Restricted execution modes
Abstract
In the restricted execution mode embodiment, the mobile device displays the device lock screen on the integrated display device, and transitions from the device lock screen to display the shared space user interface in the shared space. The transition to display the shared space user interface does not need to receive the PIN code entered on the device lock screen. The mobile device implements a restricted execution service that is implemented to activate the restricted execution mode of the mobile device and restrict access of the device application to the device content while the restricted execution mode is activated. To do. The restricted execution service can also allow access to the device content of shared device applications contained within the shared space while restricted execution mode is activated.

Term
6.3 yearsto projected expiry
Projected expiry 23 December 2032, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
10 claims: 4 independent, 6 dependent
- 1モバイルデバイスであって、 デバイスロック画面を表示し、該デバイスロック画面上に入力される認証情報を必要とせずに、共有空間の共有空間ユーザインタフェースに遷移するように構成される、ディスプレイデバイスと、 当該モバイルデバイスの制限付き実行モードをアクティブにし、 前記制限付き実行モードがアクティブ化されている間、デバイスコンテンツへのデバイスアプリケーションのアクセスを制限する ように構成される、制限付き実行サービスを実装する処理システムと を備える、モバイルデバイス。
- 2前記共有空間は、共有デバイスアプリケーションを含み、 制限付き実行サービスは、前記制限付き実行モードがアクティブ化されている間、前記デバイスコンテンツへの前記共有デバイスアプリケーションのアクセスを許可するように構成される、請求項1に記載のモバイルデバイス。
- 3前記デバイスアプリケーションは、前記デバイスコンテンツについての要求により前記共有デバイスアプリケーションを呼び出すように構成され、 前記制限付き実行サービスは、前記制限付き実行モードがアクティブ化されている間、前記共有デバイスアプリケーションを介した前記デバイスコンテンツへの前記デバイスアプリケーションのアクセスを制限するように更に構成される、請求項2に記載のモバイルデバイス。
- 4前記デバイスアプリケーションは、前記デバイスコンテンツについての要求により前記共有デバイスアプリケーションを呼び出すように構成され、前記要求は、前記デバイスアプリケーションが前記共有空間内の前記共有デバイスアプリケーションを介して前記デバイスコンテンツへアクセスすることを許可されていることを示す要求トークンを含み、 前記制限付き実行サービスは、前記制限付き実行モードがアクティブ化されている間、前記要求トークンに基づいて、前記共有デバイスアプリケーションを介した前記デバイスコンテンツへの前記デバイスアプリケーションのアクセスを許可するように更に構成される、請求項2に記載のモバイルデバイス。
- 5前記デバイスアプリケーションは、前記デバイスコンテンツにアクセスするタスクコールを開始するように構成され、 前記制限付き実行サービスは、前記制限付き実行モードがアクティブ化されている間は制限されるように指定されている1つ又は複数のデバイスアプリケーションタスクに基づいて、前記デバイスコンテンツへの前記アクセスを制限するように構成される、請求項1に記載のモバイルデバイス。
- 6モバイルデバイスの一体型ディスプレイデバイス上にデバイスロック画面を表示するステップと、 前記デバイスロック画面を表示することから、前記デバイスロック画面上に入力される認証情報を必要とせずに、共有空間の共有空間ユーザインタフェースを表示するように遷移するステップと、 前記モバイルデバイスの制限付き実行モードをアクティブにするステップと、 前記制限付き実行モードがアクティブ化されている間、デバイスコンテンツへのデバイスアプリケーションのアクセスを制限するステップと を含む、方法。
- 7前記制限付き実行モードがアクティブ化されている間、前記共有空間内に含まれる共有デバイスアプリケーションの前記デバイスコンテンツへのアクセスを許可するステップを更に含む、請求項6に記載の方法。
- 8前記制限付き実行モードがアクティブ化されている間、前記デバイスアプリケーションが、前記デバイスコンテンツを求める要求により前記共有デバイスアプリケーションを呼び出すとき、前記共有デバイスアプリケーションを介して前記デバイスコンテンツへのアクセスを制限するステップを更に含む、請求項7に記載の方法。
- 9前記制限付き実行モードがアクティブ化されている間、前記デバイスアプリケーションがタスクコール内に含んでいる、前記デバイスコンテンツを求める前記共有デバイスアプリケーションに対する要求トークンに基づいて、前記共有デバイスアプリケーションを介した前記デバイスコンテンツへの前記デバイスアプリケーションのアクセスを許可するステップを更に含み、前記要求トークンは、前記デバイスアプリケーションが、前記共有空間内の前記共有デバイスアプリケーションを介した前記デバイスコンテンツへのアクセスを許可されることを示す、請求項7に記載の方法。
- 10前記制限付き実行モードがアクティブ化されている間は制限されるように指定されている1つ又は複数のデバイスアプリケーションタスクに基づいて、前記デバイスコンテンツへの前記アクセスを制限するステップを更に含む、請求項9に記載の方法。
Independent claims10
108 paragraphs, as filed
The present invention relates to a restricted execution mode.
Many types of devices, such as mobile phones, tablet devices and other computing, communication and entertainment devices, are increasingly presenting more functionality, applications and characteristics that are convenient for users and are personal. You can improve your time as well as your work and social activities. For example, mobile phones can be used not only for text, email and voice communications, but also for listening to music, surfing the internet, watching video content, entertainment like games, and imaging photos and videos. Can also be used. Similarly, portable tablet devices can be used for a variety of entertainment and photographic features as well as email, browsers, navigation and other computing applications. In addition to the many computing, communication and entertainment applications available to users of mobile phone or tablet devices, an infinite number of seemingly third party applications and features are also available for download to the device.
Parents of young children who do not yet have their own mobile phones want their children to "play" on their phones to play games, take pictures, listen to music, and do other activities. I often experience the situation. Typically, parents may give their phone to a young child in the backseat of a car while driving to keep the child entertained. Parents are unaware of which features and applications on their device they will access, such as unintentional access to web browsers and email applications, and either audio settings, alarm settings, calendar notifications, etc. You may not know that your device settings have changed.
0004This description of the "Summary of the Invention" is further described in the "Modes for Carrying Out the Invention" below and / or introduces features and simplified concepts relating to the restricted execution mode shown in the drawings. This description of the "Summary of the Invention" should not be construed as explaining the essential features of the claimed subject matter and should not be used to establish or limit the scope of the claimed subject matter. ..
0005The restricted execution mode will be described. In embodiments, the mobile device can display the device lock screen on the integrated display device and display the transition from the device lock screen to display the shared space user interface of the shared space. The transition to display the shared space user interface occurs without receiving a PIN code or other credentials entered on the device lock screen. A mobile device is a restricted execution service that is implemented to activate the restricted execution mode of the mobile device and restrict access of the device application to the device content while the restricted execution mode is activated. To implement. The restricted execution service can also allow shared device applications contained within a shared space to access device content while restricted execution mode is activated.
0006In embodiments, the restricted execution service transfers to the device content through the shared device application when the device application calls the shared device application in response to a request for the device content while the restricted execution mode is activated. Restrict access to device applications. Alternatively, the restricted execution service allows the device application to include the device application in the task call based on the request token to the shared device application for device content while the restricted execution mode is activated. You can allow access to device content through the application. The request token indicates that the device application is allowed to access the device content through the shared device application in the shared space.
0007In embodiments, is the device application implemented so that when the device application is included in the shared space as a shared device application, the user can be specified to allow the device application to access the device content? Can be designed. Alternatively, the device application may be designed so that access to the device content is not granted, even if the device application is contained within a shared space. In addition, this type of device application may be implemented as not even qualified to be user-specified to be contained within a shared space. Device applications contained within the shared space can initiate task calls to access device content. However, the restricted execution service restricts access to device content based on one or more of the device application tasks that are designated to be restricted while the restricted execution mode is active. The restricted execution service can also restrict device applications from the mobile device's file system while restricted execution mode is activated.
0008Embodiments of the restricted execution mode will be described with reference to the drawings. In the drawings, the same reference numbers can be used throughout to refer to similar functions and components shown in the drawings.
