CA2811659C

Method and apparatus for differentiated access control

Abstract

A method for differentiated access control on a computing device having a connection with a second device, the method checking whether a timer has expired on the second device or if a connection is lost to the second device; and preventing at least one of the plurality of application subsets from being launched or enabled if the timer has expired on the second device or the connection is lost to the second device.

CA2811659C, drawing sheet 1
Sheet 1 of 12

Term

5 yearsleft in the term

Expires 23 September 2031.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

39 claims: 33 independent, 6 dependent

  1. 1
    CA 02811659 2016-02-18 CLAIMS 1. A method of providing differentiated access control on an electronic device, the method comprising:allowing user access to the electronic device upon receipt of a correct user input to unlock the electronic device;storing multiple classes of data on the electronic device, wherein a first class of data comprises work data including a plurality of work applications, and a second class of data comprises personal data including a plurality of personal applications;allowing user access to the work applications upon successful authentication to unlock the first class of data;upon expiry of a first inactivity timer, locking the first class of data without locking the second class of data;and upon expiry of a second inactivity timer, locking the second class of data;when the first class of data is locked: preventing user access to the first class of data, including preventing launching and enabling of any of the work applications;and when the second class of data is locked: preventing user access to the second class of data, including preventing launching and enabling of any of the personal applications.
  2. 4
    The method of any one of claims 1 to 3, further comprising:unlocking the first class of data upon successful authentication.
  3. 5
    The method of any one of claims 1 to 4, further comprising:displaying, via a user interface, obscured data related to one or more work applications when the first class of data is locked.
  4. 6
    The method of any one of claims 1 to 5, wherein the correct user input comprises a password.
  5. 7
    The method of any one of claims 1 to 6, wherein the correct user input is a nontext input.
  6. 8
    The method of any one of claims 1 to 7, wherein the work applications include at least one application selected from the group consisting of a contacts application, a calendar application, an email application, a word processing application, customer relationship management software, enterprise resource planning software, server and desktop virtualization software. CA 02811659 2016-02-18
  7. 9
    The method of any one of claims 1 to 8, wherein the work data comprises at least one of documents, calendar entries, electronic mails, customer data, enterprise resource data, and sales figures.
  8. 10
    The method of any one of claims 1 to 9, wherein the personal applications include at least one application selected from the group consisting of a browser application, a camera application, social networking applications, games, and really simple syndication (RSS) readers.
  9. 11
    The method of any one of claims 1 to 10, wherein the personal data comprises at least one of browser data, photographs, social networking data, and really simple syndication feeds.
  10. 12
    The method of any one of claims 1 to 11, further comprising managing data interaction between the first class of data and the second class of data.
  11. 13
    The method of any one of claims 1 to 12, wherein an application that is considered to be both a personal application and a work application is duplicated between the first class of data and the second class of data.
  12. 14
    An electronic device configured for differentiated access control, the electronic device comprising:a processor;CA 02811659 2016-02-18 a communications subsystem;and memory, wherein the electronic device is configured to;allow user access to the electronic device upon receipt of a correct user input to unlock the electronic device;store multiple classes of data, wherein a first class of data comprises work data including a plurality of work applications, and a second class of data comprises personal data including a plurality of personal applications;allow user access to the work applications upon successful authentication to unlock the first class of data;upon expiry of a first inactivity timer, lock the first class of data without locking the second class of data;and upon expiry of a second inactivity timer, lock the second class of data;when the first class of data is locked: prevent user access to the first class of data, including preventing launching and enabling of any of the work applications;when the second class of data is locked: prevent user access to the second class of data, including preventing launching and enabling any of the personal applications.
  13. 17
    The electronic device of any one of claims 14 to 16, wherein the electronic device is further configured to:unlock the first class of data upon successful authentication.
  14. 18
    The electronic device of any one of claims 14 to 17, wherein the electronic device is further configured to:display, via a user interface, obscured data related to one or more work applications when the first class of data is locked.
  15. 19
