Application marketplace administrative controls
Abstract
The subject matter of this specification can be implemented by a method, among others, which includes receiving, through one or more servers associated with the application market, a policy including identification of one or more users and restricted permissions. The server associated with the application market receives a request to access one or more applications distributed through the application market, where the request includes data identifying a specific user among the users. One or more applications associated with the restricted permission are identified by the server associated with the application market, and a specific user's access to the application associated with the restricted permission is restricted by the server associated with the application market.
Term
6 yearsleft in the term
Expires 28 September 2032.
- Priority
- Filed
- Granted
- Today
- Expires
29 claims: 3 independent, 26 dependent
- 11 •一种计算机实施的方法,包括: 由与应用市场相关联的一个或多个服务器接收策略,所述策略包括识别一个或多个用 户和一个或多个受限许可的数据,所述一个或多个受限许可与所述用户的一个或多个相应 用户设备的使用相关联; 由与所述应用市场相关联的所述服务器接收用于访问通过所述应用市场分发的一个 或多个应用的请求,其中所述请求包括识别所述用户中的特定用户的数据; 由与所述应用市场相关联的所述服务器识别所述应用中与所述受限许可中的特定受 限许可相关联的一个或多个应用,所述受限许可中的所述特定受限许可与来自所述用户设 备的所述特定用户的特定相应用户设备的所述使用相关联;以及 由与所述应用市场相关联的所述服务器限制由所述特定用户对与所述特定受限许可 相关联的所述应用的访问。
- 2根据权利要求1所述的方法,其中所述策略接收自与信息技术管理员相关联的服务 器。
- 3根据权利要求1所述的方法,其中所述策略接收自与所述特定用户相关联的移动设 备。
- 4根据权利要求1所述的方法,包括: 将所述策略存储在策略集合中;并且 响应于接收到所述请求,使用所述请求中识别所述特定用户的数据从所述集合中所存 储的所述策略中选择出所述策略。
- 5根据权利要求1所述的方法,其中限制对与所述特定受限许可相关联的所述应用的 访问包括: 提供用户界面,所述用户界面标识出与所述特定受限许可相关联的所述应用,并且针 对所标识的所述应用中的每一个应用,所述用户界面包括指示对与所述特定受限许可相关 联的所述应用中的每一个应用的访问受到限制的指示符。
- 6根据权利要求5所述的方法,其中: 所述指示符进一步指示所述应用中的每一个应用可通过所述应用市场进行分发而并 不考虑所述特定受限许可,并且 所述用户界面包括用于请求所述应用中的一个或多个应用的分发而并不考虑所述特 定受限许可的用户可选择控件。
- 7根据权利要求5所述的方法,其中指示对所述应用中的每一个应用的访问受到限制 的所述指示符在所述用户界面的一部分中提供,所述用户界面的一部分本来将被用来提供 用于请求所述应用中的一个或多个应用的分发的用户可选择控件。
- 8根据权利要求5所述的方法,其中指示对所述应用中的每一个应用的访问受到限制 的所述指示符包括用于请求所述应用的分发的被禁用的控件。
- 9根据权利要求5所述的方法,其中所述用户界面包括用于请求放宽所述特定受限许 可的用户可选择控件。
- 10根据权利要求1所述的方法,其中限制对与所述特定受限许可相关联的所述应用的 访问包括: 提供标识与所述特定受限许可不相关联的一个或多个应用、且不标识与所述特定受限 CN 103988198 Β 许可相关联的所述应用的用户界面。 11·根据权利要求1所述的方法,其中限制对与所述特定受限许可相关联的所述应用的 访问包括: 提供将与所述特定受限许可相关联的所述应用标识为受限应用的用户界面。
- 1112. 根据权利要求5所述的方法,其中提供标识与所述特定受限许可相关联的所述应用 的所述用户界面包括使得所述用户界面上标识所述应用的信息黯淡显示。
- 1213. 根据权利要求1所述的方法,其中识别所述应用中与所述特定受限许可相关联的一 个或多个应用包括识别所述应用中执行与所述特定受限许可相关联的一个或多个操作的 一个或多个应用。
- 1314. 根据权利要求1所述的方法,其中识别所述应用中与所述特定受限许可相关联的一 个或多个应用包括识别所述应用中声明所述特定受限许可的使用的一个或多个应用。
- 1415. 根据权利要求1所述的方法,其中限制对与所述特定受限许可相关联的所述应用的 访问包括: 由与所述应用市场相关联的所述服务器提供表述不与所述特定受限许可相关联的所 述应用中的每一个应用的指示,并且省略表述与所述特定受限许可相关联的所述应用中的 每一个应用的指示。
- 1516. 一种系统,包括: 一个或多个计算机以及一个或多个存储指令的存储设备,当被所述一个或多个计算机 执行时,所述指令可操作以使得所述一个或多个计算机执行包括以下的操作: 由与应用市场相关联的一个或多个服务器接收包括策略,所述策略包括识别一个或多 个用户和一个或多个受限许可的数据,所述一个或多个受限许可与所述用户的一个或多个 相应用户设备的使用相关联; 由与所述应用市场相关联的所述服务器接收用于访问通过所述应用市场分发的一个 或多个应用的请求,其中所述请求包括识别所述用户中的特定用户的数据; 由与所述应用市场相关联的所述服务器识别所述应用中与所述受限许可中的特定受 限许可相关联的一个或多个应用,所述受限许可中的所述特定受限许可与来自所述用户设 备的所述特定用户的特定相应用户设备的所述使用相关联;以及 由与所述应用市场相关联的所述服务器限制由所述特定用户对与所述特定受限许可 相关联的所述应用的访问。
- 1617. 根据权利要求16所述的系统,其中所述策略接收自与信息技术管理员相关联的服 务器。
- 1718. 根据权利要求16所述的系统,其中所述策略接收自与所述特定用户相关联的移动 设备。
- 1819. 根据权利要求16所述的系统,所述操作进一步包括: 将所述策略存储在策略集合中;并且 响应于接收到所述请求,使用所述请求中识别所述特定用户的数据从所述集合中所存 储的所述策略中选择出所述策略。
- 1920. 根据权利要求16所述的系统,其中限制对与所述特定受限许可相关联的所述应用 的访问包括: CN 103988198 Β 提供用户界面,所述用户界面标识出与所述特定受限许可相关联的所述应用,并且针 对所标识的所述应用中的每一个应用,所述用户界面包括指示对与所述特定受限许可相关 联的所述应用中的每一个应用的访问受到限制的指示符。
- 2021. 根据权利要求20所述的系统,其中: 所述指示符进一步指示所述应用中的每一个应用可通过所述应用市场进行分发而并 不考虑所述特定受限许可,并且 所述用户界面包括用于请求所述应用中的一个或多个应用的分发而并不考虑所述特 定受限许可的用户可选择控件。
- 2122. 根据权利要求20所述的系统,其中指示对所述应用中的每一个应用的访问受到限 制的所述指示符在所述用户界面的一部分中提供,所述用户界面的一部分本来将被用来提 供用于请求所述应用中的一个或多个应用的分发的用户可选择控件。
- 2223. 根据权利要求20所述的系统,其中指示对所述应用中的每一个应用的访问受到限 制的所述指示符包括用于请求所述应用的分发的被禁用的控件。
- 2324. 根据权利要求20所述的系统,其中所述用户界面包括用于请求放宽所述特定受限 许可的用户可选择控件。
- 2425. 根据权利要求16所述的系统,其中限制对与所述特定受限许可相关联的所述应用 的访问包括: 提供标识与所述特定受限许可不相关联的一个或多个应用、且不标识与所述特定受限 许可相关联的所述应用的用户界面。
- 2526. 根据权利要求16所述的系统,其中限制对与所述特定受限许可相关联的所述应用 的访问包括: 提供将与所述特定受限许可相关联的所述应用标识为受限应用的用户界面。
- 2627. 根据权利要求20所述的系统,其中提供标识与所述特定受限许可相关联的所述应 用的所述用户界面包括使得所述用户界面上标识所述应用的信息黯淡显示。
- 2728. 根据权利要求16所述的系统,其中识别所述应用中与所述特定受限许可相关联的 一个或多个应用包括识别所述应用中执行与所述特定受限许可相关联的一个或多个操作 的一个或多个应用。
- 2829. 根据权利要求16所述的系统,其中识别所述应用中与所述特定受限许可相关联的 一个或多个应用包括识别所述应用中声明所述特定受限许可的使用的一个或多个应用。
- 2930. —种装置,包括: 用于由与应用市场相关联的一个或多个服务器接收策略的装置,所述策略包括识别一 个或多个用户和一个或多个受限许可的数据,所述一个或多个受限许可与所述用户的一个 或多个相应用户设备的使用相关联; 用于由与所述应用市场相关联的所述服务器接收用于访问通过所述应用市场分发的 一个或多个应用的请求的装置,其中所述请求包括识别所述用户中的特定用户的数据; 用于由与所述应用市场相关联的所述服务器识别所述应用中与所述受限许可中的特 定受限许可相关联的一个或多个应用的装置,所述受限许可中的所述特定受限许可与来自 所述用户设备的所述特定用户的特定相应用户设备的所述使用相关联;以及 用于由与所述应用市场相关联的所述服务器限制由所述特定用户对与所述特定受限 CN 103988198 Β 许可相关联的所述应用的访问的装置。 CN 103988198 Β
Independent claims29
135 paragraphs, as filed
Application market management controls
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] Please request the priority of the U.S. Chinese Application Serial No. 13/270,457 filed on October 11, 2011 and the U.S. Application Serial No. 13/552,985 filed on July 19, 2012, the disclosure of which is by reference Combine this.
Technical field
[0003] The present disclosure generally relates to the management of access to information technology assets.
Background technique
[0004] Among the many responsibilities of IT administrators, they have the task of managing and ensuring access to organizational information. In order to fulfill this responsibility, IT administrators manage their users' accounts and passwords, and manage their users' ability to access the organization's various IT systems and database sets.
