IP Library Granted Patent US 10,158,531
Granted Patent B2
US 10,158,531 · App. 16/020,783 · Granted Dec 18, 2018

Leveraging and extending mobile operating system MDM protocol

Inventors: Tomas Vetrovsky (Mercer Island, WA); Pavel Zeman (Kirkland, WA); Thanhy Mather (Bellevue, WA)
Assignee: MOBILE IRON, INC.
H04L41/0893H04L41/28H04W4/50H04W12/04H04W12/06H04L63/0272H04L63/0281H04L67/04H04L67/1095H04W8/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,158,531
App. No.
16/020,783
Granted
Dec 18, 2018
Kind
B2
Abstract

In various embodiments, a device may include a communications interface configured to receive, from the device management server, an indication to perform an action that requires access to a privileged user space. The device may include a processor configured to use a bridge service to perform the action, where the bridge service runs in a security context that enables the service to operate in the privileged user space. In various embodiments, a server may include a communications interface and a processor. The processor may be configured to receive an indication to perform a management action not within a native device management functionality. The processor may be further configured to invoke a bridge service running on the managed device to perform the action by sending a request via the communications interface, where the bridge service runs in a security context that enables the service to operate in the privileged user space.

Claims (45)

1. A physical device comprising:

a communications interface configured to receive, from a device management server, an indication to perform an action that requires access to a privileged user space of the physical device; and

a processor configured to:

use a native device management service, wherein the native device management service is configured to perform only predefined functions; and

use a mobile device management (MDM) bridge service to perform the action, wherein the MDM bridge service runs in a security context that enables the service to operate in the privileged user space.

2. The device of claim 1 , wherein the MDM bridge service runs in a background on the device.

3. The device of claim 1 , wherein the MDM bridge service is configured to respond to commands from the device management server.

4. The device of claim 1 , wherein:

the MDM bridge service is configured to periodically check with the device management server for outstanding actions to perform; and

a status of an execution of outstanding actions is reported asynchronously to the device management server.

5. The device of claim 4 , wherein the MDM bridge service is configured to:

detect a session between a native device management service and the device management server; and

initiate a session of the MDM bridge service in response to the detected session between the native device management service and the device management server.

6. The device of claim 1 , wherein the processor is further configured to:

send a request to register the device;

receive, in response to the request, an installer for the MDM bridge service; and

automatically install the MDM bridge service.

7. The device of claim 6 , wherein the installer is one of an MSI installer and a Win 32 installer.

8. The device of claim 1 , wherein the processor is further configured to perform functions selected by a user of the device.

9. The device of claim 1 , wherein the MDM bridge service is configured to control a file system of the device.

10. The device of claim 1 , wherein the MDM bridge service is configured to control a registry of the device.

11. The device of claim 1 , wherein the MDM bridge service is configured to execute a script on the device.

12. The device of claim 1 , wherein the MDM bridge service is configured to control at least one of a configuration specification and a policy specification.

13. The device of claim 1 , wherein the MDM bridge service is configured to install an application including associating the application with an uninstall script configured to automatically remove the application and all associated data when the application is uninstalled.

14. The device of claim 1 , wherein the MDM bridge service is configured to provide a predefined number of encryption keys.

15. The device of claim 1 , wherein communications between the MDM bridge service and the device management server are authenticated.

16. The device of claim 1 , wherein the MDM bridge service is headless.

17. The device of claim 1 , wherein the privileged user space includes at least one of: a registry, a file system, and scripts.

18. A physical device comprising:

a communications interface configured to receive, from a device management server, an indication to perform an action that requires access to a privileged user space of the physical device; and

a processor configured to use a mobile device management (MDM) bridge service to perform the action including by invoking a native device management service to perform those functions associated with the action that are predefined and performing, by the bridge service those functions associated with the action that are not predefined, wherein the MDM bridge service runs in a security context that enables the service to operate in the privileged user space.

19. The device of claim 18 , wherein:

the MDM bridge service is configured to periodically check with the device management server for outstanding actions to perform; and

a status of an execution of outstanding actions is reported asynchronously to the device management server.

20. A method comprising:

receiving, from a device management server, an indication to perform an action that requires access to a privileged user space of a physical device;

using a native device management service, wherein the native device management service is configured to perform only predefined functions; and

using a mobile device management (MDM) bridge service to perform the action, wherein the MDM bridge service runs in a security context that enables the service to operate in the privileged user space.

21. The method of claim 20 , wherein:

the MDM bridge service is configured to periodically check with the device management server for outstanding actions to perform; and

a status of an execution of outstanding actions is reported asynchronously to the device management server.

22. The method of claim 20 , wherein the MDM bridge service is configured to:

detect a session between a native device management service and the device management server; and

initiate a session of the MDM bridge service in response to the detected session between the native device management service and the device management server.

23. The method of claim 20 , wherein the MDM bridge service is configured to install an application including associating the application with an uninstall script configured to automatically remove the application and all associated data when the application is uninstalled.

Assignments (7)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 2, 2025
From: IVANTI, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071164/0482 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2022
From: MOBILEIRON, INC.
To: IVANTI, INC.
Reel/Frame 061327/0751 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
Continuity (3)
Continuation 15604091 · May 24, 2017
Provisional Application 62351430 · Jun 17, 2016
Related Publication 20180316565A1 · Nov 1, 2018