IP Library Granted Patent US 10,114,932
Granted Patent B2
US 10,114,932 · App. 15/221,066 · Granted Oct 30, 2018

Adapting a mobile application to a partitioned environment

Inventors: Eric M. Marion (San Francisco, CA); Nitin Sonawane (Littleton, MA)
Assignee: MOBILE IRON, INC.
G06F21/121G06F8/61G06F21/53G06F9/45533G06F2221/0704G06F2221/2105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,114,932
App. No.
15/221,066
Granted
Oct 30, 2018
Kind
B2
Abstract

Adapting a mobile or other application (“app”) to a partitioned environment is disclosed. In various embodiments, a “secure zone” or other logical partition is created and enforced at least in part by adapting a mobile or other app to behave in a manner required by and/or otherwise associated with the secure zone or other partition and which behavior is or in various embodiments may be different than a native behavior of the mobile or other app as designed and written by an application developer of the app.

Claims (34)

1. A method of providing a secure partition, comprising:

receiving an indication that a first app is to be available to be used in a secure zone of a mobile device, wherein the indication comprises an attempt to install the first app to the secure zone, wherein the secure zone includes versions of one or more applications that exhibit a behavior associated with the secure zone;

determining that the first app is an unknown application and is not authorized to be installed in the secure zone; and

in response to the determination, modifying the first app to be an app that will not launch within the secure zone, wherein modifying the first app to be the app that will not launch within the secure zone includes changing a launcher component of the first app to be a launcher component that will not allow the app to launch; and

installing the modified first app, wherein the modified first app is a secure zone version of the first app.

2. The method of claim 1 , wherein the secure zone version of the first app exhibits the behavior associated with the secure zone at least in part by invoking a replacement operating system component instead of a corresponding operating system component that the original version of the first app was configured to invoke.

3. The method of claim 1 , wherein the secure zone version of the first app is generated at least in part by modifying or replacing one or more classes included in the first app.

4. The method of claim 3 , wherein the secure zone version of the first app is generated at least in part by modifying one or more pointers included in the first app to point to said modified or replacement classes.

5. The method of claim 1 , wherein the behavior associated with the secure zone includes storing app data in encrypted form.

6. The method of claim 1 , wherein the behavior associated with the secure zone includes performing network communication via a virtual private network or other secure connection.

7. The method of claim 1 , wherein the behavior associated with the secure zone includes storing cut or copied app data in a replacement clipboard component.

8. The method of claim 7 , wherein the replacement clipboard component is configured to provide access to content only to the one or more applications associated with the secure zone.

9. The method of claim 1 , further comprising receiving a password associated with the secure zone and allowing access to the one or more applications associated with the secure zone, without requiring reentry of the password when a user switches from using one of the one or more applications in the secure zone to using another of the one or more applications in the secure zone.

10. The method of claim 9 , further comprising requiring password reentry if a no activity timer associated with the secure zone has expired.

11. The method of claim 1 , wherein a secure zone version of an application of the one or more applications is configured to make app content available to one or more of the other applications associated with the secure zone at least in part by invoking an agent to back up the app content to a shared storage location.

12. The method of claim 11 , wherein the one or more applications are configured to access the app content at least in part by invoking the agent to recover the app content from the shared storage location.

13. The method of claim 1 , further comprising providing one or more replacement operating system components configured to hide one or more resources from the one or more applications associated with the secure zone.

14. The method of claim 13 , wherein the one or more resources include one or more of the following: a set of contacts, an address book, a camera, a non-secure network connection, an unencrypted file.

15. The method of claim 1 , wherein the secure zone version of the first app is generated at least in part by analyzing execution of the first app in a controlled test environment to observe one or more behaviors of the first app that are to be modified.

16. The method of claim 1 , wherein the one or more applications executed in the secure zone store corresponding content data in a secure zone app data storage that is accessible to the plurality of apps in the secure zone.

17. The method of claim 1 , wherein the secure zone version of the first app is generated at least in part by sending a request to a remote compliance server.

18. The method of claim 17 , wherein the remote compliance server is configured to generate the secure zone version of the first app.

19. A system for providing a secure partition, comprising:

a processor configured to:

receive an indication that a first app is to be available to be used in a secure zone of a mobile device, wherein the indication comprises an attempt to install the first app to the secure zone;

determine that the first app is an unknown application and not authorized to be installed in the secure zone;

in response to the determination, modify the first app to be an app that will not launch within the secure zone, wherein to modify the first app to be the app that will not launch within the secure zone includes changing a launcher component of the first app to be a launcher component that will not allow the app to launch; and

installing the modified first app; and

a memory coupled to the processor and configured to provide the processor with instructions.

20. A computer program product to provide a secure partition, the computer program product being embodied in a tangible, non-transitory computer readable storage medium and comprising computer instructions for:

receiving an indication that a first app is to be available to be used in a secure zone of a mobile device, wherein the indication comprises an attempt to install the first app to the secure zone;

determining that the first app is unknown and not authorized to be installed in the secure zone;

in response to the determination modifying the first app to be an app that will not launch within the secure zone, wherein modifying the first app to be the app that will not launch within the secure zone includes changing a launcher component of the first app to be a launcher component that will not allow the app to launch; and

installing the modified first app.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
Continuity (3)
Continuation 13669082 · Nov 5, 2012
Provisional Application 61555183 · Nov 3, 2011
Related Publication 20170011206A1 · Jan 12, 2017
Cited By (1)
US 12,411,990