[0005] When employees use personal hardware or software to access the organization's hardware or software systems, a source of risk to the security of IT assets appears. An example type of such hardware is a smart phone. In particular and different from carrying personal phones to perform personal functions and carrying company phones to perform company functions and access company data, some users regard their personally owned smartphones as "dual-purpose" personal/business services that serve personal and work needs at the same time. phone.
[0006] In order to reduce the risk of being exposed to malicious hardware and software or otherwise exposing its data through malicious use of benign hardware and software, a company may allow its employees to use their smartphones or other personally owned computing under predetermined conditions. Device to access company data. For example, companies can ensure that their employees devices have secure access codes, encrypted file systems, and trusted application sandboxes before authorizing access to organizational data. Alternatively, IT administrators can specify approved configurations of hardware and software that have been tested for access to organizational data.
[0007] As dual-purpose devices owned by users become more common, the restrictions placed on these devices by traditional blacklists and whitelists appear to be too rough. For example, when the IT department uses a list of "blocked" applications to define the applications that are restricted from being installed on the device, the end user may spend time and data bandwidth to download data but find that the application has been blocked. Install on the device. Employees may find that such an architecture hinders the usefulness of the application market, especially if employees do not directly understand which applications have been or have not been approved for installation on devices that have access to the organization's IT resources. In addition, employees may spend money to obtain permission for the app, only to find that the app has been blocked and is therefore of little value to them.
Summary of the invention
[0008] In general, this document describes a system and method for managing applications that can be purchased or otherwise distributed through an application market, portal, or store, and installed on user equipment. Specifically, IT administrators can issue policies for the application market to identify applications that can be distributed through the application market or restrict permission to not access. The policy may further specify which applications can or cannot access the data, functions, or operations associated with the user device permissions (such as permission to access calendar data or contact data). When a user attempts to install an application seeking to access a function associated with a specific permission, the security application or module associated with the application market determines whether the policy allows or disallows such access before allowing the application to be downloaded or installed. In the case where the user equipment is associated with multiple user accounts,
CN 103988198 Β
The policy (or the specific restrictions defined by the policy) may be configured to be applied to all user accounts associated with the user equipment, or to a specific subset of user accounts.
[0009] As used in this disclosure, "license" refers to a restriction on the code portion on the device, the access to the data or the function, or the restriction that is managed in other ways. The permissions that can be defined by the operating system of the device can restrict the reading or writing of specific data such as a contact database or an email database, or can restrict access to hardware resources or communication resources of the device, for example. The license may, for example, manage the user equipment's ability to access data generated by a specific hardware module, the ability to operate in a "roaming" mode, or the ability to access a 4G network.
[0010] The license is imposed to protect critical data and codes that may be misused to distort or damage the user experience. The license is identified by a unique name or label, which often suggests the function restricted by the license, and specifies or defines the association with the restricted code, data, or function.
[0011] According to a general implementation of this description, a method includes receiving, by one or more servers associated with an application market, a policy that includes data identifying one or more users and restricted permissions. A request is received by a server associated with the application market to access one or more applications distributed through the application market, wherein the request includes data identifying a specific user among the users. One or more applications associated with the restricted permission are identified by the server associated with the application market, and the specific user's access to the application associated with the restricted permission is restricted by the server associated with the application market. Other embodiments in this regard include corresponding systems and computer program products.