<figref num="1">It is a figure which shows the example of the restricted execution mode.</figref><figref num="2">It is a figure which shows the exemplary system which can implement the embodiment of the restricted execution mode.</figref><figref num="3">It is a figure which shows the exemplary method of the restricted execution mode which concerns on one or more embodiments.</figref><figref num="4">It is a figure which shows the exemplary method of the restricted execution mode which concerns on one or more embodiments.</figref><figref num="5">It is a figure which shows the exemplary method of the restricted execution mode which concerns on one or more embodiments.</figref><figref num="6">FIG. 5 illustrates an exemplary system in which an embodiment of a private dialogue hub can be implemented.</figref><figref num="7">FIG. 5 illustrates an exemplary system in which restricted execution modes and / or embodiments of family coordination can be implemented.</figref><figref num="8">It is a figure which shows the service and function of various client devices which concerns on one or more embodiments.</figref><figref num="9">It is a figure which shows the example of the family hub which concerns on one or more embodiments.</figref><figref num="10">It is a figure which shows the exemplary system which has the exemplary device which can implement the embodiment of the restricted execution mode.</figref>
An embodiment of a restricted execution mode is described to provide a restricted execution service that can be implemented as a client device service or application in mobile phones, portable tablet devices or other types of computing and / or communication devices and the like. The restricted execution mode allows the implementation of a shared space on the device. In a shared space on the device, the user owner can include a device application that guests or children can access without requiring a password, and the device application will access other private device content on the device. It will be programmatically prevented from doing so.
There may be situations where the user owner of a device wants to have access to some content or application on the mobile phone without unlocking the mobile phone with a PIN code or other credentials. is there. Restricted execution mode allows user owners to make some experiences available without the need for password access, without jeopardizing sensitive personal or corporate data. In implementations, restricted execution modes allow applications to run, but use several mechanisms such as security capabilities, blocked navigation, and application origin to address sensitive data and experience. Restrict access to. If an application has certain security capabilities, then when the application attempts to access a protected resource, runtime checks are central, and if the application is running in a restricted execution zone, it depends on the application. An error that can be dealt with is returned. When the device is operating in restricted execution mode, the device application is said to be operating in a restricted execution "zone".
Due to the security capabilities of blocked navigation, applications often utilize built-in tasks to complete user actions such as sending emails, making phone calls, and so on. When restricted execution mode is activated on a device, the beginning of a device application task at runtime is considered to determine whether the device application, and more specifically the task, is allowed. .. An application task that is generally synonymous with an application programming interface (API) call may include an API call aspect of data access, but this application task initiates one or more specific actions that differ from data access. Task requests, including requests, may include metadata associated with the actions of the requested task. The level of functionality is provided on a per-task basis to determine whether one or more actions of the requested task will be available in restricted execution mode during the beginning of the task request runtime. decide. The device application can be executed by the device, but when the restricted execution mode is activated in the device, only some functions of the device application will be operated.
Examples of limiting the functionality of a device application are not allowing the device application to be fully launched, or API calls available to the device application when the mobile device is operating in normal user mode. It may include limiting the device application to call only a limited subset of API calls that are narrower than the normal set. Restricting access to device content can also include disallowing certain API calls that provide access to a particular set of data or content. In many cases, restricting functionality or access is the analysis and modification of access control lists (ACLs), access control entries (ACEs) or similar file system access control metadata held by the file system. Does not include doing. For example, a device application may have restricted access to device content while restricted execution mode is active on the device.
When operating in a restricted execution zone, all navigation that requires the application is selected, but only the navigation permitted by the system can continue. Other navigations fail in a backward compatible way, so legacy applications do not need to be updated to work in restricted execution zones. With application-based security capabilities, only applications originating and / or downloaded from first-party providers can operate (eg, run) in restricted execution mode. This ensures that applications that are not security checked and may access sensitive and / or personal data on the device will not work unless the user first unlocks the device.
The functions and concepts of the restricted execution mode can be implemented in any number of different devices, systems, environments and / or configurations, but embodiments of the restricted execution mode include the following exemplary devices, systems and methods. Explained in the context of.
FIG. 1 illustrates an example of a user interface in restricted execution mode. The illustrated mobile device 100 may be any one or combination of mobile phones, tablet devices, computing devices, communication devices, entertainment devices, gaming devices, navigation devices and / or other types of portable electronic devices. Can be done. The shared space is for user access to the functionality of device applications that do not require a password, and for access to any application, function, and mechanism of the mobile device 100 designated within the shared space by the user. Can be implemented.
The illustrated mobile device 100 includes an integrated display device 102 and may display a user interface on the integrated display device 102, such as a device lock screen 104 indicating that the device is locked at 106. it can. For example, mobile device user owners may not allow others to access the full functionality of applications such as email and text, and / or personal identification numbers (PINs), login information or other credentials. You may set the device to lock when not in use so that you cannot access the Internet through a browser application without providing such credentials.
The user owner of the mobile device 100 allows another person to use the phone and hand over the phone by entering a PIN or other credentials without unlocking the device from the device lock screen 104. Can be done. As shown in 108, the borrower can swipe the lock screen of the device by gesture input to access the shared space user interface 110 as shown in 112. The shared space user interface 110, when displayed on a display device, provides access to a limited subset of application functionality. The borrower accesses the shared space user interface without entering a PIN or other credentials. In various implementations, the gesture input can be any type of user and / or gesture input in any direction on the integrated display device 102 of the mobile device. Alternatively, any type of device, button and / or gesture input may be used for an effective transition from the device lock screen 104 to the shared space user interface 110.
FIG. 2 illustrates an exemplary system 200 that can implement a restricted execution mode embodiment. This exemplary system has a mobile device 100 having an integrated display device 102 capable of displaying a user interface such as a shared space user interface 110 representing a shared space on the device, as described in connection with FIG. including. In addition, mobile devices are implemented with various components, such as a processor and / or memory system, and any number of different components and combinations thereof as further described in connection with the exemplary device shown in FIG. It is possible.
The mobile device 100 includes a restricted execution service 202. The restricted execution service 202 may be implemented as a software application (eg, executable instruction) stored on a computer-readable storage medium, such as any suitable memory device or electronic data storage. Further, the restricted execution service 202 can be executed by the processing system of the mobile device to implement an embodiment of the restricted execution mode as described herein. The Restricted Execution Service 202 may be implemented as an independent device application that can be run on the device, interfacing with many applications, mechanisms and functions of the device.
The exemplary system 200 may also include cloud storage and service 206. The cloud storage and service 206 is of any type of cloud-based (eg, network-based) used to store or retain accessible data 210 (eg, data accessible by a device application on the mobile device 100). Data service 208 can be included. Any of the devices and services described herein (eg, implemented as a server device) can communicate over network 212, which is implemented to include wired and / or wireless networks. Can be done. Networks can also be implemented using any type of network topology and / or communication protocol and are represented as a combination of two or more networks, including IP-based networks and / or the Internet. It can be implemented otherwise.
The restricted execution service 202 limits and / or limits the device application 218 and the shared device application 220 contained in the shared space 216 that can be accessed without the need for a PIN or authentication information. Implemented to manage mode 214. Device application 218 can include any type of software application and its features and characteristics that run on the device such as messaging, gaming, media playback, document viewing and user interaction with communication applications. The device application may include system level components. A system-level component is a component that is normally not accessed or used by the user of the device, but is typically running in the background while the device is in operation. The shared device application can include any subset of the device application, and the shared device application is for limited and / or limited functionality when restricted execution mode 214 is activated on the device. When included in shared space 216, it is designated as a shared device application.
The user owner of the mobile device 100 selects device applications and features and / or device content that can be included in the shared space and accessible to children or guests while restricted execution mode is activated. can do. In addition, device applications may be allowed a limited level of functionality (ie, the application may run) while running in shared space, but access such as contacts, email and calendar databases. The restricted device content 222 is generally not yet accessible and access to the device file system is limited.
When restricted execution mode is activated, content databases, device file systems, internet access and other device content and features can be protected from device application access. For example, a device application that can access the internet, email, contacts, etc. has the device application already added to the shared space when the device is unlocked and operating in normal user mode. When restricted execution mode is activated, such as when limited functionality within a shared space is allowed, it will be automatically restricted. As an example, a digital camera application that has already been added to the shared space will allow the user to take and view new photos, but previous photos will be viewed when restricted execution mode is active on the device. That will be restricted.
The shared space user interface 110 of the shared space can be customized by the user owner of the device. For example, the user owner can add applications such as game and music applications to the shared space, and as a result, the added application can be recognized and launched in the shared space, perhaps with limited functionality. it can. However, an application that is not recognized in the shared space may not be able to start in the shared space. For example, if a game application pinned or recognized in a shared space attempts to launch a browser application on its own (eg, as part of running the game), the restricted execution service 202 will allow the browser application to launch. It will be checked whether it is pinned and recognized in the shared space. If the browser application is not recognized in the shared space, the restricted execution service will not be able to launch the application. Alternatively, if the browser application is recognized in the shared space, the browser application can be launched in the shared space by the game application.
