发明名称 System for the distribution and deployment of applications with provisions for security and policy conformance
摘要 A system and method are disclosed for deploying applications to end point devices. The applications are obtained from a marketplace that checks the applications and packages them for endpoint use according to certain policies. Packaging an application includes compiling or assembling and linking the application, possibly with a framework and possibly with a binding token, which can be a device binding token and/or a user binding token. The application is loaded onto an endpoint device and if the application is bound to the device and the user is allowed to use the application, the application is enabled to be used on the endpoint device. A gateway between the endpoint device and an authentication server helps to authenticate the user. The gateway also manages data transfers between the endpoint device and a data server according to a selected protocol.
申请公布号 US8832855(B1) 申请公布日期 2014.09.09
申请号 US201113226351 申请日期 2011.09.06
申请人 Symantec Corporation 发明人 Enderwick Thomas Jeffrey;Perret Christopher Edward
分类号 G06F7/04 主分类号 G06F7/04
代理机构 Holland & Hart LLP 代理人 Holland & Hart LLP
主权项 1. A method for deploying applications to endpoint devices, the method comprising: obtaining an application for an endpoint device, said endpoint device having a particular user and said application including application logic, wherein the application has embedded therein a device-binding token and the endpoint device includes a device ID; launching the application, wherein the application has embedded therein a user-binding token and has an application ID, and wherein the application holds cryptographic keys for enabling decryption of encrypted data on the endpoint device; during the launching of the application, connecting the application to a gateway, determining whether the application is bound to the endpoint device, and halting the launch of the application if the application is not bound to the endpoint device, wherein the step of determining whether an application is bound to an endpoint device is performed by obtaining the device ID of the endpoint device and comparing the device-binding token to the device ID to determine if the device-binding token matches the device ID; determining the authenticity of the user; determining whether the application is bound to the user, wherein determining whether the application is bound to the user comprises: obtaining the user-binding token;comparing the user-binding token to the application ID to determine if the user-binding token matches the application ID; andwhen the user-binding token does not match the application ID, disconnecting the application from the gateway and erasing cryptographic keys held by the application prior to disconnecting the application from the gateway to cause encrypted data on the endpoint device to be unreadable; and invoking the application logic on the endpoint device if the application is bound to the user and to the device and the user is authenticated.
地址 Mountain View CA US