IP Library Granted Patent US 12,271,493
Granted Patent B2
US 12,271,493 · App. 18/165,995 · Granted Apr 8, 2025

Controlling access to application data

Inventors: Sean Michael Quinlan (Duvall, WA); Haniff Somani (Mercer Island, WA); Sanjiv Maurya (Fremont, CA); Peter Barker (Flower Mound, TX); Siavash James Joorabchian Hawkins (Maidenhead, GB)
Assignee: Malikie Innovations Limited
G06F21/6209G06F3/0622G06F3/0637G06F3/0673G06F21/602G06F21/6218G06F2221/2113G06F2221/2147
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,271,493
App. No.
18/165,995
Granted
Apr 8, 2025
Kind
B2
Abstract

A method, system and computer-readable storage medium for controlling access to application data associated with an application configured on a computing device. The method comprises: storing data comprising, for each of a plurality of access levels associated with the application, first data indicative of a combination of one or more credentials associated with the respective access level and an access level key corresponding to the respective access level, the access level key being encrypted by the combination of one or more credentials associated with the respective access level; determining, based on the first data, an access level in the plurality of access levels corresponding to a combination of one or more credentials available to the application; decrypting the access level key in the stored data corresponding to the determined access level using the combination of one or more credentials available to the application; and providing access to encrypted application data associated with the application and corresponding to the determined access level using, at least in part, the decrypted access level key corresponding to the determined access level.

Claims (67)

1. A method, comprising:

generating, by an application runtime of an application having a current authentication state, application data, wherein:

the application defines a plurality of data categories for data in the application data,

the application data includes a plurality of containers into which the application data is segregated and securely stored in encrypted format to prevent unauthorized access, and

the current authentication state is associated with one or more credentials that are currently available to the application runtime;

requesting, by the application runtime, access to data associated with a particular one of the plurality of data categories;

determining, by the application runtime, whether the current authentication state includes a credential combination corresponding to the particular one of the plurality of data categories;

in response to determining that the current authentication state includes the credential combination corresponding to the particular one of the plurality of data categories, obtaining, by the application runtime, an access level key corresponding to one access level of a plurality of access levels associated with the current authentication state, wherein the access level key is encrypted by one or more credentials associated with the one access level;

decrypting, by the application runtime, an encrypted container key corresponding to the one access level by using the access level key;

decrypting, by the application runtime, application data stored in a particular one of the plurality of containers by using the decrypted container key; and

providing access to the decrypted application data in the particular one of the plurality of containers.

2. The method of claim 1 , further comprising:

obtaining one or more subordinate access level keys corresponding to one or more access levels that are subordinate to the one access level;

decrypting one or more encrypted subordinate container keys corresponding to the one or more subordinate access level keys; and

decrypting subordinate application data stored in one or more subordinate containers by using the one or more decrypted subordinate container keys.

3. The method of claim 1 , wherein the obtaining the access level key comprises:

receiving one or more credentials available to the application;

determining the one access level in the plurality of access levels based on the received one or more credentials available to the application; and

decrypting the access level key corresponding to the one access level by using the received one or more credentials available to the application.

4. The method of claim 1 , further comprising:

storing information along with the access level key, the information indicating a credential type for each of the one or more credentials that is used to encrypt the access level key.

5. The method of claim 4 , wherein the information comprises credential meta-data associated with the access level and the credential type.

6. A device, comprising:

at least one hardware processor; and

a non-transitory computer-readable storage medium coupled to the at least one hardware processor and storing programming instructions for execution by the at least one hardware processor, wherein the programming instructions, when executed, cause the at least one hardware processor to perform operations comprising:

generating application data using an application runtime of an application having a current authentication state, wherein:

the application defines a plurality of data categories for data in the application data,

the application data includes a plurality of containers into which the application data is segregated and securely stored in encrypted format to prevent unauthorized access, and

the current authentication state is associated with one or more credentials that are currently available to the application runtime;

requesting access to data associated with a particular one of the plurality of data categories;

determining whether the current authentication state includes a credential combination corresponding to the particular one of the plurality of data categories;

in response to determining that the current authentication state includes the credential combination corresponding to the particular one of the plurality of data categories, obtaining an access level key corresponding to one access level of a plurality of access levels associated with the current authentication state, wherein the access level key is encrypted by one or more credentials associated with the one access level;

decrypting an encrypted container key corresponding to the one access level by using the access level key;

decrypting application data stored in a particular one of the plurality of containers by using the decrypted container key; and

providing access to the decrypted application data in the particular one of the plurality of containers.

7. The device of claim 6 , the operations further comprising:

obtaining one or more subordinate access level keys corresponding to one or more access levels that are subordinate to the one access level;

decrypting one or more encrypted subordinate container keys corresponding to the one or more subordinate access level keys; and

decrypting subordinate application data stored in one or more subordinate containers by using the one or more decrypted subordinate container keys.

8. The device of claim 6 , wherein the obtaining the access level key comprises:

receiving one or more credentials available to the application;

determining the one access level in the plurality of access levels based on the received one or more credentials available to the application; and

decrypting the access level key corresponding to the one access level by using the received one or more credentials available to the application.

9. The device of claim 6 , wherein the operations performed by the at least one hardware processor further comprise:

storing information along with the access level key, the information indicating a credential type for each of the one or more credentials that is used to encrypt the access level key.

10. The device of claim 9 , wherein the information comprises credential meta-data associated with the access level and the credential type.

11. A non-transitory computer-readable medium storing instructions which, when executed, cause a computing device to perform operations comprising:

generating application data using an application runtime of an application having a current authentication state, wherein:

the application defines a plurality of data categories for data in the application data,

the application data includes a plurality of containers into which the application data is segregated and securely stored in encrypted format to prevent unauthorized access, and

the current authentication state is associated with one or more credentials that are currently available to the application runtime;

requesting access to data associated with a particular one of the plurality of data categories;

determining whether the current authentication state includes a credential combination corresponding to the particular one of the plurality of data categories;

in response to determining that the current authentication state includes the credential combination corresponding to the particular one of the plurality of data categories, obtaining an access level key corresponding to one access level of a plurality of access levels associated with the current authentication state, wherein the access level key is encrypted by one or more credentials associated with the one access level;

decrypting an encrypted container key corresponding to the one access level by using the access level key;

decrypting application data stored in a particular one of the plurality of containers by using the decrypted container key; and

providing access to the decrypted application data in the particular one of the plurality of containers.

12. The non-transitory computer-readable medium of claim 11 , wherein the operations performed by the computing device further comprise:

obtaining one or more subordinate access level keys corresponding to one or more access levels that are subordinate to the one access level;

decrypting one or more encrypted subordinate container keys corresponding to the one or more subordinate access level keys; and

decrypting subordinate application data stored in one or more subordinate containers by using the one or more decrypted subordinate container keys.

13. The non-transitory computer-readable medium of claim 11 , wherein the obtaining the access level key comprises:

receiving one or more credentials available to the application;

determining the one access level in the plurality of access levels based on the received one or more credentials available to the application; and

decrypting the access level key corresponding to the one access level by using the received one or more credentials available to the application.

14. The non-transitory computer-readable medium of claim 11 , wherein the operations performed by the computing device further comprise:

storing information along with the access level key, the information indicating a credential type for each of the one or more credentials that is used to encrypt the access level key.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: QUINLAN, SEAN MICHAEL; SOMANI, HANIFF; MAURYA, SANJIV; BARKER, PETER; HAWKINS, SIAVASH JAMES JOORABCHIAN
To: GOOD TECHNOLOGY CORPORATION
Reel/Frame 062660/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: GOOD TECHNOLOGY CORPORATION
To: GOOD TECHNOLOGY HOLDINGS LIMITED
Reel/Frame 062701/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: GOOD TECHNOLOGY HOLDINGS LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 062701/0200 →
Continuity (4)
Continuation 16926361 · Jul 10, 2020
Continuation 16055674 · Aug 6, 2018
Continuation 15093183 · Apr 7, 2016
Related Publication 20230185937A1 · Jun 15, 2023
References Cited (29)
US 7546300B2 · Chisholm et al. · 2009 [cited by applicant]
US 7934249B2 · Chan et al. · 2011 [cited by applicant]
US 8863303B2 · Robert · 2014 [cited by applicant]
US 9509664B2 · Zuerner · 2016 [cited by applicant]
US 9690538B1 · Doyle et al. · 2017 [cited by applicant]
US 10043021B2 · Quinlan et al. · 2018 [cited by applicant]
US 10075450B2 · Bush et al. · 2018 [cited by applicant]
US 10733310B2 · Quinlan et al. · 2020 [cited by applicant]
US 11610014B2 · Quinlan · 2023 [cited by examiner]
US 20060112423A1 · Villadiego et al. · 2006 [cited by applicant]
US 20110178930A1 · Scheidt et al. · 2011 [cited by applicant]
US 20110252234A1 · De Atley et al. · 2011 [cited by applicant]
US 20150281239A1 · Brophy · 2015 [cited by applicant]
US 20170293769A1 · Quinlan et al. · 2017 [cited by applicant]
US 20180373886A1 · Quinlan et al. · 2018 [cited by applicant]
US 20200342130A1 · Quinlan et al. · 2020 [cited by applicant]
CN 104641591A · 2015 [cited by applicant]
WO WO2014052069 · 2014 [cited by applicant]
Extended European Search Report in European Appln. No. 17163976.8, dated Aug. 16, 2017, 8 pages. [cited by applicant]
Communication Pursuant to Article 94(3) EPC in European Appln. No. 17163976.8, dated May 29, 2019, 6 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 15/093,183, dated Sep. 29, 2017, 18 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 15/093,183, dated Jan. 12, 2018, 11 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 15/093,183, dated Apr. 9, 2018, 7 pages. [cited by applicant]
Final Office Action in U.S. Appl. No. 16/055,674, dated Jan. 29, 2020, 11 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 16/055,674, dated Oct. 11, 2019, 18 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 16/926,361, dated Jul. 20, 2022, 11 pages. [cited by applicant]
Notice of Allowance in U.S. Appl. No. 16/926,361, dated Nov. 16, 2022, 8 pages. [cited by applicant]
Office Action in Chinese Appln. No. 201710222397.2, dated Nov. 18, 2022, 23 pages (with English Translation). [cited by applicant]
Wang, et al., “Supervising Secret-key Agreements in a Level-based Hierarchy”, 18th International Conference on Advanced Information Networking and Applications, 2004. [cited by applicant]
Cited By (1)
US 12,683,939