As described in connection with FIG. 1, an input such as a gesture input or a device selectable control input can be received and the restricted execution service 202 is a PIN code or other on the device lock screen. The transition is started from the display of the device lock screen 104 to display the shared space user interface 110 of the shared space 216 without receiving the input of the authentication information. The restricted execution service 202 is implemented to manage the shared space 216 when the restricted execution mode 214 is activated. The restricted execution service 202 activates the restricted execution mode 214 of the mobile device 100, and while the restricted execution mode is activated, the device content 222 and the device application 218 access to the file system of the mobile device. And / or the application can be limited to a limited set of functionality or tasks.
The shared space 216 can include the shared device application 220, and the restricted execution service 202 can grant the shared device application access to the device content 222 while the restricted execution mode 214 is activated. .. The restricted execution service 202 can specify that when the device application 218 is included as a shared device application in the shared space 216, the user can specify to allow the device application to access the device content. Can be determined whether is implemented or designed. Alternatively, the device application may be designated not to be granted access to the device content, even if the device application is contained within a shared space. In addition, this type of device application may be implemented as not even qualified to be user-specified to be contained within a shared space.
In some restricted modes, the device application configuration is designed or programmed to indicate whether, in one restricted mode, the device application is always allowed to operate (eg, run) regardless of the user's choice. May be done. For example, a sensitive enterprise application, or another application downloaded from a third-party application store that may have access to private enterprise data, should operate (eg, run) in any restricted mode, if the user so desires. May be configured so that is never allowed. Some device application configurations allow a subset of games or applications in Kids Zone restricted mode, or allow a subset of camera lens applications to work when the phone is locked. , Can be user controlled to indicate whether it should be allowed to operate in a particular restricted mode.
Can the Restricted Execution Service 202 navigate a given device application, regardless of the reason for the navigation request, taking into account the current restricted mode and the system and user configuration of the application in question? It can also be implemented to evaluate whether or not. In addition, it is possible to maintain a separate navigation stack for the normal mode user experience and the current restricted execution mode. The restricted execution service 202 uses when the application migration from the normal mode stack to the restricted mode stack and vice versa should be permitted or denied based on the necessity of the scenario, and the application in each stack should be closed. It is also implemented to make decisions based on possible resources and transitions between restricted modes.
The device application 218 may initiate a task call to the shared device application 220 with a request for device content 222, and the restricted execution service 202 may initiate a shared device while restricted execution mode 214 is activated. You can restrict access of the device application to the device content through the application. The device application may also initiate a task call to operating system 204 to request access to the device content, and the restricted execution service will now be restricted while restricted execution mode is activated. Access to device content can be restricted based on one or more specified device application tasks.
Alternatively, the device application 218 can initiate a task call to the shared data application 220 with a request for device content 222, which request is made by the device application via the shared device application in the shared space 216. Includes a request token indicating that you are allowed to access the content. The restricted execution service 202 can then allow the device application to access the device content through the shared device application based on the request token while the restricted execution mode is activated. The restricted execution service deactivates the restricted execution mode in response to the PIN code or credentials entered on the device lock screen, and the device application 218 has unlimited access to the device content 222 on the mobile device. You can also return to normal user mode.
The restricted execution service 200 implements a mechanism that indicates in which restricted mode the device application can operate (for example, execute) based on the task information field of the device application task. The task information field indicates whether a particular task can be allowed to run in the shared space when restricted run mode is activated. This new field will be a bitmask. The bitmask will be used by the navigation server to compare with the navigation filter mask that the mobile UI will give when entering restricted mode. These are marked per task instead of the application. This is because some first-party device applications have tasks that are allowed to function in a children's shared space (eg, kids' corner), but not necessarily while the restricted execution mode is active on the device. Not all functionality is allowed. When a device application is allowed to run in shared space, the restricted execution service is from the caller (eg, the device application) that initiates the task call, through the application layer, based on the token passed with the core system components. API task calls can be tracked, but without this token it would not be possible to determine if the task call originated from a device application running in shared space. Tokens can be used to determine if a task call is protected from restricted execution mode.
The exemplary methods 300, 400 and 500 will be described with reference to FIGS. 3-5, respectively, according to one or more embodiments of the restricted execution mode. In general, any of the services, components, modules, methods and operations described herein, using software, firmware, hardware (eg, fixed logic circuits), manual processing, or any combination thereof. Can be implemented. Illustrative methods may be described in the general context of executable instructions stored on computer-readable storage media local and / or remote to the computing system, and implementations include software applications, programs and. Functions and the like can be included.
FIG. 3 illustrates an exemplary method 300 of a restricted execution mode. The order in which the methods are described is not intended to be construed as limiting, and any number of method actions or combinations thereof may be combined in any order to implement a method or alternative method. ..
At 302, the device lock screen is displayed on the integrated display device of the mobile device. For example, the mobile device 100 (FIG. 1) displays the device lock screen 104 on the integrated display device 102 of the mobile device. At 304, the display transitions from the device lock screen to display the shared space user interface of the shared space without the need for a PIN code or other authentication information entered on the device lock screen. For example, the input system of the mobile device 100 receives an input such as a gesture input or a device selectable control input, which does not require a PIN code or other credentials to be entered on the device lock screen. This is effective for the transition from the display of the device lock screen 104 to the display of the shared space user interface 110 of the shared space 216.
At 306, the restricted execution mode of the mobile device is activated. For example, the restricted execution service 202 of the mobile device 100 activates the restricted execution mode 214 of the mobile device in response to entering the shared space. At 308, access to the device application to the device content is restricted while the restricted execution mode is activated. For example, the restricted execution service 202 of the mobile device 100 restricts access of the device application 218 to the device content 222 while the restricted execution mode 214 is activated.
At 310, the restricted execution mode is deactivated in response to a PIN code or other credentials entered on the device lock screen. For example, the restricted execution service 202 of the mobile device 100 deactivates the restricted execution mode in response to a PIN code or other authentication information entered on the device lock screen. At 312, the device returns to the user mode of the mobile device where the device application is not restricted from accessing the device content. For example, the restricted execution service 202 of the mobile device 100 returns the device application 218 to the user mode of the mobile device where access to the device content 222 is not restricted.
FIG. 4 illustrates an exemplary method 400 of restricted execution modes. The order in which the methods are described is not intended to be construed as limiting, and any number of method actions or combinations thereof may be combined in any order to implement a method or alternative method. ..
At 402, the shared device application contained within the shared space is granted access to the device content while the restricted execution service is activated. For example, the restricted execution service 202 (FIG. 2) on the mobile device 100 grants access to the device content 222 to the shared device application 220 contained in the shared space 216 while the restricted execution mode is activated. To do.
At 404, device applications that request access to device content through shared device applications are restricted while restricted execution mode is activated on the device. For example, the restricted execution service 202 of the mobile device 100 makes a task call of the device application 218 to the shared device application 220 with a request for access to the device content 222 while the restricted execution mode is activated on the device. Restrict.
At 406, the device application is the device content through the shared device application based on the request token for the device content that the device application includes in the task call to the shared device application while the restricted execution mode is activated. Allow access to. For example, the restricted execution service 202 of the mobile device 100 is based on the request token for the device content that the device application includes in the task call to the shared device application while the restricted execution mode is activated. Allows access to device content 222 through the shared device application. The request token indicates that the device application is allowed to access the device content through the shared device application in the shared space.
FIG. 5 illustrates an exemplary method 500 of restricted execution modes. The order in which the methods are described is not intended to be construed as limiting, and any number of method actions or combinations thereof may be combined in any order to implement a method or alternative method. ..
In 502, when the device application initiates a task call to access the device content, access to the device content is specified to be restricted while restricted execution mode is activated. Limited based on the task of the application. For example, the restricted execution service 202 of the mobile device 100 is designated to be restricted while the restricted execution mode 214 is activated when the device application 218 initiates a task call to access the device content. Restrict access to device content 222 based on the device application task being used.
At 504, the device application is restricted from the mobile device's file system while the restricted execution mode is activated. For example, the restricted execution service 202 of the mobile device 100 restricts the device application 218 from the file system of the mobile device while the restricted execution mode is activated.
At 506, the device application is determined to be user-specified to allow access to the device content in restricted execution mode when the device application is included as a shared device application in the shared space. .. Alternatively, at 508, it is determined that the device application is designated not to be granted access to the device content, even if the device application is contained within the shared space. For example, the restricted execution service 202 on the mobile device 100 allows the device application to allow the device content application access to the device content in the restricted execution mode when the device application is included as a shared device application in the shared space. You can determine if it is specified. The Restricted Execution Service 202 states that even if the device application is contained within a shared space, the device application is specified (eg, programmed) not to be granted access to the device content. It may be decided. In addition, this type of programmed device application may be implemented as not even qualified to be user-specified to be contained within a shared space.
