a use of at least one mobile application in the protected subset may be retrieved from a shared storage location associated with a protected subset of two or more protected mobile applications. It may be determined that the last activity time is within a session expiration time period associated with the protected subset. Access to one or more applications in the protected subset may be allowed without credential verification based at least in part on the determination.

Claims (61)

1. A method, comprising:

retrieving, from a shared storage location on a mobile device, a last activity time associated with a use of a first mobile application in a protected subset of two or more protected mobile applications, wherein a library associated with a second mobile application is configured to retrieve from the shared storage location on the mobile device the last activity time associated with the use of the first mobile application, wherein the library associated with the second mobile application is configured to modify code of the second mobile application to behave differently than an unmodified version of the code, wherein the shared storage location is accessible to the protected subset of two or more protected mobile applications and is not accessible to at least one application not in the protected subset;

determining that the last activity time is within a session expiration time period associated with the protected subset; and

allowing, by the library associated with the second mobile application, access to the second mobile application in the protected subset based at least in part on the determination.

2. The method of claim 1 , further comprising:

determining that the second mobile application is associated with the protected subset of protected mobile applications.

3. The method of claim 1 , further comprising writing the last activity time to the shared storage location upon an occurrence of a triggering event.

4. The method of claim 1 , wherein said steps of retrieving, determining, and allowing are performed at least in part in response to a request to access the second mobile application.

5. The method of claim 1 , wherein determining that the last activity time is within a session expiration time period comprises determining that a difference between a current time and the last activity time is less than the session expiration period.

6. The method of claim 1 , further comprising:

receiving, at a second time after the allowed access to the one or more mobile applications, a request to access an application in the protected subset; and

determining that a difference between the second time and the last activity time is within the session expiration time period.

7. The method of claim 1 , further comprising:

determining that a difference between a current time and the last activity time exceeds the session expiration time period; and

providing an indicator to a management agent associated with the protected subset of mobile applications.

8. The method of claim 7 , further comprising:

outputting, by the management agent, a request for user credentials;

receiving credentials based at least in part on the request;

determining that the received credentials match a stored credential; and

allowing access to mobile applications in the protected subset based at least in part on the determined match.

9. The method of claim 8 , wherein allowing access includes:

providing, to the shared storage location, authorization information and authentication information; and

launching an application in the protected subset based at least in part on a validation of the authorization information and authentication information.

10. The method of claim 7 , further comprising:

outputting, by the management agent, a request for user credentials;

receiving credentials based at least in part on the request;

determining that the received credentials do not match stored credentials; and

denying access to each application in the protected subset based at least in part on the determination that the received credentials do not match stored credentials.

11. The method of claim 1 , further comprising:

receiving a request to restrict access to the protected subset of the protected mobile applications; and

blocking access to the protected subset of protected mobile applications.

12. A system, comprising:

a memory or other storage device; and

a processor coupled to the memory or other storage device and configured to:

retrieve, from a shared storage location on the memory or other storage device, a last activity time associated with a use of a first mobile application in a protected subset of two or more protected mobile applications, wherein a library associated with a second mobile application is configured to retrieve from the shared storage location on the mobile device the last activity time associated with the use of the first mobile application, wherein the library associated with the second mobile application is configured to modify code of the second mobile application to behave differently than an unmodified version of the code, wherein the shared storage location is accessible to the protected subset of two or more protected mobile applications and is not accessible to at least one application not in the protected subset;

determine that the last activity time is within a session expiration time period associated with the protected subset; and

allow, by the library associated with the second mobile application, access to the second mobile application in the protected subset without credential verification based at least in part on the determination.

13. The system recited in claim 12 , wherein the processor is further configured to determine that the second mobile application is associated with the protected subset of protected mobile applications.

14. The system recited in claim 12 , wherein the processor is further configured to determine that a difference between a current time and the last activity time exceeds the session expiration time period; and

provide an indicator to a management agent associated with the protected subset of mobile applications.

15. The system recited in claim 14 , wherein the processor is further configured to:

output, by the management agent, a request for user credentials;

receive credentials based at least in part on the request;

determine that the received credentials match a stored credential; and

allow access to the mobile applications in the protected subset based at least in part on the determined match.

16. The system recited in claim 14 , wherein the processor is further configured to:

output, by the management agent, a request for user credentials;

receive credentials based at least in part on the request;

determine that the received credentials do not match stored credentials; and

deny access to each application in the protected subset based at least in part on the determination that the received credentials do not match stored credentials.

17. A computer program product, the computer program product being embodied in a tangible non-transitory computer readable storage medium and comprising computer instructions, which when executed cause a computer to perform steps of:

retrieving, from a shared storage location on a mobile device, a last activity time associated with a use of a first mobile application in a protected subset of two or more protected mobile applications, wherein a library associated with a second mobile application is configured to retrieve from the shared storage location on the mobile device the last activity time associated with the use of the first mobile application, wherein the library associated with the second mobile application is configured to modify code of the second mobile application to behave differently than an unmodified version of the code, wherein the shared storage location is accessible to the protected subset of two or more protected mobile applications and is not accessible to at least one application not in the protected subset;

determining that the last activity time is within a session expiration time period associated with the protected subset; and

allowing, by the library associated with the second mobile application, access to the second mobile application in the protected subset based at least in part on the determination.

18. The computer program product recited in claim 17 , further comprising computer instructions for:

determining that a difference between a current time and the last activity time exceeds the session expiration time period; and

providing an indicator to a management agent associated with the protected subset of mobile applications.

19. The computer program product recited in claim 17 , further comprising computer instructions for:

receiving, at a time after the allowed access, a request to access an application in the protected subset; and

determining that a difference between the access time and the last activity time is within the session expiration time period.

20. The computer program product recited in claim 17 , wherein determining that the last activity time is within a session expiration time period comprises determining that a difference between a current time and the last activity time is less than the session expiration period.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →