IP Library Granted Patent US 10,038,598
Granted Patent B2
US 10,038,598 · App. 15/604,091 · Granted Jul 31, 2018

Leveraging and extending mobile operating system MDM protocol

Inventors: Tomas Vetrovsky (Mercer Island, WA); Pavel Zeman (Kirkland, WA); Thanhy Mather (Bellevue, WA)
Assignee: MOBILE IRON, INC.
H04L41/0893H04L41/28H04W4/50H04L63/0272H04L67/04H04L67/1095H04W8/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,038,598
App. No.
15/604,091
Granted
Jul 31, 2018
Kind
B2
Abstract

In various embodiments, a device may include a communications interface configured to receive, from the device management server, an indication to perform an action that requires access to a privileged user space. The device may include a processor configured to use a bridge service to perform the action, where the bridge service runs in a security context that enables the service to operate in the privileged user space. In various embodiments, a server may include a communications interface and a processor. The processor may be configured to receive an indication to perform a management action not within a native device management functionality. The processor may be further configured to invoke a bridge service running on the managed device to perform the action by sending a request via the communications interface, where the bridge service runs in a security context that enables the service to operate in the privileged user space.

Claims (44)

1. A physical device comprising:

a communications interface configured to receive, from a device management server, an indication to perform an action that requires access to a privileged user space of the physical device; and

a processor configured to:

use a native device management service, wherein the native device management service is configured to perform only predefined functions without access to the privileged user space; and

use a mobile device management (MDM) bridge service to perform the action, wherein the MDM bridge service runs in a security context that enables the service to operate in the privileged user space.

2. The device of claim 1 , wherein the MDM bridge service runs in a background on the device.

3. The device of claim 1 , wherein the MDM bridge service is configured to respond to commands from the device management server.

4. The device of claim 1 , wherein:

the MDM bridge service is configured to periodically check with the device management server for outstanding actions to perform; and

a status of an execution of outstanding actions is reported asynchronously to the device management server.

5. The device of claim 4 , wherein the MDM bridge service is configured to:

detect a session between a native device management service and the device management server; and

initiate a session of the MDM bridge service in response to the detected session between the native device management service and the device management server.

6. The device of claim 1 , wherein the processor is further configured to:

send a request to register the device;

receive, in response to the request, an installer for the MDM bridge service; and

automatically install the MDM bridge service.

7. The device of claim 6 , wherein the installer is one of an MSI installer and a Win 32 installer.

8. The device of claim 1 , wherein the processor is further configured to perform functions selected by a user of the device.

9. The device of claim 1 , wherein the MDM bridge service is configured to control a file system of the device.

10. The device of claim 1 , wherein the MDM bridge service is configured to control a registry of the device.

11. The device of claim 1 , wherein the MDM bridge service is configured to execute a script on the device.

12. The device of claim 1 , wherein the MDM bridge service is configured to control at least one of a configuration specification and a policy specification.

13. The device of claim 1 , wherein the MDM bridge service is configured to install an application including associating the application with an uninstall script configured to automatically remove the application and all associated data when the application is uninstalled.

14. The device of claim 1 , wherein the MDM bridge service is configured to provide a predefined number of encryption keys.

15. The device of claim 1 , wherein communications between the MDM bridge service and the device management server are authenticated.

16. The device of claim 1 , wherein the MDM bridge service is headless.

17. The device of claim 1 , wherein the privileged user space includes at least one of: a registry, a file system, and scripts.

18. A method comprising:

receiving, from a device management server, an indication to perform an action that requires access to a privileged user space of a physical device;

using a native device management service, wherein the native device management service is configured to perform only predefined functions without access to the privileged user space; and

using a mobile device management (MDM) bridge service to perform the action, wherein the MDM bridge service runs in a security context that enables the service to operate in the privileged user space.

19. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, from a device management server, an indication to perform an action that requires access to a privileged user space of a physical device;

using a native device management service, wherein the native device management service is configured to perform only predefined functions without access to the privileged user space; and

using a mobile device management (MDM) bridge service to perform the action, wherein the MDM bridge service runs in a security context that enables the service to operate in the privileged user space.

20. A server comprising:

a communications interface;

a processor coupled to the communications interface, the processor configured to:

receive, via an administrative user interface, an indication to perform with respect to a managed physical device, a management action not within a native device management functionality of the managed physical device; and

invoke a mobile device management (MDM) bridge service running on the managed device to perform the action by sending a request via the communications interface, wherein the MDM bridge service runs in a security context that enables the service to operate in a privileged user space.

21. The server of claim 20 , wherein:

the administrative user interface exposes a set of management actions, wherein some of the management actions are native and some of the management actions are not native.

22. The server of claim 20 , wherein the bridge service is invoked based on a determination that the MDM bridge service is to be used and the native device management functionality is used based on a determination that the MDM bridge service is not to be used.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2018
From: VETROVSKY, TOMAS; ZEMAN, PAVEL; MATHER, THANHY
To: MOBILE IRON, INC.
Reel/Frame 045696/0372 →
Continuity (2)
Provisional Application 62351430 · Jun 17, 2016
Related Publication 20170366402A1 · Dec 21, 2017