USPatent applicationPatented

Location and time based mobile app policies

Granted 23 Aug 2016 · 2 office actions

Application· this page
14/137,853
filed 20 Dec 2013
Publication
Not published
not published
Patent
US 9,426,120
granted 23 Aug 2016

Life of the application

20 dated events
⤢ drag to zoom20142016201820202022202420262028203020322034ProsecutionOwnershipDisputesTerm & fees
ProsecutionOwnershipDisputesTerm & feeshover for detail · click to open

Abstract

Location and time based mobile app policies are disclosed. One or more location and time policies are received at a management agent on a device. The policies are calculated by processing user and group information. Policy information in a bus is updated with a current allowed state. Location information is received from the device. The location information includes a new location that is not an allowed location. A use of an application may be blocked by the management agent based at least in part on the received location information.

Description

4 parts
›CROSS REFERENCE TO OTHER APPLICATIONS

This application claims priority to U.S. Provisional Patent Application No. 61/745,487 entitled LOCATION AND TIME BASED MOBILE APP POLICIES filed Dec. 21, 2012 which is incorporated herein by reference for all purposes.

›BACKGROUND OF THE INVENTION

Today many enterprises are building multiple enterprise apps, for example, Patient information app, Factory automation app, ERP, CRM, Factory automation to reserving conference rooms. Some of those apps have to be allowed or disallowed in certain situations.

›BRIEF DESCRIPTION OF THE DRAWINGS

FIG. 1 is a table including apps that may be installed on a mobile device according to various embodiments.

FIG. 2 is a block diagram illustrating a system including location and time based app policies according to various embodiments.

›DETAILED DESCRIPTION

Techniques to provide an Enterprise zone which will be aware of device location and time/day before authorizing app launching are disclosed.

Some apps have to be allowed or disallowed (i.e., their use prevented) while devices are physically in certain location (for example, allow certain apps to run only when devices are in hospital building or factory building) or certain time schedule (for example, allow use between 8 am to 5 pm).

In summary, location and time awareness are provided in a mobile device enterprise zone. The enterprise zone is a zone within which a degree of control or management is provided over apps, and apps not in the zone are not able to communicate with or access data of apps in the zone. In some embodiments, the enterprise zone provides the ability to allow or disallow information to apps which have had an enterprise zone library embedded into them, e.g, using a software developer kit (SDK) or other tool.

User authentication, authorization, and lock zone code (enterprise zone library) added to apps developed for the Zone. For each session authentication will validate the user's credential with the enterprise authentication and store an authentication cookie with expiration based on authentication policy. After authentication, list of authorized apps will be updated. Lock zone is to lock the zone apps, so user can share the device with other employees, customers, family members and friends. The user can unlock the zone with the zone passcode and continue previous enterprise zone session.

VSP stands for Virtual Smartphone Platform by MobileIron. In some embodiments, VSP is used to provide and/or configure an enterprise zone as described herein. All managed mobile devices' configuration, policies and apps are managed from here. MobileIron clients connect to VSP on a periodic basis to update the device status as well as get the new configuration and policies.

FIG. 1 is a table including apps that may be installed on a mobile device according to various embodiments.

FIG. 2 is a block diagram illustrating a system including location and time based app policies according to various embodiments.

(1) Enterprise IT administrator configure enterprise policies (Location, Time schedule, and device posture) to VSP. For example, {app=ERP, allowLocation={wifi=[{ssid=hospital, bssid=001c.0ed1.ac80} ], cellular=[{mnc=123,mcc=123}],latlong=[{lat=1.1,long=2.2,radius=2}]}, disallowLocation=={wifi=[{ssid=hospital, bssid=001c.0ed1.ac80}], cellular=[{mnc=123,mcc=123}],latlong=[{lat=1.1,long=2.2,radius=2} ]} }

(2) VSP will calculate applicable policies to each device by processing user and group relationship in enterprise directory.

(3) Management Agent will receive this location and time based policies

For example, {app=ERP,allowLocation={wifi=[{ssidhash=abcd123, bssidhash=cdef1234}], cellularhash=[{mncmcc=fda123}],latlong=[{lat=1.1,long=2.2,radius=2}]} }

(4) Management Agent will update policies information in AppConnect Bus with current allowed state. AppConnect Bus in various embodiments provides secure communication between apps within the enterprise zone; e.g., via encrypted content shared via a pasteboard or other mechanism. For example, if device is currently connected with wifi ssid hospital with bssid 001c.0ed1.ac80, ERP app will be allowed to authorized app list. {Zone={authenticationExpire=1343071545, AuthorizedApps=[{appid=company.files.Se,locationPolicy=1}, {appid=company.browser.Be,locationPolicy=2}, {appid=company.SFA.Ae,locationPolicy2}, {appid=company.viewer.De, location policy=3}, {appid=company.ERP.Ee, LocationPolicy=1], zoneLock=false}, LocationPolicy={1={wifi=[{ssidhash=abcd123, bssidhash=cdef1234}]}}}

(5) User can use ERP app. Enterprise zone library in ERP app will receive location change from device.

(6) When user moved to new location where location is not in allowLocation, Enterprise Zone library will forward user to Management agent and Management agent will block the user from using the app and inform the user appropriately

Location information will be gathered by the management agent either from the operating system or an app that can determine the location (app could be part of AppConnect bus or outside AppConnect bus)

Claims as granted

17 claims

Log in to read the claims of this application.

Log in to unlock

Classifications

4 codes
IPC · International Patent Classification
Section G — Physics
  • G06F17/00
Section H — Electricity
  • H04L29/06
  • H04W4/029
  • H04W4/02

Claim changes

Soon
Coming soonHow the claims changed between publication and grant

See which claims were amended, added or cancelled during examination, with every added and removed word marked.

AmendedAddedCancelledUnchanged

The published claims of this application are not paired with the granted ones in what we hold.

File wrapper

⤢ drag to zoomJan 2014Jul 2014Jan 2015Jul 2015Jan 2016Jul 2016USPTOApplicantNon-final rejectionResponse after non-finalFinal rejectionRequest for continued examination
USPTOApplicanthover for detail · click to open
Pendency
2.7 y
977 days filing → grant
Office actions
2
non-final + final
Responses
1
1 RCE
Examiner
Mohammad W Reza
art unit 2436 · TC 2400
Citations: 8 back · 3 forward

See the full prosecution history — every USPTO and applicant action on this file, in order.

Log in to unlock

Documents

Log in to open the documents of this file: the application as filed, every office action and response, the notice of allowance.

Log in to unlock

Chain of title

⤢ drag to zoom20142016201820202022202420262028203020322034Owner 1Owner 2liens, releases & corrections
TitleLienhover for detail · click to open

See the full assignment history — every owner this patent has passed through, with recordation dates and reel/frame numbers.

Log in to unlock