Although described herein as a single restricted execution mode, in some examples the device is associated with a child's shared space to facilitate sharing of the mobile device with the child. Provides multiple restricted execution modes, such as the restricted mode of, and a second restricted execution mode associated with a shared space for safe driving to facilitate safer driving by users of mobile devices. .. Each of these various restricted execution modes may impose different sets of restrictions on the functionality of the device. For example, a child-related run mode may block access to e-mail, changes to device settings, or purchases in the application, and a second restricted run zone for safe driving distracts the driver from the road. You may block possible graphical user interfaces.
From the lock screen displayed on the device, the user may reach different shared spaces, each with a different restricted execution mode associated with each, without entering a PIN or other credentials. For example, from the lock screen, the user enters a first gesture (eg, left swipe) to reach a first shared space with a first restricted execution mode, and a second different gesture (eg, right swipe). May be entered to reach a second different shared space with a second restricted execution mode. In some examples, the shared space associated with the restricted execution mode may be accessed from different entry points rather than receiving input (eg, gesture input) on the lock screen.
The features and concepts of restricted execution modes described herein include one or more restricted execution modes associated with the device's children's shared space to facilitate sharing of the device with children. It may be used to support and implement. This application in restricted execution mode is the "Mobile Device Child" filed on December 22, 2012. Incorporates a related US Patent Application No. 13/726095 entitled "Share", the disclosure of this related application being incorporated herein by reference in its entirety. Sharing mobile devices with children allows the implementation of "kids corners" (also known as kids spaces or children's zones) for parental controls of any application, data, functionality and features of mobile devices. As a result, parents can allow their children to play on their devices without access to restricted applications, data, functionality and features. The Kids Corner is a shared space for kids that provides a custom destination for mobile phones just for the kids when they want to "play" on the device. In the children's shared space, children's access is restricted to applications, games, music, videos, movies and other content of their choice by the restricted execution mode. All external settings and content in the Kids Corner are protected and purchases can be blocked while in the Kids Corner. Blocked and / or restricted applications, as well as mobile device features, have the ability to make phone calls, send text or access email, access the internet such as posting to social networks and searching the internet. May include the ability to do.
The features and concepts of the restricted execution modes described herein support and implement one or more restricted execution modes associated with the safe driving shared space of the device to facilitate the safe driving mode. May be used for. This application in Limited Execution Mode incorporates a related US Patent Application No. 13/726097, entitled "Mobile Device Safe Driving" filed December 22, 2012, the disclosure of this related application in its entirety. Is incorporated herein by reference. Safe driving with mobile devices allows the implementation of one or more safe driving modes that minimize the distraction of the mobile phone driver while driving the vehicle.
FIG. 6 illustrates an exemplary system 600 capable of implementing embodiments of a private dialogue hub and restricted access mode. System 600 includes an exemplary mobile device 602. The exemplary mobile device 602 can be any one or combination of mobile phones, tablets, computing, communications, entertainment, games, media playback and / or other types of devices. Any of these devices may be used with various components such as a processing system and memory, as well as any number of different components and combinations as described further in connection with the exemplary device shown in FIG. Can be implemented. Therefore, the mobile device 602 may implement the techniques described above in whole or in part, such as the techniques described in the context of the restricted execution service 202.
The mobile device 602 includes an integrated display device 604 and can display a user interface such as the hub user interface 606 of the hub application 608 on the integrated display device 604. The hub user interface presents a unified dialogue view of hub data 610 with respect to a single private dialogue hub, and hub application 608 aggregates heterogeneous types of hub data 610 originating from various member users of the private dialogue hub. .. For example, the hub user interface provides a single unified access point for shared hub messages, status updates, check-ins, hub calendar events, hub media, hub applications and other types of hub content. It is possible. As mentioned above, a private dialogue hub (or simply a "hub") is a private network or association of member users who voluntarily choose to interact and collaborate privately with each other. Hub data 610 contains any shared or metadata used to facilitate dialogue or coordination between private dialogue hubs, including messages, notes, contact management, documents, tasks, location updates, photos. , Calendar events, applications (including collaborative gaming applications), and / or other media such as audio, music, video and / or image data of any type that may be available or accessible from any source. It may also contain shared data for content.
The basic functionality of an exemplary private dialogue hub is shown as a golf hub displayed within the hub user interface 606 of hub application 608. For example, the hub user interface can include various selectable user interface tiles 612, such as member tiles that can be selected to initiate the display of the members of the private dialogue hub. User interface tiles 612 may also include hub chat and / or message tiles that allow hub members to join other member users of the hub within a shared message thread. For example, as shown, the member "Bob" is a "Anyone up for a round light". now? (Anyone wants to round now?) " User interface tiles 612 include photo album tiles that can be selected to view photos shared by any of the hub members of that hub, as well as shared notebook tiles that allow hub members to view shared notes within the tiles. You may be. For example, a golf hub may include a shared node document in which hub members compile collaborative research on new golf equipment. The hub user interface 606 may display a shared calendar that allows hub members to see, edit, and post calendar events that will be shared with all other hub members. The calendar tile, for example, shows all other members that they are booking with St. Andrew starting at 9am on Saturday morning. When the user selects a group item (eg a message from Bob) or a tile (eg a messaging tile), even if the hub application itself displays further details about the selected item or the group item associated with the selected tile. Well, or the hub application may call a different device application 636 (eg, a messaging application) to display further details about one or more of its items.
When the user selects a portion of the displayed hub data, such as a golf message from Bob, or otherwise engages, the hub application provides the user with additional details or options so that the user can It may be possible to further interact with the hub data. For example, a hub application may display a control to allow the user to edit or respond to Bob's message. Alternatively, when the user selects a portion of the displayed hub data (eg Bob's message) or otherwise engages, the hub application launches or calls another device application, and the user hubs. It may allow further interaction with parts of the data (for example, a hub application may call a native messaging application).
The hub user interface 606 of the hub application 608 may include user-selectable access to a third party application, such as when the application is "pinned" to a private dialogue hub or otherwise shared. it can. Pinned third-party applications may also use shared hub data, such as shared application preferences and shared application state data. The illustrated golf hub, for example displayed within the hub user interface 606, is a quick way to check the weather forecast at a local golf club, such as when a member of the hub is planning the next golf. Includes live tiles that represent third-party weather applications that you can access. The user of the mobile device 602 can also customize the display mode of the hub user interface, such as how to arrange the contents of the user interface and the elements of the hub user interface. Another example of a hub user interface for hub application 608 is a panoramic hub user interface, such as for a family-centric private dialogue hub, illustrated and described in more detail in connection with FIG.
The exemplary system 600 also includes a hub management service 614 and cloud storage and service 616. Hub management service 614 manages the formation and retention of the private dialogue hub 618. The hub management service 614 can correlate or correlate member users of a hub by associating the member's account identifier 620 with one or more of the private dialogue hubs. The member user account identifier 620 may be associated with the private dialogue hub 618 identifier in the data table held by the hub management service to correlate the hub member with one or more of the private dialogue hubs. The hub management service 614 may associate the device corresponding to the hub member based on the device identifier. Account identifier 620 can include user membership identifiers and / or sign-on credentials such as email and password combinations and username and password combinations. The sign-on authentication information may be single sign-on (SSO) authentication information used for authentication purposes in a member of a Web service including cloud storage and service 616.
The cloud storage and service 616 can include any type of cloud-based (eg, network-based) data and messaging service 622. The messaging service 622 may include any type of email, text (eg SMS, MMS) and / or instant messaging service. Data services share any type of calendar, photo album, file and document sharing, location, map, music sharing, video sharing, games, contact management and / or notebook services, and stored hub data 624. May include any other type of service that can be used for. Stored hub data is retained for the private dialogue hub 618 and is accessible from the mobile device 602 upon request and / or "push" of data to the device, any form of message, update, event. , Content, media and information can be included. Cloud storage and services 616 also retain stored hub metadata 618, including settings and information about the private dialogue hub 618, such as hub names and hub background images or photos and hub member associations.
Although the data and messaging services 622 are shown together, different application data services and different messaging services may be run on separate devices and / or by separate and different entities. In addition, although the hub management service 614 and the cloud storage and service 616 are shown as independent services, they may be implemented together as a single service. Further, a server device (or group of server devices) includes implementations of both hub management service 614 and cloud storage and service 616, representing a single entity that can be the same server system, company system domain, etc. be able to.
Cloud storage and service 616 and its components, data and messaging service 622, exchange stored hub data 624 and stored hub metadata 626 with mobile devices associated with member users of private interactive hub 618. To do. For example, the data and / or messaging service of cloud storage and service 616 receives a copy of hub data 610 and / or hub metadata 628 from the mobile device 602 used by the hub member and receives this hub data and hub metadata. Stored in cloud storage as stored hub data 624 and stored hub metadata 626, respectively, and then associated this stored hub data and stored hub metadata with other member users of the same private interactive hub. Can be distributed to other mobile devices associated with the same hub member. The stored hub metadata 626 contains membership information about member users of the private dialogue hub, a hub identifier that correlates a portion of the hub data with a particular private dialogue hub, and a user identifier that correlates a portion of the hub data with a particular member user. , Modification date and / or other metadata can be included.
The cloud storage and service 616 and its components, the data and messaging service 622, are single for the purpose of authenticating the spread of stored hub data 624 and stored hub metadata 626 only to authenticated devices of hub members. Sign-on (SSO) authentication may be used. In addition, any of the devices and services described herein (eg, implemented as server devices) can communicate over networks that can be implemented to include wired and / wireless networks. .. Networks can also be implemented using any type of network topology and / or communication protocol, represented as a combination of two or more networks to include IP-based networks and / or the Internet, or It can be implemented in other ways. The network may also include mobile operator networks managed by mobile network operators and / or other network operators, such as communications service providers, mobile phone providers and / or Internet service providers.
The mobile device 602 includes the device operating system 632, which integrates cloud-based services, hub application 608 and local device application 636 with the operating system to implement aspects of the private interaction hub 618. Includes a hub operating system 624 to be implemented. Aspects that can be implemented are hub formation and membership retention, hub data 610 on mobile devices synchronized with stored hub data 624, hub metadata 628 synchronized with stored metadata 626, cloud storage and Synchronizing with service 616 and providing hub application 608 and local device application 636 on mobile device 602 with access to hub data 610 and hub metadata 628. For example, the hub operating system service 634 may directly access the cloud storage and the stored hub metadata 626 of the service 616.
Hub Operating System Service 634 (or Hub Application 608) may determine and retain a local copy of the membership association between the member user's account identifier 620 and the private dialogue hub identifier. The hub operating system service 634 synchronizes the stored hub data 624 from the cloud storage and service 616 with the hub data 610 of the mobile device 602, and stores the stored hub metadata 626 from the cloud storage and service 616 to the mobile device 602. May be synchronized with the hub metadata 628 of. Hub operating system service 634 may synchronize with cloud storage and service 616 (eg, by sending changes or additions to hub data 610 and hub metadata 628 to cloud storage and service 616). Such data synchronization can occur in response to the user launching a hub application.
The mobile device 602 includes a device application 636. The device application 636 allows the user of the mobile device to access the hub data 610, the user's private data 638, and the stored hub data 624 managed by either the data and messaging service 622 in the cloud storage and service 616. Allow to create and / or modify. Part or all of the device application 636 may be implemented as a client-side component or module of any of the data and messaging services 622, or as a stand-alone native application on a mobile device (eg, a local device application). You may. The device application 636 typically has hub data 610 and private data, such as only a single type of hub data and private data (eg, messaging data but not calendar data), respectively. It consumes only a portion or subset of 638 and provides access to it. The device application also presents the consumed hub data to the user along with the private data 638. Private data 638 is data or metadata that is not associated with a private dialogue hub and is not shared with other members of the hub (eg, data not shared via cloud storage and services 616).
Device application 636 in mobile device 602 may include native or third party messaging applications that provide users with messaging alerts and access to messaging threads. The messaging application provides access to both shared message threads that are shared with the Private Dialogue Hub and private message threads between users of mobile devices and other people who are not members of the hub. The messaging application also allows the user to send a message to all hub members without accessing the hub user interface of the hub application. Messaging applications may not provide user access to other types of hub data 610 other than hub messages. For example, messaging applications may not provide access to hub shared calendar events or shared photo albums.
Device application 636 may include native or third party calendar applications that provide schedule alerts and access to visual calendars. The calendar application provides user access to both shared calendar events shared between hub members and private calendar events that are not shared with other members of the hub (eg, exchanging calendar events). The calendar application also allows the user to create and / or share calendar events for all members of the hub without accessing the hub user interface of the hub application. Calendar applications may not provide user access to other types of hub data 610 other than hub calendar events. For example, calendar applications may not provide access to hub shared message threads or shared photo albums.
Device application 636 may also include native or third party media viewing and / or editing applications that provide access to digital photo albums or other digital media. The media application provides user access to both shared media files (eg, photos, videos and / or music) shared with the Private Dialogue Hub and private media files that are not shared with other members of the hub. The media application also allows the user to share media files with all members of the hub without accessing the hub user interface of the hub application. Media applications may not provide user access to other types of hub data 610 other than hub media files. For example, media applications may not provide access to hub shared message threads or shared calendar events.
Hub operating system services 634 present one or more application programming interfaces (APIs), application binary interfaces, and / or hub applications 608 on mobile device 602 and other types of interfaces 640 to device applications. These applications may be able to access, generate and / or modify hub data 610 and / or hub metadata 628 as described herein. Hub operating system service 634 can be implemented as an integrated software component or module of operating system 632. Hub operating system services are stored on a computer-readable storage medium, such as any suitable memory device or electronic data storage as described in the context of the exemplary device shown in FIG. 10 on the mobile device 602. Can be held as an executable instruction. In addition, hub operating system services can be run with the processing system on the mobile device to implement the aspects of a private dialogue hub.
In embodiments, the hub operating system service 634 can initiate the hub management service 614 to prepare the private dialogue hub 618. The user of the mobile device 602 can also start the Private Dialogue Hub 618 and invite other users to join the existing Private Dialogue Hub. For example, the hub user interface 606 of the hub application 608 can provide existing hub members with the option to add new members to the hub, allowing the user to provide a mobile device number or social. It is possible to identify expected members by either selecting an existing contact from one of the networks or one of the other contacts.
Hub operating system service 634 receives a request from an existing member user of the device, and in response, hub operating system service 634 and / or hub management service 614 invites to join the hub at the registration site. It can be communicated as an instant message sent to an SMS, MMS or expected member's mobile device that may include a link to or other registration instructions. Hub Operating System Service 634 and / or Hub Management Service 614 receives acceptance (eg, via a registration website) for an invitation to join a private dialogue hub, including, for example, at least an account identifier (such as SSO credentials). Associate the new member with an existing hub in Hub Management Service 614. Updated membership information, including the new member's account identifier 620, can be propagated from the hub management service 614 to other mobile devices of other members within the private dialogue hub. When a new member user joins the hub, the new member user provides access to stored hub data 624 and stored sub-metadata 626, such as either hub application 608 and / or device application 636. You may be prompted to download and / or install various applications that are configured to do so. The hub application 608 can also be an entry point where the user creates a new hub and modifies the membership of an existing hub.
The Private Dialogue Hub 618 can be prepared for any association of people, such as family members, colleagues, friends, neighbors and any other people who can be associated together within the hub. In addition, a member user of one private interactive hub may be based on a single member sign-on that identifies a member to the hub operating system service 634 and / or to the hub management service 614 for multiple hubs. It can also be a member. For example, a person is not only a member of a family hub that associates members of that person's family, but also a member of a neighbor hub that associates members of that person's neighbors, and a golf hub that often associates friends who play golf with them. May be good.
Integration of the mobile device hub application 608 with operating system 632 allows device users to view messages or updates on the hub user interface 606 within the application user interface of the application associated with the message or update. become. For example, the hub calendar is integrated with a calendar application on the mobile device 602 (eg, device application 636), and the calendar updates displayed in the hub user interface 606 are selected by the user and displayed in the calendar user interface of the calendar application. You can start the update that has been done. Alternatively, the user may look at the calendar user interface, select the calendar event associated with the private interaction hub, and start displaying the hub calendar containing the calendar event for the members of the hub. As another example, hub calendar events can be displayed within the hub user interface, and the device calendar application is any private data calendar where only the device user has access to the views within the device calendar application user interface. Along with the event, you can access the hub calendar event to view the hub calendar event. Both the hub application 608 and the device application 636 acquire the same hub calendar event data (eg, the same hub data 610 stored on a mobile device). Two different user interfaces (eg, hub user interface and device application user interface) display the same calendar event data.
In another example, the hub message and chat function is integrated with a messaging application on the mobile device 602 (eg, device application 636) to display email, text or instant messages within the hub user interface 606 on the mobile device 602. Can be selected by the user to initiate the message displayed within the messaging application user interface. Alternatively, the user may view a recent message from a member of the Private Dialogue Hub within the messaging application user interface, select this recent message, and view the discussion thread associated with that recent message. , May start displaying the hub message interface.
