Session slicing of mirrored packets
US-12184680-B2 · Dec 31, 2024 · US
US9497220B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9497220-B2 |
| Application number | US-201113274913-A |
| Country | US |
| Kind code | B2 |
| Filing date | Oct 17, 2011 |
| Priority date | Oct 17, 2011 |
| Publication date | Nov 15, 2016 |
| Grant date | Nov 15, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and techniques relating to securely managing electronic resources are described. A described technique includes receiving a request to add to a mobile device an account setting for a server resource account. Detecting a trigger event for a new perimeter based on the account setting. In response to a parameter or a pattern associated with the account setting, retrieving a security policy from a resource server for the server resource account, and generating, by the mobile device, a new perimeter including the server resource account based on the security policy. The new perimeter is configured to prevent transferring data associated with the server resource account being transferred to mobile-device resources external to the new perimeter.
Opening claim text (preview).
What is claimed is: 1. A method, comprising: receiving a request to add to a mobile device an enterprise application for accessing an enterprise account; in response to detection of a parameter or a pattern associated with an account setting, retrieving a security policy from a resource server for the enterprise account; in response to the request to add the enterprise application and the detection of the parameter or the pattern associated with the account setting, generating, by the mobile device, a new logical separation of resources associated with the enterprise application and other enterprise resources on the mobile device, wherein the new logical separation of resources prevents applications on the mobile device external to the new logical separation of resources from accessing resources associated with the new logical separation of resources; receiving, from the resource server, a client certificate for establishing a secure channel with an enterprise; assigning the client certificate to the new logical separation of resources; when the new logical separation of resources is unlocked, granting access between the other enterprise resources and the enterprise application and granting the external resources on the mobile device to access the enterprise application and the other enterprise resources on the mobile device, wherein an unlock state allows applications to access files in a file system domain; when the new logical separation of resources is soft locked, granting access and operations between the other enterprise resources and the enterprise application while preventing user interactions with the enterprise application the external resources on the mobile device from accessing the enterprise application and the other enterprise resources on the mobile device, wherein the soft locked state allows applications running on the mobile device to access the files in the file system domain and locks an user interface on the mobile device; and when the new logical separation of resources is hard locked, preventing access between the other enterprise resources and the enterprise application while preventing the external resources on the mobile device from accessing the enterprise application and the other enterprise resources on the mobile device, wherein a hard lock state prohibits applications from accessing the files in the file system domain and locks an underlying encryption domain. 2. The method of claim 1 , wherein the enterprise account comprises at least one of an email account, a calendar account, or a contacts account. 3. The method of claim 1 , wherein generating the new logical separation of resources comprises automatically generating the new logical separation of resources independent of an administrator of the resource server setting policies or configuring of the new logical separation of resources. 4. The method of claim 1 , wherein the pattern or parameter includes at least one of an account address, a network address, a policy, one or more settings associated with adding access to a new account that provides push synchronization, or one or more settings associated with connecting to a bridge device. 5. The method of claim 1 , wherein the security policy includes at least one of password protection or data encryption. 6. The method of claim 1 , wherein the account setting includes login information. 7. The method of claim 1 , wherein the account setting includes an email address. 8. The method of claim 1 , wherein the server resource account includes an enterprise account. 9. The method of claim 8 , wherein the enterprise account includes an enterprise email account. 10. The method of claim 1 , wherein the new logical separation of resources includes a logical separation of resources for enterprise or a logical separation of resources for corporate. 11. A mobile device, comprising: one or more processors operable to: receive a request to add to a mobile device an enterprise application for accessing an enterprise account; in response to detection of a parameter or a pattern associated with an account setting, retrieve a security policy from a resource server for the enterprise account; in response to the request to add the enterprise application and the detection of the parameter or the pattern associated with the account setting, generate, by the mobile device, a new logical separation of resources associated with the enterprise application and other enterprise resources on the mobile device, wherein the new logical separation of resources prevents applications on the mobile device external to the new logical separation of resources from accessing resources associated with the new logical separation of resources including the enterprise application; receive, from the resource server, a client certificate for establishing a secure channel with an enterprise; assign the client certificate to the new logical separation of resources; when the new logical separation of resources is unlocked, grant access between the other enterprise resources and the enterprise application and grant the external resources on the mobile device to access the enterprise application and the other enterprise resources on the mobile device, wherein an unlock state allows applications to access files in a file system domain; when the new logical separation of resources is soft locked, grant access between the other enterprise resources and the enterprise application and prevent user interactions with the enterprise application, wherein the soft locked state allows applications running on the mobile device to access the files in the file system domain and locks an user interface on the mobile device; and when the new logical separation of resources is hard locked, prevent access between the other enterprise resources and the enterprise application and prevent the external resources on the mobile device from accessing the enterprise application and the other enterprise resources on the mobile device, wherein a hard lock state prohibits applications from accessing the files in the file system domain and locks an underlying encryption domain. 12. The mobile device of claim 11 , wherein the enterprise account comprises at least one of an email account, a calendar account, or a contacts account. 13. The mobile device of claim 11 , wherein the one or more processors operable to generate the new logical separation of resources comprises the one or more processors operable to automatically generate the new logical separation of resources independent of an administrator of the resource server setting policies or configuring the new logical separation of resources. 14. The mobile device of claim 11 , wherein the pattern or parameter includes at least one of an account address, a network address, a policy, one or more settings associated with adding access to a new account that provides push synchronization, or one or more settings associated with connecting to a bridge device. 15. The mobile device of claim 11 , wherein the security policy includes at least one of password protection or data encryption. 16. A computer program product encoded on a non- transitory storage medium, the product comprising computer readable instructions for causing one or more processors to perform operations comprising: receiving a request to add to a mobile device an enterprise application for accessing an enterprise account; in response to detection of a parameter or a pattern associated with an account setting, retrieving a security policy from a resource server for the enterprise account; in response to the request to add the enterpr
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
resulting in reduced user or operator actions, e.g. presetting, automatic actions, using hardware token storing data · CPC title
via local network · CPC title
Access security · CPC title
using delegated authorisation, e.g. open authorisation [OAuth] protocol · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.