[0012] The various implementations of the previous implementation may include some or all of the following features, or may not include the following features. The policy can be received from a server associated with the information technology administrator. The policy can be received from a mobile device associated with a specific user. The policy may be stored in a policy set; and in response to receiving the request, the data identifying a specific user in the request may be used to select the policy from the policies stored in the set.
[0013] In another embodiment, restricting access to applications associated with restricted permissions may include providing a user interface that identifies applications associated with the restricted permissions and is specific to the identified applications Each of the applications includes an indicator indicating that access to each of the applications associated with the restricted permission is restricted. The indicator may further indicate that each application in the application can be distributed through the application market without considering the restricted permission, and the user interface includes a request for the distribution of one or more applications in the application without considering the restriction Licensed users can select controls. An indicator indicating that access to each of the applications is restricted may be provided in a part of the user interface that was originally used to provide user-selectable controls for requesting the distribution of one or more of the applications.
[0014] In another example, the indicator indicating that access to each of the applications is restricted may include a disabled control for requesting distribution of the application. The user interface may include user selectable controls for requesting relaxation of restricted permissions. Restricting access to applications associated with restricted permissions may include providing a user interface that identifies one or more applications not associated with restricted permissions and does not identify applications associated with restricted permissions. Restricting access to applications associated with restricted permissions may include providing a user interface that identifies applications associated with restricted permissions as restricted applications.
[0015] In other examples, providing a user interface that identifies the application associated with the restricted permission may include greying out the information identifying the application on the user interface. Identifying one or more of the applications associated with the restricted permission may include identifying one or more of the applications that perform one or more operations associated with the restricted permission. Identifying one or more of the applications associated with the restricted permission may include identifying one or more of the applications that declare the use of the restricted permission. Restricting access to applications associated with restricted permissions may include
CN 103988198 Β
The associated server provides an instruction that expresses each of the applications that are not associated with the restricted license, and omits the instruction that expresses each of the applications that are associated with the restricted license.
[0016] The systems and techniques described herein can provide one or more of the following advantages. For example, the system can restrict access to company data on a per-license basis, on an application-by-application basis, and optionally on an account-by-account basis, without excessively restricting user devices to the rich applications that can be installed and used Market visits.
[0017] Details of one or more implementations are given in the following drawings and description. Other features will be apparent from the description and drawings and claims.
Description of the drawings
[0018] FIG. 1 is a schematic diagram of an example system that implements permission-based management controls.
[0019] FIG. 2 is a flowchart showing an example process for controlling access to an application.
[0020] FIGS. 3A-3I show example screenshots of the user interface of the application market for controlling access to the application.
[0021] FIG. 4 is a timeline diagram showing example interactions between systems for controlling access to applications of the application market.
[0022] FIG. 5 is a timeline diagram showing example interactions between systems for synchronizing policies for controlling access to applications of the application market.
[0023] FIG. 6 is a block diagram of a computing device.
[0024] In the drawings, the same reference numerals always refer to similar elements.
Detailed ways
[0025] FIG. 1 is a schematic diagram illustrating an example system that implements permission-based management controls. The system 100 includes an administrator server 102, an application market server 103, and a user device 104 connected through a network 130.
[0026] The administrator server 102 is a computer device that provides an administrator interface 106 for employees of a representative organization such as an IT administrator to manage IT resources. The network 130 includes a wired or wireless private network (such as a company local area network or an intranet), a public network (such as the Internet, a cellular data network), or any other suitable type of computer network.
[0027] The user device 104 is a computing device used by the same or different employees of the organization, and can be a smart phone, a traditional cellular phone, a personal computer, a tablet computer, an e-book reader, a music player, or any other suitable type Computing equipment. The user device 104 may be a dual-purpose device used by the device owner to serve both business and personal needs.
[0028] Generally, the administrator interface 106 allows an IT administrator to configure settings that define a policy 107, which can at least partially determine the applications that the user device 104 is permitted to install. IT administrators can use the administrator interface 106 to create policies 107 that group user domains, permissions, and applications, and/or specify specific restrictions for the grouped permissions and applications. The policy 107 can restrict access to company data on a domain-by-domain, license-by-license, and/or application-by-application basis, without excessively restricting user equipment's access to the rich application market available for installation and use.
[0029] In one example, the policy 107 may specify a grouping such as {Contact Permission=All Applications} to allow all applications on the user device 104 to access functions associated with the "Contact" permission; such as {email Permission = grouping of applications ABC} to allow only applications identified by the identifier "ABC" to access the functions associated with the "email" permission; or a grouping such as {camera permission = no application} can be specified to prevent all applications from accessing Functions associated with the "camera" permission. This architecture allows applications that may require access to restricted permissions to be installed, but only allows such applications to access the permissions that are paired with them or unrestricted permissions (for example, access to non-company account data) ) Associated functions.
CN 103988198 Β
[0030] When applied to the application market server 103, the policy 107 may specify grouping to selectively allow, prevent, or change the performance or appearance of applications made available through the application market 150 to selected users or user groups. In the illustrated example, the administrator interface 106 shows that the administrator is creating a policy that specifies groups such as {for all users in the "example.com" domain, "email data access" has been "disabled"}} However, applications that access email data as part of their functions are managed differently than unrestricted applications. For example, the application market server 103 can prevent such restricted applications from appearing in the application market 150. Likewise, the user of the user equipment 104 can save the work of downloading applications that may have been restricted from being used on the user equipment 104. Several techniques for handling the presentation of restricted applications in the application market are discussed in the description of FIGS. 3A-3F.
[0031] In FIG. 1, the administrator interface 106 provides a user input control 108, a permission input control 110, and a restriction input control 112. During state (a), the IT administrator inputs data into the user input control 108 to identify the user or user group for which the policy 107 will be applied. (Multiple) users can be defined by username (for example, Nate Godbout, ngodbout, nathan@example.com) or user domain (for example, *.example.com<sup>,,</sup>, Hr. example. com) to recognize another U. The users identified in Figure 1 are all users in the example.com domain.
[0032] Next, the IT administrator enters a license name into the license input control 110 to specify that the function, data, operation, or resource associated with the license allows the identified application to access or restricts the license that is not allowed. In Figure 1, the IT administrator has identified the "access email data" permission.