In embodiments, the hub operating system service 634 of the mobile device 602 has two or more members of the private dialogue hub 618 (eg, Facebook®, Twitter® or LinkedIn®. You can receive social network updates for member users of the Private Dialogue Hub 618, such as when you are also a "friend" on a public social network site (such as). Social network updates can be retrieved from the social network site in the hub management service 614 based on the association established for the hub member account identifier 620 of the private dialogue hub 618. Hub Operating System Services 634 then aggregates social network updates for a particular hub for display within the hub user interface 606 or for display on the "live tile" of the home page associated with the hub. Can be done. Hub operating system service 634 on the mobile device 602 can also be implemented to coordinate updates for multi-user dialogue for events managed in the private dialogue hub. For example, several members of a hub participate in a multiplayer dialogue game, and each continuous dialogue update from a member of the hub is initiated by that member on their respective associated mobile device.
FIG. 7 illustrates an exemplary system 700 capable of implementing various embodiments of a private dialogue hub, restricted execution modes and / or family coordination. This exemplary system includes a client device 702, which is a mobile phone 704, a tablet device 706, a computing device 708, a communication, entertainment, a game, a navigation and / or other type of portable electronic device. It can be any one or a combination of them. Any of the client devices 710 are implemented using various components such as a processor and / or memory system, as well as any number and combination of different components further described in the context of the exemplary device shown in FIG. can do.
An exemplary system 700 includes a device association service 712 that associates or correlates client devices 710 by device identifier 714, user identifier 716, and / or by any other type of identifiable association. Either the device and the service can communicate over a network 718, which can be implemented to include wired and / or wireless networks. Networks can also be implemented using any type of network topology and / or communication protocol, as a combination of two or more networks, including IP-based networks and / or the Internet. It can be represented or implemented in other ways. The network may also include a mobile operator network managed by the mobile operator, such as a communications service provider, a cell phone provider and / or an internet service provider. Mobile operators can facilitate mobile data and / or voice communication for any type of wireless device or mobile phone.
Each client device 710 can be associated with a different user, who defines the members of the family 720. The exemplary client device 702 represents various client devices 710 within the family. Any of the client devices in the family includes services such as software applications (eg, computer executable instructions) that can be executed by a processor or processor system to implement the embodiments described herein. be able to. In this example, the client device 702 has a family collaborative architecture 722 that implements the functionality of the family hub, a parental control service 724 that implements the functionality of the parent dashboard, a family check-in service 726, and quiet time and quietness. It includes a device quiet service 728 that implements the functions of various zones, a safe driving service 730, and a device sharing service 732. Client device services are further described in connection with FIG.
In addition, any one or combination of various client device services may be abstracted for implementation by a network service provider such as device association service 712. For example, the client devices 710 associated in the family 720 can be interconnected through a central computing device or system (eg, one of the client devices 710), the central computing device or system being a plurality of them. It may be local to or remote from these devices. In embodiments, the central computing device can be a cloud service of one or more server computers connected to the plurality of devices via a network 718 or other communication link. The interconnect architecture allows functionality across multiple devices and can provide users of these multiple devices with a common seamless experience. Each of the client devices may have different physical configurations and capabilities, and the central computing device has the experience of being tuned for a particular device and even for all of these devices in common. Provides a platform that enables distribution of.
FIG. 8 further illustrates the various client device services described in connection with FIG. Client device 702 includes family co-op architecture 722, parental control service 724, family check-in service 726, device quiet service 728, safe driving service 730 and device sharing service 732, which are related to FIGS. 1-6. It can be embodied as a parental execution service 202 described in. In embodiments, the Family Cooperative Architecture 722 can generally be implemented as a service as described herein. Generally, any of the services described is software, firmware, hardware (eg, fixed logic circuits), manual processing, applications, routines, programs, objects, components, data structures, procedures, modules, functions or these. It can be implemented or explained in the general context of any combination. A software implementation represents program code that, when executed by a computer processor, performs a specified task. In embodiments, any of processing, computation, filtering code execution, etc. is implemented using distributed computing services and / or devices such as on client devices, server devices, and / or network-based services. be able to.
In this example of client device services, the Family Cooperative Architecture 722 is like Family Calendar 802, Family Chat 804, Family Sharing Contact 806, Family Journal and Memory 810, Work and Chores 810, Family Key 812, and Family Household 814. Includes the Family Hub Manager 800, which implements, coordinates and / or manages various family features. Parental control service 724 implements features such as parental dashboard manager 816, age-appropriate content control 818 and secure social networking 820. The device quiet service 728 implements features such as quiet time 822 and quiet zone 824. Various client device services and features are further described herein.
Any of the client device services can include, integrate with, or implement any of the other client device services and applications. For example, the family collaborative architecture 722 may include any one or combination of parental control service 724, family check-in service 726, device quiet service 728, safe driving service 730 and device sharing service 732. In embodiments, a family collaborative architecture may be implemented for coordinating time, messaging, data, activity and any other shared service. The shared service can be either a client device service and / or any type of shared service that can be associated with certain services and / or multisystem operator (MSO) devices. In addition, parental control services can be implemented to throttle, extend, manage and / or reallocate data sharing with client device services.
Implement any of the family features and / or applications of the family collaborative architecture as private, partly private, partly public, or private with optional user control, and use public third-party services and applications for information. And data can be shared. Similarly, the client device services and applications described herein can be private, public, shareable, user controllable and / or any combination thereof. In embodiments, the Family Cooperative Architecture and / or Family Hub Manager can be implemented as an overall management architecture for extensibility or can be exemplified together as a Family Cooperative and / or Family Hub Architecture. And / or can be implemented as a collective embodiment and / or integration of any of the applications. In addition, any of the client device services can include, integrate with, or implement any of the other client device services and applications, and collectively, the Family Hub and / Or can be embodied as a collaborative architecture or service.
The device sharing service 732 allows, for example, a user to share his or her phone (eg, a mobile device) with another person, but still limits other people's access to the features, features and information of that phone. It is possible to embody the restricted execution service 202 described in connection with FIGS. 1 to 6 that implements the sharing function. For example, a mobile phone user owner can activate restricted execution mode on the device and then share the phone with others. In restricted execution mode, only outgoing calls are allowed, and restricted execution mode enforces task restrictions to limit incoming calls and make outgoing calls to device phone applications contained within the shared space. Allow the caller when it is traced.
In one implementation, parents can share their phone with their child to play games on the phone, but the child answers the call, reads the email, accesses the text, and any You may not be able to access other data or phone settings and initiate any type of financial transaction (eg purchasing an application for the phone or downloading music). Similarly, phone users can share their phone with a friend who asks to see the entire photo, but that friend has no access to any other phone's data and settings. Phone users may share their phone with someone who needs to make a call without giving access to any other phone's data and settings.
Phone sharing as a feature of restricted execution mode can be passcoded to allow only another person to access a given feature of the phone based on user-set limits. Phone sharing passcodes can be quickly initiated using gestures, keystrokes, and keystroke sequences. In addition, phone sharing profiles can be implemented for different types of individuals such as friends, parents, others, kids, children and more. Either family can use the phone sharing feature, for example, when a child goes out with a friend, or when a parent finishes a store affair, or when a house guest is allowed to use it during their stay. It can also be implemented for home family phones when members use the phone's sharing capabilities.
The device sharing service 732 restricts the display of incoming calls and messages so as to limit the communication function of the mobile device 1000, but is also implemented so that outgoing calls can be permitted for the use of sharing. Displaying messages includes displaying emails and text messages, calendar events and alerts, instant messages, and any other display that may be displayed to the user who owns the device (eg, rather than a temporarily shared user). May include a message. In the shared use mode of mobile devices, the device sharing service 732 provides financial services such as through a browser, music and / or game application that allows the user to perform a purchase transaction, download music, purchase and download applications. You can also restrict access to transactions, as well as applications that can initiate any other type of financial transaction. However, there may be cases where children are allowed access to money, such as taking a taxi in an emergency. The device sharing service 732 can also be implemented to limit the ability of young children to pair the phone with a car or send items from the phone to a home printer. The device sharing service 732 has been implemented to limit the child's ability to use the phone to open some doors, as the phone will be NFC compliant and the phone will replace the key when providing secure access. It is possible.
