发明名称 Method and system for facilitating isolated workspace for applications
摘要 A system maintains a workspace environment of enterprise applications on a mobile device. The system receives enterprise applications for installation on the mobile device, wherein functionality has been inserted into binary executables of the enterprise applications to force the enterprise applications to communicate with an application management agent to obtain a security policy including a validity time period value related to keeping the workspace valid. The application management agent provides cryptographic keys to the enterprise applications to share encrypted messages. Upon launching, an enterprise application stores a workspace expiration time value as an encrypted message. The workspace expiration time value is extended if the user continues its use or, by another enterprise application, if the other enterprise application is launched by the user before an expiration of the expiration time value. The application management agent requests authentication credentials from the user if the workspace expiration time value expires.
申请公布号 US9087191(B2) 申请公布日期 2015.07.21
申请号 US201213595881 申请日期 2012.08.27
申请人 VMware, Inc. 发明人 Deasy Stephen;Newell Craig
分类号 G06F21/00;G06F21/54;G06F9/445;G06F21/31;G06F21/60;G06F21/53;H04W12/02;H04L29/06;H04W12/00 主分类号 G06F21/00
代理机构 代理人
主权项 1. A method for maintaining an isolated workspace environment of enterprise applications on a mobile device, the method comprising: receiving enterprise applications for installation on the mobile device, wherein functionality has been inserted into binary executables of the enterprise applications to force the enterprise applications to communicate with an application management agent installed on the mobile device in order to obtain a security policy governing a user's ability to access the enterprise applications, the security policy including a validity time period value related to keeping the isolated workspace valid; providing by the application management agent, cryptographic keys to the enterprise applications to share encrypted messages relating to the isolated workspace that are stored on the mobile device; upon launch of one of the enterprise applications, encrypting, by the launched enterprise application, a workspace expiration time value using one of the cryptographic keys provided by the application management agent and storing, by the launched enterprise application, the encrypted workspace expiration time value as an encrypted message on the mobile device, wherein the workspace expiration time value is a function of the validity time period value and reflects a period of time in which the isolated workspace remains valid; extending the workspace expiration time value by the launched enterprise application if the user continues to use the launched enterprise application or, by at least one other enterprise application, if the other enterprise application is launched by the user before an expiration of the expiration time value; and requesting, by the application management agent, authentication credentials from the user to continue using enterprise applications in the isolated workspace if the workspace expiration time value expires due to a lack of activity by the user of any of the enterprise applications.
地址 Palo Alto CA US