[0033] The license and the code, data, or function associated with each license may be predefined by the application, operating system, or file system of the user device 104. In other examples, the IT administrator can manually configure and store the database set on or accessed by the user device 104, user device functions (e.g., microphone, location awareness, wireless connectivity), device capabilities (e.g., text messaging, Data connectivity, cellular roaming) or other applications or user equipment 104 features. The IT administrator can use the administrator interface 106 to manually configure such permissions.
[0034] Next, the IT administrator inputs data into the restriction input control 112 to identify the restriction type to be associated with the application identified in the application input control 108. In some embodiments, the restriction options may include "restrict", "block", "permit" or "allow". The "restrict" or "block" selection can cause the application to be placed on the blacklist for the identified permissions, or cause the application to be removed or omitted from the whitelist for the identified permissions. The "permission" or "allow" selection can cause the application to be placed on the whitelist for the identified permissions, or cause the application to be removed or omitted from the blacklist for the identified permissions. In Figure 1, the IT administrator has chosen to "disable" the application associated with the "access email data" permission.
[0035] In other embodiments, the restriction options are not specified by the IT administrator, and default settings or inherent settings of this type are used. When a user requests to download and install such an application, the IT administrator can, for example, select "Get Approval" to additionally specify approval for the application that wants to obtain "Access Email Data". With this restriction, when a user tries to download and install an application that needs to access email data from the application market 150, a request message can be sent from the application market server 103 to the administrator server 102 across the network 130, and the IT administrator is presented with permission or The option to download and install the app is not allowed. The IT administrator selects the appropriate option, and the approval message or the disapproval message is sent to the application market server 103 across the network 130, and the user device 104 is allowed or not allowed to download and not based on the type or content of the message received by the application market server 103 Install the selected application.
[0036] During the state (b), the administrator server 102 transmits to the application market server 103 via the network 130 a policy 107 identifying the specified user(s), restrictions, and permissions. The application market server 103 stores the strategy in the strategy database. The strategy database includes a data structure (for example, a list) that identifies one or more strategies, as well as identifying data structures available for download and
CN 103988198 Β
The data structure of one or more applications installed on the user's device. Generally, the policy list identifies the policy to be applied to the application, and the application list identifies the application and the permissions associated with each corresponding application.
[0037] During the state (c), the user interacts with the application market 150 to send a request to the application market server 103 to browse the application library. The request includes an identifier 114 of the user domain associated with the user and/or user device 104.
[0038] During the state (d), the application market server 103 selects an application that responds to a user request. The application market server 103 also determines that some of the applications requested to be browsed are managed by one or more specific permissions. For example, the application market server 103 can determine that the user is requesting to browse the "communication" application (for example, instant messaging client, email client, chat client), and determine that the "communication" application library available through the application market server 103 The middle is a "communication" application registered with the application market server 103 as a "communication" application that adopts the permission of "access to email data".
[0039] During the state (θ), the application market server 103 sends back information 116 describing the selected application to the user equipment 104. The information 116 includes information describing applications that respond to user requests and are not restricted by policies (such as the policy 107) on the application market server 103. In some embodiments, the information 116 may omit the description of the applications on the application server 103 that have been restricted by the policy. In some embodiments, the information 116 may be a description of both allowed applications and restricted applications, as well as a description of the allowed and/or restricted status of the selected application. For example, the information 116 may describe that "application A" exists in a "communication" application available through the application market server 103, but "application A" is prevented from being downloaded and installed on the user device 104.
[0040] During the state (f), the application market 150 presents a display of the selected application described by the information 116. In the illustrated example, the application market 150 presents an application description 152 and an application description 154. The application descriptions 152, 154 describe (for example, provide application name, summary, screenshots, evaluation information) "application A" and "application B". In this example, both "application A" and "application B" are prevented from being downloaded and installed on the user device 104. For example, both "application A" and "application B" can be email client applications, and therefore both can use the "access email data" permission as part of their functions.
[0041] Since the policy 107 restricts the applications that have been registered for invoking the functions associated with the "access to email data" permission, the application descriptions 152,154 both include that the described applications have been blocked from being downloaded and installed in An indicator 156 on the user equipment 104. Both the application descriptions 152, 154 also include a user control 158 that the user can activate to obtain information about why the corresponding application is blocked. For example, the user can click on one of the user controls 158, and in response, the application market 150 can present an explanation that the corresponding application has been blocked because the user belonging to the "example.com" domain has been blocked Restrict the use of applications that use "access to email data" permission.
[0042] FIG. 2 is a flowchart illustrating an example process 200 for controlling access to an application. In some embodiments, the process 200 can be performed by the application market server 103 of FIG. 1.
[0043] In step 210, a policy including identifying (1) one or more users and (ii) restricted permission data is received from the network and received by one or more servers associated with the application market. In some embodiments, the policy may be received from a server associated with an information technology administrator. For example, during state (b), the application market server 103 can receive a policy 107 from the administrator server 102, where the policy 107 includes identifying user groups (e.g., "*.example.comO and restricted permissions (e.g., "Access to email Data=disabled") data.
[0044] In some embodiments, the policy may be received from a mobile device associated with a specific user. For example, strategy
107 may be provided by the user equipment 104 to the application market server 103.
[0045] In step 220, a request to access one or more applications distributed through the application market is received by a server associated with the application market, wherein the request includes data identifying a specific user among users. For example, in the state (c) period
CN 103988198 Β
In the meantime, the user interacts with the application market 150 to send a request to the application market server 103 to browse the application library. The request includes an identifier 114 of the user domain associated with the user and/or user device 104.
[0046] In some embodiments, identifying one or more of the applications associated with the restricted permission may include identifying one or more of the applications that perform one or more operations associated with the restricted permission . For example, the applications "Α" and "Β" described by the application descriptions 152, 154 can perform operations to access email information and are therefore restricted by the policy 107, which indicates that all users of the "example.com" domain have been targeted Access to email data is disabled.
[0047] In some embodiments, identifying one or more of the applications associated with the restricted permission may include identifying one or more of the applications that declare the use of the restricted permission. For example, the applications "Α" and "Β" described by the application descriptions 152 and 154 can be explicitly, such as through license requirements certification or through reflected metadata, or implicitly such as through the application provided on the application market server. In the above-mentioned application "sandbox", the application can be installed in a simulated deployment environment to detect the functions and resources that the application may try to access during execution.
[0048] In step 230, one or more of the applications associated with the restricted permission are identified by the server associated with the application market. For example, during the state (d), the application market server 103 selects a group of applications that respond to user requests, and also determines that some of the applications that request browsing are managed by one or more specific permissions.
[0049] In step 240, access by a specific user to the application associated with the restricted permission is restricted by the server associated with the application market. For example, in states (e) and (f), the application market server 103 provides information 116 that includes information describing applications that respond to user requests. In some embodiments, the user interface may identify the application associated with the restricted permission as a restricted application. For example, the application descriptions 152 and 154 include an indicator 156 indicating that the application "A" and the application "B" have been "blocked".
[0050] In some embodiments, the user interface may identify one or more applications that are not associated with restricted permissions, and may not identify applications that are associated with restricted permissions. For example, the application market 150 may show application descriptions for applications available for download and installation on the user device 104, and omit application descriptions for blocked applications.
[0051] In some embodiments, a user interface may be provided that identifies applications associated with restricted permissions and includes a label indicating that access to each of the applications associated with restricted permissions is restricted. For example, the application market 150 is a user interface that displays application descriptions 152 and 154, and includes an indicator 156 indicating that the application descriptions 152 and 154 have been blocked from being downloaded and installed on the user device 104.
[0052] In some embodiments, an indicator indicating that access to each of the applications is restricted may be used in the user interface to provide a user requesting the distribution of one or more of the applications. Available as part of the selectable control. For example, the indicator 156 may replace a user control (e.g., an "install" button) that can be activated to download and install unlimited applications. In some embodiments, the indicator indicating that access to each of the applications is restricted may include a disabled control that is distributed for the requesting application. For example, the application description 152 may include an "install" button that is dimmed and/or has been otherwise made visually distinguishable to indicate the unavailability of the associated application. In other examples, the entire application description 152 may be dimmed and/or otherwise made visually different to indicate the unavailability of the associated application.
[0053] In some embodiments, the user interface may include user selectable controls for requesting relaxation of restricted permissions. For example, the application description 152 may include a button that causes the user to request access to the application "A". The request may be sent to the administrator server 102, or may be relayed to the administrator server 102 by the application market server 103. Administrators can
CN 103988198 Β
To receive the request, and respond by creating or modifying a policy that will allow the requested application "Α" to be deployed and installed on the user equipment 104.
[0054] In some embodiments, the server associated with the application market may provide a mark describing each of the applications not associated with the restricted license, and omit describing each of the applications associated with the restricted license. An applied mark. For example, the application market server 103 may search for and return to the application market 150 application descriptions of applications that are allowed to be installed by the user, and omit the results describing applications that have been blocked for the user.
[0055] FIGS. 3A-3I show example screenshots 300a300i of a user interface for an application market that controls access to applications. In some embodiments, the screenshots 300a-300i may be views of the application market 150 of FIG. 1.
[0056] FIG. 3A shows an example screenshot 300a. The screenshot 300a shows the application description 302 and the application description 304. The application description 304 includes a user control 306, which when activated, will indicate the download and installation of the associated application "B" on the user device (such as the user device 104).
[0057] In the illustrated example, the application "A" represented by the application description 302 has been restricted by the application market server (such as the application market server 103). The application description 302 includes an indicator 308 indicating that the application "A" has been blocked. In the illustrated example, the indicator 308 replaces a user control (such as the user control 306), which would have allowed the application associated with the application description 302 to be installed.
[0058] FIG. 3B shows an example screenshot 300b. The screenshot 300b shows the application description 304 and the application description 310. The application description 310 describes the application "A" that has been restricted by the application market server. In the illustrated example, the application description 310 is dimmed to indicate the restricted state of the application "A". In some embodiments, making the application description (such as the application description 310) dimmed may include changing the color saturation, transparency, opacity, measurement, contrast, z-axis depth, color scheme, or other appropriate aspects of these and/or application descriptions. A combination of visual attributes.
[0059] FIG. 3C shows an example screenshot 300c. The screenshot 300c shows the application description 312. The application description 312 includes a warning indicator 314, which warns that the function of the application "A" has been restricted by the administrator. The application description 312 also includes a user control 316, which when activated, initiates the download and installation of the associated application. In some embodiments, the user control 316 can still allow the user to install the application even though some or all of the functions of the application may be limited.
[0060] For example, the application "A" may be a navigation application that provides a way of e-mailing the user's location to others. In this way, the user will still be able to install the app to use its navigation function, but will be prevented from using the app's ability to notify the location by email. Since the user has seen the warning provided by the warning indicator 314 before, the user will experience less confusion or frustration than what they might experience without such advance warning.
[0061] FIG. 3D shows an example screenshot 300d. The screenshot 300d shows the application description 320, the application description 322, and the application description 324. The application description 320 describes the allowed application "Α", the application description 322 describes the blocked application "B", and the application description 324 describes the allowed application "C". In the illustrated example, the presentation of application descriptions 320-324 are arranged in a modified alphabetical order. For example, without modifying the alphabetic presentation order, the application description 322 of the blocked application "B" will be displayed between the application descriptions 320 and 324. However, in the illustrated example, the alphabetic presentation order has been modified to sort and present the application descriptions 320 and 324 of the allowed applications "A" and "C", and the application descriptions of the blocked applications (for example, The application descriptions of blocked applications "B") are ranked and presented as lower than those of allowed applications.
[0062] FIG. 3E shows an example screenshot 300e. The screenshot 300e shows the application description 330, the application description 332, and the application description 334. The application description 330 describes the allowed application "Α", the application description 332 describes the blocked application "B", and the application description 334 describes the allowed application "C". In the illustrated example, the application descriptions of allowed applications "A" and "C"
CN 103988198 Β
The descriptions 330 and 334 are included in the visually distinguished area 336. The application description 332 of the blocked application "B" is included in the visually distinguished area 338. The visually distinguished area 336 provides one or more visual cues identifying the application descriptions 330 and 334 included therein describing applications that the user can download and install. The visually distinguished area 338 provides identification of the application description 332 included therein, which describes one or more visual cues for the application that is blocked by the user.
[0063] FIG. 3F shows an example screenshot 300f. The screenshot 300f shows the application description 340 and the application description 342. The application description 340 describes the allowed application "A", and the application description 342 describes the allowed application "C". In the illustrated example, five other applications and their corresponding application descriptions have been blocked. The blocked applications are indicated by the blocked applications overview 344. In some embodiments, the blocked application overview 344 may notify the user that one or more applications have been blocked from use, and present such a screen space compared to the screen space required to display the application description separately for each blocked application. Information basically does not consume so much screen space.
[0064] The blocked applications overview 344 includes user controls 346. When activated by the user, the user control 346 causes the blocked application described by it to be presented. For example, the user may click on the user control 346, and in response, the screenshot 300f may be updated to resemble the screenshot 300b or the screenshot 300e.
[0065] FIG. 3G shows an example screenshot 300g. The screenshot 300g shows an application description 350 for application "A". The application description 350 includes an indicator 352 for indicating that the application "A" has been blocked by the application market server. When activated, the user control 354 forms additional information about the reason(s) why the associated application is restricted from being used by the user. For example, the user can click on the user control 354 and see the display such as the permissions that have been restricted, the identification of the administrator or management organization that has restricted the permissions, the identification of the range of users affected by the restriction, and/or these and other appropriate information. The combined information screen.
[0066] The application description 350 includes user controls 356. When activated by the user, the user control 356 causes a request for approval for application "A" to be sent. For example, application "A" may have been blocked in the past due to its request to access sensitive functions, but the request has been removed. By clicking on the user control 356, the user can make the administrator follow the application "A" to re-evaluate the application "A" and possibly unblock it so that the user can download and install it.
[0067] FIG. 3H shows an example screenshot 300h. The screenshot 300h shows an application description 360 for the application "A" and an application description 362 for the application "C". In the illustrated example, the description for the application "B" that would otherwise appear between the application description 360 and the application description 362 has been restricted by the application market server. Therefore, the application description for the application "B" is omitted at position 364.
[0068] FIG. 31 shows an example screenshot 300i. The screenshot 300i presents a collection 370 of application descriptions for applications associated with the selected application category 372 (eg, email application). The application description 374 for application "A" includes user controls 376. When selected by the user, the user control 376 initiates a request sent to the application market server for the download and installation of the application "A". Similarly, the application description 378 for application "C" includes user controls 380. When selected by the user, the user control 380 initiates a request sent to the application market server for the download and installation of the application "C".
[0069] The application description 382 for the application "B" includes an indicator 384. In the illustrated example, unlike the applications "A" and "C", the application market server has restricted the application "B". The indicator 384 provides a visual notification that the application "B" described by the application description 382 has been blocked by the application market server from downloading and installing by the user.
[0070] FIG. 4 is a timeline diagram showing example interactions between systems for controlling access to applications of the application market. This interaction occurs between the administrator server 402, the user device 404, and the application market server 406. In some embodiments, the administrator server 402 may be the administrator server 102 of FIG. 1, the user equipment 404 may be the user equipment 104, and
CN 103988198 Β
And the application market server 406 may be the application market server 103.
[0071] The interaction starts at 410, when the administrator server 402 sends policy information to the application market server 406. In some embodiments, the policy information may be the policy 107 of FIG. 1. The policy information describes the permissions that the user and the administrator have selected to allow or disallow for the selected user. For example, the policy information may indicate that all users in the "area51.gov" domain are prevented from using the camera function of the user device 404.
[0072] At 412, the user equipment 404 sends a request to the application market server 406. In some embodiments, the request may be a request for information about a collection of applications displayed in the application market (such as the application market 150). In some embodiments, the request may be a request to download and/or install the selected application.
[0073] In the illustrated example, the application or applications requested by the user equipment 404 have been restricted by the policy sent at 410. The application market server 406 therefore sends a rejection message to the user device 404 at 414.
[0074] At 416, the user equipment 404 sends a relaxation request to the application market server 406. At 416, the application market server 406 forwards the relaxation request to the administrator server 402. The relaxation request is to request the administrator of the administrator server 402 to view the existing policies related to the permission restriction, check and possibly modify them.
[0075] For example, the user of the user equipment 404 may think that the requested application has been blocked by an overly broad policy, and send a request to try to make the policy to be viewed and updated to allow the selected application or application category to be installed. In another example, the user may send a request to obtain an individual or group exemption from one or more policies. For example, users belonging to the group generals. area51. gov can be allowed to install applications that access the camera function, while all other users of area51. gov are still blocked (for example, privates.area51.gov). In yet another example, the user can request an exemption for a specific application. For example, administrators can only allow "whitelisted" (for example, tested, trusted, and approved) email applications to access email data on company user devices (for example, to prevent malicious or poorly written applications from accessing sensitive data) , And therefore when new email applications appear in the application market, they are also blocked by existing policies. The user can send a request to try to make the administrator view the new application and/or add the new application to the "white list" of allowed applications.
[0076] At 420, the relaxation result is sent to the application market server 406. In some embodiments, the relaxation result may include a reflection of the administrator's exemption from the relaxation request. For example, the administrator can update the policy to unblock the selected permission, create a new policy to exempt selected users and/or applications from being unrestricted, reject the request, and these and other appropriate responses to the relaxation request The combination. In some embodiments, the administrator can simply ignore the relaxation request. In this way, the existing policy will remain unchanged and the application market server 406 can basically treat the lack of response as a refusal to relax the request.
[0077] At 422, the relaxation result is sent to the user equipment 402. For example, the relaxation result may indicate that the administrator has changed one or more policies in order to allow the download and installation of applications that were previously blocked for the user of the user device 404.
[0078] At 424, a response to the relaxation is sent from the user device 404 to the application market server 406. For example, the user can try again to download and install an application that was blocked before but is now allowed as a result of relaxation. At 426, the installation information is sent from the application market server 406 to the user device 404. For example, the installation information may be an application description, or it may be installable application code.
[0079] FIG. 5 is a timeline diagram showing exemplary inter-system interactions for synchronizing policies for controlling access to applications of the application market. This interaction occurs between the administrator server 502, the user device 504, and the application market server 506. In some embodiments, the administrator server 502 may be the administrator server 102 of FIG. 1 or the administrator server 402 of FIG. 4, the user equipment 504 may be the user equipment 104 or 404, and the application market server 506 may be the application market.
CN 103988198 Β
Farm server 103 or 506.
[0080] At 510, the administrator server 502 sends the policy "Α" to the user equipment. The policy "Α" includes information describing the permissions that have been restricted for applications running on the user equipment 504. For example, the administrator may push or otherwise install the policy description on the user equipment 504 to enable the user equipment 504 to allow or prevent applications from accessing selected functions of the user equipment 504.
[0081] At 512, the administrator server 502 sends the policy "B" to the application market server 506. The policy "B" includes information describing the permissions that have been restricted for applications running on the user equipment 504. For example, the policy "B" may instruct the application market server 506 to selectively allow or block applications that utilize the selected function of the selected user's user equipment. In some embodiments, the strategy "Α" may be different from the strategy "B". For example, the policy "Α" may agree to the selected permission and the policy "Β" may reject it.