    The electronic device of any one of claims 14 to 18, wherein the correct user input comprises a password.
  16. 20
    The electronic device of any one of claims 14 to 19, wherein the correct user input is a non-text input.
  17. 21
    The electronic device of any one of claims 14 to 20, wherein the work applications include at least one application selected from the group consisting of a contacts application, a calendar application, an email application, a word processing application, customer relationship management software, enterprise resource planning software, server and desktop virtualization software. CA 02811659 2016-02-18
  18. 22
    The electronic device of any one of claims 14 to 21, wherein the work data comprises at least one of documents, calendar entries, electronic mails, customer data, enterprise resource data, and sales figures.
  19. 23
    The electronic device of any one of claims 14 to 22, wherein the personal applications include at least one application selected from the group consisting of a browser application, a camera application, social networking applications, games, and really simple syndication (RSS) readers.
  20. 24
    The electronic device of any one of claims 14 to 23, wherein the personal data comprises at least one of browser data, photographs, social networking data, and really simple syndication feeds.
  21. 25
    The electronic device of any one of claims 14 to 24, wherein the electronic device is further configured to manage data interaction between the first class of data and the second class of data.
  22. 26
    The electronic device of any one of claims 14 to 25, wherein an application that is considered to be both a personal application and a work application is duplicated between the first class of data and the second class of data. CA 02811659 2016-02-18
  23. 27
    A non-transitory computer readable medium storing program code executable by a processor of an electronic device for causing performance of a method for differentiated access control, the method comprising:allowing user access to the electronic device upon receipt of a correct user input to unlock the electronic device;storing multiple classes of data on the electronic device, wherein a first class of data comprises work data including a plurality of work applications, and a second class of data comprises personal data including a plurality of personal applications;allowing user access to the work applications upon successful authentication to unlock the first class of data;upon expiry of a first inactivity timer, locking the first class of data without locking the second class of data;and upon expiry of a second inactivity timer, locking the second class of data;when the first class of data is locked: preventing user access to the first class of data, including preventing launching and enabling of any of the work applications;and when the second class of data is locked: preventing user access to the second class of data, including preventing launching and enabling of any of the personal applications.
  24. 30
    The non-transitory computer readable medium of any one of claims 27 to 29, wherein the method further comprises:unlocking the first class of data upon successful authentication.
  25. 31
    The non-transitory computer readable medium of any one of claims 27 to 30, wherein the method further comprises:displaying, via a user interface, obscured data related to one or more work applications when the first class of data is locked.
  26. 32
    The non-transitory computer readable medium of any one of claims 27 to 31, wherein the correct user input comprises a password.
  27. 33
    The non-transitory computer readable medium of any one of claims 27 to 32, wherein the correct user input is a non-text input.
  28. 34
    The non-transitory computer readable medium of any one of claims 27 to 33, wherein the work applications include at least one application selected from the group consisting of a contacts application, a calendar application, an email application, a word processing application, customer relationship management software, enterprise resource planning software, server and desktop virtualization software. CA 02811659 2016-02-18
  29. 35
    The non-transitory computer readable medium of any one of claims 27 to 34, wherein the work data comprises at least one of documents, calendar entries, electronic mails, customer data, enterprise resource data, and sales figures.
  30. 36
    The non-transitory computer readable medium of any one of claims 27 to 35, wherein the personal applications include at least one application selected from the group consisting of a browser application, a camera application, social networking applications, games, and really simple syndication (RSS) readers.
  31. 37
    The non-transitory computer readable medium of any one of claims 27 to 36, wherein the personal data comprises at least one of browser data, photographs, social networking data, and really simple syndication feeds.
  32. 38
    The non-transitory computer readable medium of any one of claims 27 to 37, wherein the method further comprises managing data interaction between the first class of data and the second class of data.
  33. 39
    The non-transitory computer readable medium of any one of claims 27 to 38, wherein an application that is considered to be both a personal application and a work application is duplicated between the first class of data and the second class of data.
Independent claims33