Enterprise managed systems with collaborative application support
US-9424554-B2 · Aug 23, 2016 · US
US2016277387A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016277387-A1 |
| Application number | US-201615171411-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jun 2, 2016 |
| Priority date | Sep 16, 2013 |
| Publication date | Sep 22, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Disclosed are various examples for multi-persona management on a client device. In one example, a client device can be configured to maintain multiple personas for a single user where each of the personas includes a unique configuration of the client device. A first one of the personas can include an enterprise persona while a second one of the personas can include a personal persona. Different methods of authentication can result in the client device toggling between the enterprise persona and the personal persona where the client device is managed by a device management service, for example, when the client device is configured in accordance with the enterprise persona.
Opening claim text (preview).
Therefore, the following is claimed: 1 . A non-transitory computer-readable medium for logging a single user into one of a plurality of personas on a client device comprising program instructions that, when executed by at least one hardware processor of the client device, cause the client device to: maintain the plurality of personas for the single user on the client device, each of the plurality of personas comprising a unique configuration of the client device, wherein a first one of the plurality of personas comprises an enterprise persona and a second one of the plurality of personas comprises a personal persona; identify an authentication being made on the client device by the single user using one of a first authentication method or a second authentication method; in response to the first authentication method being used in the authentication, toggle the client device in accordance with the enterprise persona, wherein the client device is managed by a device management service when the client device is toggled in accordance with the enterprise persona; and in response to the second authentication method being used in the authentication, toggle the client device in accordance with the personal persona, wherein the client device is not managed by the device management service when the client device is toggled in accordance with the personal persona. 2 . The non-transitory computer-readable medium of claim 1 , wherein maintaining the plurality of personas for the single user on the client device further comprises maintaining a first memory partition for the enterprise persona and a second memory partition for the personal persona, wherein the first memory partition is separate from the second memory partition. 3 . The non-transitory computer-readable medium of claim 1 , wherein: the first authentication method comprises scanning a first finger of the single user using a fingerprint reader communicatively coupled to the client device; and the second authentication method comprises scanning a second finger of the single user using the fingerprint reader communicatively coupled to the client device, the second finger being different than the first finger. 4 . The non-transitory computer-readable medium of claim 1 , wherein: the first authentication method comprises detecting entry of a first password provided by the single user in association with the client device; and the second authentication method comprises detecting entry of a second password provided by the single user in association with the client device, the second password being different than the first password. 5 . The non-transitory computer-readable medium of claim 1 , wherein the unique configuration comprises at least one of: a setting, a policy, a rule, or an attribute customized in association with a user environment. 6 . The non-transitory computer-readable medium of claim 1 , wherein the enterprise persona or the personal persona comprises a virtual separation of at least one hardware component of the client device, wherein the at least one hardware component comprises a hardware processor, a battery, or memory. 7 . The non-transitory computer-readable medium of claim 1 , wherein the at least one application executable in a client device further comprises program instructions that, when executed by the at least one hardware processor of the client device, cause the client device to limit access to content for at least the enterprise persona based at least in part on a time, a location of the client device, a presence of another device, a software version, or a required component of software. 8 . A method for logging a single user into one of a plurality of personas on a client device, comprising: maintaining the plurality of personas for the single user on the client device, each of the plurality of personas comprising a unique configuration of the client device, wherein a first one of the plurality of personas comprises an enterprise persona and a second one of the plurality of personas comprises a personal persona; identifying an authentication being made on the client device by the single user using one of a first authentication method or a second authentication method; in response to the first authentication method being used in the authentication, toggling the client device in accordance with the enterprise persona, wherein the client device is managed by a device management service when the client device is toggled in accordance with the enterprise persona; and in response to the second authentication method being used in the authentication, toggling the client device in accordance with the personal persona, wherein the client device is not managed by the device management service when the client device is toggled in accordance with the personal persona. 9 . The method of claim 8 , wherein maintaining the plurality of personas for the single user on the client device further comprises maintaining a first memory partition for the enterprise persona and a second memory partition for the personal persona, wherein the first memory partition is separate from the second memory partition. 10 . The method of claim 8 , wherein: the first authentication method comprises scanning a first finger of the single user using a fingerprint reader communicatively coupled to the client device; and the second authentication method comprises scanning a second finger of the single user using the fingerprint reader communicatively coupled to the client device, the second finger being different than the first finger. 11 . The method of claim 8 , wherein: the first authentication method comprises detecting entry of a first personal identification number provided by the single user in association with the client device; and the second authentication method comprises detecting entry of a second personal identification number provided by the single user in association with the client device, the second personal identification number being different than the first personal identification number. 12 . The method of claim 8 , wherein the unique configuration comprises at least one of: a setting, a policy, a rule, or an attribute customized in association with a user environment. 13 . The method of claim 8 , wherein the enterprise persona or the personal persona comprises a virtual separation of at least one hardware component of the client device, wherein the at least one hardware component comprises a hardware processor, a battery, or memory. 14 . The method of claim 8 , further comprising limiting access to content for at least the enterprise persona based at least in part on a time, a location of the client device, a presence of another device, a software version, or a required component of software. 15 . A system for logging a single user into one of a plurality of personas, comprising: a client device comprising at least one hardware processor and in data communication with a device management service over a network; program instructions that, when executed by the client device, cause the client device to: maintain the plurality of personas for the single user on the client device, each of the plurality of personas comprising a unique configuration of the client device, wherein a first one of the plurality of personas comprises an enterprise persona and a second one of the plurality of personas comprises a personal persona; identify an authentication being made on the client device by the single user using one of a first authentication method or a second authentication method; in response to the first authentication method
operating in dual or compartmented mode, i.e. at least one secure mode · CPC title
including at least an additional display (G06F1/1692 takes precedence) · CPC title
for controlling access to devices or network resources · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.