FIG. 9 is an example of a system 900 showing two different examples 902, 904 of the hub user interface for a family oriented hub. Text, images, photographs, graphics, links, data, information and presentation features shown in the context of the hub user interface and in connection with any other user interface described herein and / or shown in the drawings. Descriptions, layouts, functions and arrangements are merely exemplary and may be modified in any manner relating to various embodiments and / or implementations of mobile device check-in.
The hub is a central space for membership-oriented coordination of communication, activities, information and integration. Specified member relationships can be used to define how data and information are managed, and in the example illustrated, social conventions such as between members of a defined family group. Can be implemented to use. In one or more implementations, the hub is implemented as a user interface (eg, by a client device application) for membership-oriented communication, activity and information integration and aggregation. The hub can be implemented as a private shared space between the defined members. The hub contains links to the profiles of other members and allows aggregation for the visibility of some of the data and information of other members within the hub, based on the setting of constraints. The hub shares group calendars that can be viewed and edited, common text message windows, bulletin boards, shared photo albums, check-in features and any other type of shared information.
Devices and / or device accounts can be associated within a set of devices or device accounts (eg, family phone accounts, user accounts, a set of linked devices, etc.), and all or a subset of devices or accounts are other. Can communicate with the device or account. Hub members can be defined by any number of different classes of people, such as juniors, teens, mothers, fathers (or parents), grandparents, sitters, life coaches, etc. in the illustrated family of examples. .. In addition, family members can be defined to distinguish, for example, live-in sitters from babysitters.
In addition, hub membership and hub use by members can be controlled by a user's selection set, such as one or two mobile phones by multiple related users of a client device. For example, one of the members in the hub can be a designated controller, such as a mother or employer doing household chores.
From a single configuration of members, hubs can be prepared, configured, and propagated automatically, for example. By default, the functionality and configuration of the hub may be an automatic, easy setup, but any rule, functionality or configuration aspect can be easily modified by the user. Preparing a hub may be based on payments, such as family or corporate payment plans. However, if, for example, the phone is changed to a different carrier, the phone can continue to receive text associated with the hub. Alternatively, preparing a hub can be based on an email address, telephone number, user account identifier or any other identifier.
A salesperson selling a new phone package can easily identify, for example, a member for each new phone and start the illustrated hub. From the consumer's point of view, this works correctly and members can leave the store after completing all the setup. All of the data and information can be shared with a single choice, so members do not have to share each item (eg grocery list, photo, calendar, etc.) separately.
The hub user interface is a customizable shared space that may function as a shared space that provides content generated and shared by the user. Some information may be shared and others may not. For example, a complete Christmas list of mothers cannot be seen by other family members, but fathers and children can add to the list (and only their contributions can be viewed). The hub setup may be performed "à la carte", which means that members can only select the features they want to see on the hub wall. For example, a mother may want to see a shopping list, while a father does not shop, so she may want to hide the shopping list on her device. However, in this case, the father can still access the shopping list to add items if he wishes.
The hub user interface integrates features, calendar features, events and / or data summaries (ie, "walls"), as well as content shared between members of the hub (eg lists, documents, etc.). For example, the hub user interface may include a "family check-in" or "check-in" option. The hub user interface may also include a chat section where location check-in messages are displayed along with other messages exchanged between members of the hub. The "wall" of the hub represents an area where members of the group can add what they want, such as a canteen board or a family refrigerator. In various implementations, information can be aggregated in columns or columns and shown on the wall of the hub as shown. The hub wall can also represent the interrelationship between any of the information and data appearing on the wall and the arrangement of time. Hub settings allow the user to control which features are integrated and displayed within the hub, such as on a wall.
The hub information may be the context associated with the members of the hub, and the calendar contains shared hub events. Calendar updates are posted as notifications of events on the wall, allowing users to look at the wall to see upcoming hub events or events related to one or more other members of the hub. Private messaging between hub members can also be performed. Members can send instant text (or other communications) to all other members in the hub. Text-like textualization of work meetings allows the display of each member on each device to be split into individual screens for each member.
The hub may be extensible, linked to a hard drive on the home computer, or synchronized with only one of the other devices, such as a manager or cloud control (eg from a network-based service). .. The hub may be extensible to third parties annotating the hub wall, such as those implemented using application programming interfaces (APIs) for the ability to post data to the hub. However, third party applications may not have access to the hub wall context, such as retrieving or displaying hub data. Private information and hub data can be encrypted and decrypted only by the phone associated with the hub.
Therefore, the hub supported by the hub collaboration architecture can be thought of as a central space for coordination of communication, activity, information and integration of hub members. Hubs can be defined to support a variety of different memberships, such as family members, colleagues, friends, acquaintances, fan clubs, and so on. Therefore, in the discussion below, we will consider examples related to families, but it is easy to define membership within a hub in various other ways without departing from the spirit and scope of the invention. It should be clear. Therefore, a hub-coordinated architecture can be used to support a variety of different features. An example of this feature is described herein as a restricted execution service for the hub, and further aspects of the private dialogue hub are also described herein.
FIG. 10 illustrates an exemplary system 1000 that includes an exemplary device 1002 that can implement a restricted execution mode embodiment. The exemplary device 1002 relates to FIGS. 1-9 above, such as any type of client or mobile device, mobile phone, tablet, computing, communication, entertainment, game, media playback and / or other type of device. It can be implemented as any of the devices, services and / or servers described above. For example, the mobile device 100 shown in FIGS. 1 and 2 may be implemented as an exemplary device 1002.
Device 1002 includes communication device 1004 that enables wired and / wireless communication of device data 1006 such as media content and shared messages, updates and event data on the device. Media content can include any type of audio, video and / or image data. Communication device 1004 can also include transceivers for mobile phone communication and / or network data communication.
Device 1002 also includes an input / output (I / O) interface 1008, such as a data network interface that provides connectivity and / or communication links between devices, data networks and other devices. The I / O interface can be used to combine devices with any type of component, peripheral and / or accessory device. The I / O interface also includes a data input port, through which the user input to the device and any type of audio, video and / or image data received from any content and / or data source. Any type of data, media content and / or input can be received, such as.
The I / O interface 1008 also supports natural user interface (NUI) input to device 1002. Natural user interface (NUI) input allows users to interact with the device in a "natural" way, freed from the artificial constraints imposed by input devices such as mice, keyboards, and remote controls. Any interface technology to be used. Examples of natural user interface inputs are voice recognition, touch and stylus recognition, on-screen gesture recognition, device-close motion gesture recognition, head, eye and environment recognition and tracking, augmented reality and virtual reality systems, and user input. It may rely on any other type of audible, visible, touch, gesture and / or machine intelligence that can determine intent.
Device 1002 includes, at least in part, a processing system 1010 that can be implemented in hardware such as any type of microprocessor that processes executable instructions and a controller. Processing systems include integrated circuits, programmable logic devices, logic devices formed using one or more semiconductors, and memory systems implemented as silicon and / or processors and system-on-chip (SOC). Can include components of other implementations with different hardware. Alternatively, the device can be implemented in any one or combination of software, hardware, firmware, or fixed logic circuits that can be implemented by processing and control circuits. Device 1002 may further include any type of system bus or other data, and a command transmission system that combines various components within the device. The system bus can include any one or combination of different bus structures and architectures, as well as control and data lines.
The device 1002 is also accessible by a computing device and is also a computer readable storage medium 1012 such as a data storage device that provides persistent storage of data and executable instructions (eg, software applications, programs, functions, etc.). Including. Examples of computer-readable storage media include volatile and non-volatile memory, fixed and removable media devices, and any suitable memory device or any suitable memory device that holds data for access by computing devices. Includes electronic data storage. Computer-readable storage media can include various implementations of random access memory (RAM), read-only memory (ROM), flash memory, and other types of storage media with various memory device configurations.
In general, computer-readable storage media represent media and / or devices that allow persistent and / or non-temporary storage of data, as opposed to simple signal propagation, carrier waves, signals, and the like. A computer-readable signal medium may refer to a signal-carrying medium that transmits instructions, such as over a network. The signal medium can embody computer-readable instructions as data in a modulated data signal such as a carrier wave or other transmission mechanism.
The computer-readable storage medium 1012 provides storage for device data 1006, as well as storage for various device applications 1014, such as operating systems that are held as software applications using computer-readable storage media and run by processing system 1010. To do. In this example, the device application also includes a device sharing service 1016 that implements an embodiment of a restricted execution mode, such as when the exemplary device 1002 is implemented as the mobile device 100 shown in FIG. An example of device sharing service 1016 is a restricted execution service 202 that is integrated with operating system 204 in mobile device 100 as described in connection with FIG.