[0082] In 514, the user equipment sends a policy request to the application market server 506. The request includes policy "Α". The policy request is a request for the application market server 506 to synchronize or update the policy information appearing on the user equipment 504 in other ways. For example, the administrator may have blocked the selected function in the policy "Α", but then decides to allow the function in the policy "B". By requesting the application market server 506 to synchronize the policy "Α" with the policy "B", the policy on the user equipment 504 can be updated to reflect the current management restrictions, and thus can allow previously blocked applications to be installed and installed on the user equipment 504. operating.
[0083] At 516, the application market server 506 performs a strategy synchronization operation. In some embodiments, the policy synchronization operation may favor the most recent policy restrictions. For example, if the strategy "B" is closer than the strategy "Α", the settings provided by the strategy "Β" can be implemented for the settings also found in the strategy "Α". In some embodiments, the policy synchronization operation may favor the most restrictive policy restrictions. For example, if the policy "Α" restricts the permissions allowed by the policy "Β", the settings provided by the policy "Α" can be implemented for the settings also found in the policy "Β".
[0084] At 518, the application market server 506 sends a response to the user equipment 504. The response includes information describing the synchronized or otherwise updated policy to be applied to the application operating on the user equipment 504.
[0085] At 520, the application market server 506 sends policy synchronization information to the administrator server 502. For example, the application market server 506 may report a conflict determined to exist between the strategy "A" and the strategy "B". The administrator can use such information to update or otherwise modify the permission policy for the user device 504 and/or the application market server 506, or the administrator can be prompted to directly perform management operations on the user device 504.
[0086] FIG. 6 is a block diagram of a computing device 600, 650 as a client or as a server or multiple servers that can be used to implement the systems and methods described herein. Computing device 600 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframes, and other suitable computers. Computing device 650 is intended to represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, and other similar computing devices. The components shown here, their connections and relationships, and their functions are only intended to be examples, and are not intended to limit the implementation of the invention described and/or claimed herein.
[0087] The computing device 600 includes a processor 602, a memory 604, a storage device 606, a high-speed interface 608 connected to the memory 604 and a high-speed expansion port 610, and a low-speed interface 612 connected to the low-speed expansion port 614 and the storage device 606. Each of the components 602, 604, 606, 608, 610, and 612 are interconnected using various buses, and can be installed on a common motherboard or installed in other suitable ways. The processor 602 is capable of processing instructions for execution within the computing device 600 to display graphical information for the GUI on an external input/output device (such as the display 616 coupled to the high-speed interface 608), the instructions including being stored in the memory 604 or Instructions in device 606. In other embodiments, if appropriate
CN 103988198 Β
Suitably, multiple processors and/or multiple buses, as well as multiple memories and memory types can be used. Moreover, multiple computing devices 600 may be connected to each device that provides the necessary operations of various parts (for example, as a server group, a blade server group, or a multi-processor system).
[0088] The memory 604 stores information in the computing device 600. In one embodiment, the memory 604 is a non-transitory computer readable medium. In one embodiment, the memory 604 is one or more volatile storage units. In another embodiment, the memory 604 is one or more non-volatile storage units.
[0089] The storage device 606 is a non-transitory computer-readable medium capable of providing large-scale storage for the computing device 600. In one embodiment, the storage device 606 is a computer-readable medium. In various embodiments, the storage device 606 may be a floppy disk device, a hard disk device, an optical disk device, a tape device, a flash memory or other similar solid-state storage devices, or a device array, including devices in a storage area network or other configurations. In one embodiment, the computer program product is tangibly implemented in an information carrier. The computer program product contains instructions that, when executed, perform one or more methods such as those described above. The information carrier is a computer or machine-readable medium, such as the memory 604, the storage device 606, and the memory on the processor 602.
[0090] The high-speed interface 608 manages bandwidth-intensive operations for the computing device 600, while the low-speed interface 612 manages lower bandwidth-intensive operations. Such assignment of responsibilities is only exemplary. In one embodiment, the high-speed interface 608 is coupled to the memory 604, the display 616 (for example, through a graphics processor or accelerator), and to a high-speed expansion port 610 that can accept various expansion cards (not shown). In the described embodiment, the low-speed interface 612 is coupled to the storage device 606 and the low-speed expansion port 614. The low-speed expansion port 614, which can include various communication ports (eg, USB, Bluetooth, Ethernet, wireless Ethernet), can be coupled to one or more input/output devices, such as keyboards, pointing devices, scanners, or, for example, via a network The adapter is coupled to networked devices such as switches and routers.
[0091] As shown in the figure, the computing device 600 may be implemented in a variety of different forms. For example, it can be implemented as a standard server 620, or multiple servers in such a server group. It can also be implemented as part of the rack server system 624. In addition, it can also be implemented in a personal computer such as a laptop 622. Alternatively, components from computing device 600 may be combined with other components in a mobile device (not shown) such as device 650. Each such device may include one or more computing devices 600, 650, and the entire system may be composed of multiple computing devices 600, 650 communicating with each other.
[0092] Among other components, the computing device 650 includes a processor 652, a memory 664, an input/output device such as a display 654, a communication interface 666, and a transceiver 668. The device 650 may also be provided with a storage device such as a microdrive or other devices to provide additional storage. Each of the components 650, 652, 664, 654, 666, and 668 are interconnected using various buses, and several components can be installed on a common motherboard or installed in other suitable ways.
[0093] The processor 652 can process instructions executed in the computing device 650, including instructions stored in the memory 664. The processor may also include separate analog and digital processors. For example, the processor may provide coordination of other components of the device 650, such as controlling a user interface, an application run by the device 650, and wireless communication performed by the device 650.
[0094] The processor 652 may communicate with the user through a display interface 656 and a control interface 658 coupled to the display 654. The display 654 may be, for example, a TFT LCD display or an OLED display, or other appropriate display technology. The display interface 656 may include appropriate circuitry for driving the display 654 to display graphics and other information to the user. The control interface 658 may receive commands from the user and convert them for submission to the processor 652. In addition, an external interface 662 for communicating with the processor 652 may be provided, so that the device 650 can perform near field communication with other devices. For example, external connection
Port 662 may provide wired communication (for example, via a docking process) or wireless communication (for example, via Bluetooth or other such technology).
[0095] The memory 664 stores information in the computing device 650. In one embodiment, the memory 664 is a computer-readable medium. In one embodiment, the memory 664 is one or more volatile memory units. In another embodiment, the memory 664 is one or more non-volatile memory units. An expansion memory 674 may also be provided and connected to the device 650 through an expansion interface 672. For example, the expansion interface 672 may include a SIMM card interface. Such an extended memory 674 can provide additional storage space for the device 650, or can also store application programs or other information for the device 650. Specifically, the extended memory 674 may include instructions to perform or supplement the processing described above, and may also include security information. For example, the extended memory 674 can thus be provided as a security module of the device 650, and can be programmed with instructions that allow the device 650 to be used safely. In addition, security applications and additional information can be provided via the SIMM card, such as placing identification information on the SIMM card in a non-intrusive manner.
[0096] For example, as described below, the memory may include flash memory and/or NVRAM memory. In one embodiment, the computer program product is tangibly implemented in an information carrier. The computer program product also contains instructions, which when executed, implement one or more methods such as those described above. The information carrier is a computer or machine-readable medium, such as the memory 664, the extended memory 674, and the memory on the processor 652.
[0097] The device 650 may perform wireless communication through the communication interface 666. If necessary, the communication interface 666 may include a digital signal processing circuit. The communication interface 666 may provide communication in various modes or protocols, among others, such as GSM voice calling, SMS, EMS or MMS messaging, CDMA, TDMA, PDC, WCDMA, CDMA2000 or GPRS. For example, such communication may be performed through the radio frequency transceiver 668. In addition, for example, Bluetooth, WiFi, or other such transceivers (not shown) may be used for short-range communication. In addition, the GPS receiver module 670 can provide the device 650 with additional wireless data, which can be appropriately used by applications running on the device 650.
[0098] The device 650 may also use an audio codec 660 for audible communication, which receives voice information from a user and converts it into usable digital information. The audio codec 660 may also generate audible sound for the user (such as through a speaker), for example in the earpiece of the device 650. Such sounds may include sounds from voice phone calls, may include recorded sounds (for example, voice messages, music files, etc.), and may also include sounds generated by applications operating on the device 650.
[0099] As shown, the computing device 650 can be implemented in a number of different ways. For example, it may be implemented as a cellular phone 680. It can also be implemented as part of a smart phone 682, a personal digital assistant, or other similar mobile devices.
[0100] Various implementations of the systems and technologies described herein can be implemented with digital circuits, integrated circuits, specially designed ASICs (application specific integrated circuits), computer hardware, firmware, software, and/or combinations thereof. These various implementations may include implementations in one or more computer programs, which may be executed and/or interpreted on a programmable system including at least one programmable processor, and the programmable system may be a dedicated Or universally, it is coupled to receive data and instructions from a storage device, at least one input device, and at least one output device, and transmit data and instructions to them.
[0101] These computer programs (also referred to as programs, software, software applications or codes) include machine instructions for programmable processors, and can be implemented in high-level programs and/or object-oriented programming languages, and/or in Implementation in assembly/machine language. As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and/or device used to provide machine instructions and/or data to a programmable processor (for example, Magnetic disk, optical disk, memory, programmable logic device (PLD), which includes a machine-readable medium that receives machine instructions as machine-readable signals. the term
CN 103988198 Β
"Machine-readable signal" refers to any signal used to provide machine instructions and/or data to a programmable processor.
[0102] In order to provide interaction with the user, the system and technology described herein can be used to display information to the user display device (for example, CRT (cathode ray tube) or LCD (liquid crystal display) monitor) and the user can Implementation on a computer through a keyboard and pointing device (for example, a mouse or trackball) that provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensor feedback (for example, visual feedback, auditory feedback, or tactile feedback); and the input from the user can be in any form Receive, including voice, voice or tactile input.
[0103] The systems and technologies described herein can be implemented in a computing system that includes back-end components (for example, data servers), or it includes middleware components (for example, application servers), or it includes front-end components (For example, a client computer with a graphical user interface or web browser through which a user can interact with the implementation of the systems and technologies described herein), or any combination of these back-end, middleware, or front-end components. The components of the system can be interconnected through any form of medium or digital data communication (for example, a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0104] The computing system may include a client and a server. The client and server are usually remote from each other and typically interact through a communication network. The relationship between the client and the server is derived from the computer programs running on the respective computers and has a client-server relationship with each other.
[0105] A number of embodiments have been described. However, it will be understood that various changes can be made without departing from the spirit and scope of the present invention. For example, the various forms of processes shown above can be used with reordered, added or removed steps. In addition, although several applications of the system and method have been described, it should be recognized that a variety of other applications are foreseen. Therefore, other implementations are within the scope of the following claims.
CN 103988198 Β
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US6092194A | Cites | United States of America | Y | Search report | 5-9,12,14,20-24,29 |
| US20110230211A1 | Cites | United States of America | Y | Search report | 5-9,12,14,20-24,29 |
| CN102077208A | Cites | China | A | Search report | 1-29 |
| CN1841397A | Cites | China | A | Search report | 1-29 |
| CN101005699A | Cites | China | A | Search report | 1-29 |
| EP1950681A1 | Cites | European Patent Office (EPO) | A | Search report | 1-29 |
| US5991877A | Cites | United States of America | A | Search report | 1-29 |
| US5974549A | Cites | United States of America | A | Search report | 1-29 |
18 members in 4 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 13270457 | United States of America | – | |
| 201113270457 | United States of America | A | |
| 13552985 | United States of America | – | |
| 201213552985 | United States of America | A | |
| 2012057883 | United States of America | W |
Members18
| Document | Office | Kind | |
|---|---|---|---|
| US8239918B1 | United States of America | B1 | |
| US2013091542A1 | United States of America | A1 | |
| WO2013055532A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN103988198A | China | A | |
| EP2766822A1 | European Patent Office (EPO) | A1 | |
| US8832817B2 | United States of America | B2 | |
| US2014366160A1 | United States of America | A1 | |
| EP2766822A4 | European Patent Office (EPO) | A4 | |
| US9721074B2 | United States of America | B2 | |
| CN103988198BThis record | China | B | |
| CN107480517A | China | A | |
| CN107506620A | China | A | |
| US2017372044A1 | United States of America | A1 | |
| US9898592B2 | United States of America | B2 | |
| CN107506620B | China | B | |
| CN107480517B | China | B | |
| EP2766822B1 | European Patent Office (EPO) | B1 | |
| EP4009214A1 | European Patent Office (EPO) | A1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Transfer of patent rightTR01 | TR01 | |
| Change in the name or title of a patent holderCP01 | CP01 | |
| Patent grantGrantedGR01 | GR01 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 103988198
- Application
- 800571971
Titles2
- Chinese
- 应用市场管理控件
- English
- Application market management controls
Classification
- CPC, 9
- G06F21/12
- G06F21/50
- G06F21/10
- G06F21/128
- G06F21/30
- G06F21/604
- G06F21/6245
- G06F21/629
- G06F2221/2141
- IPC, 5
- G06F17 00
- G06F7 04
- G06F15 16
- G06F17 30
- H04L29 06