The device application 1014 may include either a service or application 1018 that implements an embodiment of a restricted execution mode. The exemplary device 1002 also includes a family co-operation architecture 1020, which is software, firmware, hardware (eg, fixed logic) to support a restricted execution mode and / or a family co-operation embodiment of a mobile device. It can be implemented in the general context of a circuit) or any combination of these. Device 1002 can also include positioning system 1022, such as a GPS transceiver, or similar positioning system components that can be used to determine the global or navigation position of the device.
Device 1002 also includes an audio and / or video system 1024 that produces audio data for audio device 1026 and / or display data for display device 1028. Audio and / or display devices include any device that processes, displays, and / or otherwise renders audio, video, display and / or image data. In implementations, audio and / or display devices are integrated into the components of exemplary device 1002. Alternatively, the audio device and / or display device is an external peripheral component to the exemplary device.
In embodiments, at least some of the techniques for the described restricted execution modes may be implemented in distributed systems, such as on the "cloud" 1030 on platform 1032. Cloud 1030 includes and / or represents platform 1032 for service 1034 and / or resource 1036. For example, service 1034 may include either cloud storage and service 206 and data service 208, as described in connection with FIG. In addition, resource 1036 may include accessible data 210 as described in connection with FIG.
Platform 1032 abstracts the underlying functionality of hardware and / or software resources (eg, included as resource 1036), such as server devices (eg, contained within service 1034), and illustrates device 1002 as another device. , Connect with a server, etc. Resource 1036 may include applications and / or data that can be used while computer processing is being performed on a server remote from the exemplary device 1002. In addition, server 1034 and / or resource 1036 may facilitate subscriber network services such as the Internet, mobile phone networks, and Wi-Fi® networks. Platform 1032 acts to abstract and scale resources and serve the demand for resources 1036 implemented through platforms such as interconnected device embodiments that have the ability to be distributed throughout the system 1000. Sometimes. For example, this function may be implemented in a part of the exemplary device 1002 via a platform 1032 that abstracts the functionality of the array cloud 130.
Although the embodiments of the restricted execution mode have been described in terms specific to the function and / or method, the claims are not necessarily limited to the specific features or methods described. Rather, specific features and methods are disclosed as exemplary implementations of restricted execution modes.
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2018056960A | Cited by | Japan | Search report |
| JP2005340976A | Cites | Japan | Search report |
| JP2005340976A | Cites | Japan | Search report |
| JP2005340976A | Cites | Japan | Search report |
| JP2006146598A | Cites | Japan | Search report |
| JP2006146598A | Cites | Japan | Search report |
| JP2006146598A | Cites | Japan | Search report |
| JP2009017239A | Cites | Japan | Search report |
| JP2009017239A | Cites | Japan | Search report |
| JP2009017239A | Cites | Japan | Search report |
| US2009205041A1 | Cites | United States of America | Search report |
| WO2010065752A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2010147610A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| JP2011199637A | Cites | Japan | Search report |
| JP2011216043A | Cites | Japan | Search report |
| JP2011216043A | Cites | Japan | Search report |
| JP2011216043A | Cites | Japan | Search report |
| JP2013041512A | Cites | Japan | Search report |
| JP2013041512A | Cites | Japan | Search report |
| JP2013041512A | Cites | Japan | Search report |
| JP2013540321A | Cites | Japan | Search report |
| JP2013540321A | Cites | Japan | Search report |
| JP2013540321A | Cites | Japan | Search report |
68 members in 7 offices
Members68
| Document | Office | Kind | |
|---|---|---|---|
| WO2013096943A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096944A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096947A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096949A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096950A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2013225151A1 | United States of America | A1 | |
| US2013225152A1 | United States of America | A1 | |
| US2013227431A1 | United States of America | A1 | |
| US2013295872A1 | United States of America | A1 | |
| US2013295913A1 | United States of America | A1 | |
| US2013298037A1 | United States of America | A1 | |
| US2013303143A1 | United States of America | A1 | |
| US2013305319A1 | United States of America | A1 | |
| US2013305354A1 | United States of America | A1 | |
| US2014068755A1 | United States of America | A1 | |
| WO2014035454A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201415245A | Taiwan Province of China | A | |
| CN104011630A | China | A | |
| CN104012133A | China | A | |
| CN104012150A | China | A | |
| CN104012151A | China | A | |
| KR20140113985A | Republic of Korea | A | |
| US8874162B2 | United States of America | B2 | |
| CN104126315A | China | A | |
| EP2795435A1 | European Patent Office (EPO) | A1 | |
| EP2795939A1 | European Patent Office (EPO) | A1 | |
| EP2795949A1 | European Patent Office (EPO) | A1 | |
| EP2795970A1 | European Patent Office (EPO) | A1 | |
| EP2795971A1 | European Patent Office (EPO) | A1 | |
| US2015011203A1 | United States of America | A1 | |
| EP2795949A4 | European Patent Office (EPO) | A4 | |
| EP2795970A4 | European Patent Office (EPO) | A4 | |
| JP2015508530AThis record | Japan | A | |
| CN104584607A | China | A | |
| KR20150052035A | Republic of Korea | A | |
| EP2795939A4 | European Patent Office (EPO) | A4 | |
| EP2795971A4 | European Patent Office (EPO) | A4 | |
| EP2891353A1 | European Patent Office (EPO) | A1 | |
| EP2795435A4 | European Patent Office (EPO) | A4 | |
| US2015220712A1 | United States of America | A1 | |
| JP2015528674A | Japan | A | |
| US9230076B2 | United States of America | B2 | |
| US9325752B2 | United States of America | B2 | |
| EP2891353A4 | European Patent Office (EPO) | A4 | |
| US9363250B2 | United States of America | B2 | |
| US2016197968A1 | United States of America | A1 | |
| US9420432B2 | United States of America | B2 | |
| US2016248906A1 | United States of America | A1 | |
| US9467834B2 | United States of America | B2 | |
| US9491589B2 | United States of America | B2 | |
| US2016328902A1 | United States of America | A1 | |
| JP6058138B2 | Japan | B2 | |
| US9665702B2 | United States of America | B2 | |
| US9680888B2 | United States of America | B2 | |
| CN104011630B | China | B | |
| TWI588664B | Taiwan Province of China | B | |
| US9710982B2 | United States of America | B2 | |
| JP2017130960A | Japan | A | |
| US9736655B2 | United States of America | B2 | |
| EP2795971B1 | European Patent Office (EPO) | B1 | |
| EP2795949B1 | European Patent Office (EPO) | B1 | |
| JP6275650B2 | Japan | B2 | |
| CN104012150B | China | B | |
| EP2795939B1 | European Patent Office (EPO) | B1 | |
| CN104012133B | China | B | |
| CN104584607B | China | B | |
| US10249119B2 | United States of America | B2 | |
| KR102011177B1 | Republic of Korea | B1 |
17 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A711A711 | A711 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2015508530
- Application
- 2014548998
Titles2
- Japanese
- 制限付き実行モード
- English
- Limited execution mode
Classification
- CPC, 14
- G06F21/629
- G06F21/31
- H04W12/08
- H04W88/02
- H04L63/105
- G06F21/6218
- G06F21/6281
- H04W4/60
- G06F2221/2149
- H04W12/37
- H04W12/68
- H04W12/10
- G06F2221/2129
- G06F21/53
- IPC, 3
- G06F21 62
- H04M1 673
- H04W4 60
Designated states143
- Regional, 78
- Botswana
- Ghana
- Gambia
- Kenya
- Liberia
- Lesotho
- Malawi
- Mozambique
- Namibia
- Rwanda
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Russian Federation
- Tajikistan
and 54 moreShow fewer
- Turkmenistan
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Lithuania
- Luxembourg
- Latvia
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 65
- United Arab Emirates
- Antigua and Barbuda
- Angola
- Australia
- Bosnia and Herzegovina
- Barbados
- Bahrain
- Brunei Darussalam
- Brazil
- Belize
- Canada
- Chile
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Dominican Republic
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Guatemala
and 41 moreShow fewer
- Honduras
- Indonesia
- Israel
- India
- Japan
- Comoros
- Saint Kitts and Nevis
- Democratic People’s Republic of Korea
- Republic of Korea
- Lao People’s Democratic Republic
- Saint Lucia
- Sri Lanka
- Libya
- Morocco
- Republic of Moldova
- Montenegro
- Madagascar
- Mongolia
- Mexico
- Malaysia
- Nigeria
- Nicaragua
- New Zealand
- Oman
- Panama
- Peru
- Papua New Guinea
- Philippines
- Qatar
- Seychelles
- Singapore
- Sao Tome and Principe
- El Salvador
- Syrian Arab Republic
- Thailand
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines