Restricted execution modes
Abstract
In an embodiment of the restricted execution mode, the mobile device may display the device lock screen on the integrated display device and may transition from the device lock screen to display the shared space user interface of the shared space. The transition to display the shared space user interface does not receive a PIN code entered on the device lock screen. The mobile device implements a restricted execution service that is implemented to activate a restricted execution mode of the mobile device, and restricts the device application's access to device content while the restricted execution mode is activated. The restricted execution service may also allow shared device application access contained in the shared space to device content while the restricted execution mode is activated.

Term
Projected expiry 23 December 2032.
- Priority
- Filed
- Published
- Today
- Projected expiry
10 claims: 2 independent, 8 dependent
- 1모바일 디바이스에 있어서, 디바이스 잠금 스크린을 디스플레이하고, 상기 디바이스 잠금 스크린에 입력되는 인증 크리덴셜(authentication credential) 없이 공유 공간의 공유 공간 사용자 인터페이스로 전환하도록 구성된 디스플레이 디바이스와, 상기 모바일 디바이스의 제한된 실행 모드를 활성화하고, 상기 제한된 실행 모드가 활성화되는 동안 디바이스 콘텐츠로의 디바이스 애플리케이션의 액세스를 제한하도록 구성되는 제한된 실행 서비스를 구현하는 처리 시스템을 포함하는 모바일 디바이스.
- 2제1항에 있어서, 상기 공유 공간은 공유 디바이스 애플리케이션을 포함하고, 상기 제한된 실행 서비스는, 상기 제한된 실행 모드가 활성화되는 동안 상기 디바이스 콘텐츠로의 상기 공유 디바이스 애플리케이션 액세스를 허용하도록 구성되는 것인 모바일 디바이스.
- 3제2항에 있어서, 상기 디바이스 애플리케이션은 상기 디바이스 콘텐츠에 대한 요구에 의해 상기 공유 디바이스 애플리케이션을 호출하도록 구성되고, 상기 제한된 실행 서비스는, 상기 제한된 실행 모드가 활성화되는 동안 상기 공유 디바이스 애플리케이션을 통해 상기 디바이스 콘텐츠로의 상기 디바이스 애플리케이션 액세스를 제한하도록 추가로 구성되는 것인 모바일 디바이스.
- 4제2항에 있어서, 상기 디바이스 애플리케이션은 상기 디바이스 콘텐츠에 대한 요구에 의해 상기 공유 디바이스 애플리케이션을 호출하도록 구성되고, 상기 디바이스 애플리케이션을 나타내는 요구 토큰을 포함하는 상기 요구는, 상기 공유 공간에서 상기 공유 디바이스 애플리케이션을 통해 상기 디바이스 콘텐츠에 액세스하도록 허용되며, 상기 제한된 실행 서비스는, 상기 제한된 실행 모드가 활성화되는 동안 상기 요구 토큰에 기초하여 상기 공유 디바이스 애플리케이션을 통해 상기 디바이스 콘텐츠로의 상기 디바이스 애플리케이션 액세스를 허용하도록 추가로 구성되는 것인 모바일 디바이스.
- 5제1항에 있어서, 상기 디바이스 애플리케이션은 상기 디바이스 콘텐츠에 액세스하기 위해 작업 호출을 개시하도록 구성되고, 상기 제한된 실행 서비스는, 상기 제한된 실행 모드가 활성화되는 동안 제한된 것으로서 지정되는 하나 이상의 디바이스 애플리케이션 작업에 기초하여 상기 디바이스 콘텐츠로의 액세스를 제한하도록 구성되는 것인 모바일 디바이스.
- 6방법으로서, 모바일 디바이스의 통합된 디스플레이 디바이스 상에 디바이스 잠금 스크린을 디스플레이하는 단계와, 상기 디바이스 잠금 스크린 상에 입력되는 인증 크리덴셜 없이 상기 디바이스 잠금 스크린을 디스플레이하는 것으로부터 공유 공간의 공유 공간 사용자 인터페이스를 디스플레이하는 것으로 전환하는 단계와, 상기 모바일 디바이스의 제한된 실행 모드를 활성화하는 단계와, 상기 제한된 실행 모드가 활성화되는 동안 디바이스 콘텐츠로의 디바이스 애플리케이션의 액세스를 제한하는 단계를 포함하는 방법.
- 7제6항에 있어서, 상기 제한된 실행 모드가 활성화되는 동안 상기 디바이스 콘텐츠로 상기 공유 공간에 포함되는 공유 디바이스 애플리케이션이 액세스하는 것을 허용하는 단계를 더 포함하는 방법.
- 8제7항에 있어서, 상기 디바이스 애플리케이션이 상기 디바이스 콘텐츠에 대한 요구에 의해 상기 공유 디바이스 애플리케이션을 호출할 때 상기 제한된 실행 모드가 활성화되는 동안 상기 공유 디바이스 애플리케이션을 통해 상기 디바이스 콘텐츠로의 상기 디바이스 애플리케이션 액세스를 제한하는 단계를 더 포함하는 방법.
- 9제7항에 있어서, 상기 디바이스 애플리케이션이 상기 디바이스 콘텐츠에 대한 공유 디바이스 애플리케이션으로 작업 호출 시에 포함하는 요구 토큰에 기초하여 상기 제한된 실행 모드가 활성화되는 동안 상기 공유 디바이스 애플리케이션을 통해 상기 디바이스 콘텐츠로의 상기 디바이스 애플리케이션 액세스를 허용하는 단계를 더 포함하고, 상기 요구 토큰은 상기 디바이스 애플리케이션이 상기 공유 공간에서 상기 공유 디바이스 애플리케이션을 통해 상기 디바이스 콘텐츠에 액세스하도록 허용되는 것을 나타내는 방법.
- 10제6항에 있어서, 상기 제한된 실행 모드가 활성화되는 동안 제한되는 것으로서 지정되는 하나 이상의 디바이스 애플리케이션 작업에 기초하여 상기 디바이스 콘텐츠로의 액세스를 제한하는 단계를 더 포함하는 방법.
Independent claims10
107 paragraphs in 1 section, as filed
RESTRICTED EXECUTION MODES
The present invention relates to a mobile device and method for implementing a restricted execution mode.
Many types of devices, such as cell phones, tablet devices, and other computing, communication and entertainment devices, are progressively offering more and more functions, applications and features that are beneficial to users, thereby saving users' personal time as well as work and social activities. can be improved For example, cell phones may be used for text, email and voice communications, as well as for entertainment such as listening to music, surfing the Internet, watching video content, gaming, and for taking pictures and videos. Similarly, portable tablet devices may be used for e-mail, browsers, navigation and other computing applications, as well as for various entertainment and photo features. In addition to the many computing, communication and entertainment applications available to users of mobile phone or tablet devices, a seemingly unlimited number of third-party applications and features are also available for download to the device.
Parents of children who do not yet have their own cell phones often find that they want their children to "play" games, taking pictures, listening to music, and other activities with their phones. In general, parents may pass their phone to a child in the backseat of a car to keep the children entertained while driving. Thereafter, the parent may have changed which features and applications the child accesses on the device, such as unintentional access to a web browser or email application, or which device settings such as audio settings, alarm settings, calendar announcements, etc. may not know
This summary introduces simplified concepts and features of the restricted mode of execution described more below that are illustrated in the detailed description below and/or in the drawings. This Summary should not be considered as delineating essential features of the claimed subject matter, nor should it be used to determine or limit the scope of the claimed subject matter.
A limited execution mode is described. In an embodiment, the mobile device may display the device lock screen on the integrated display device and may transition from the device lock screen to display the shared space user interface of the shared space. The transition to display the shared space user interface occurs without receiving a PIN code or other authentication credential that is entered on the device lock screen. The mobile device implements a restricted execution service that is implemented to activate a restricted execution mode of the mobile device, and restricts the device application's access to device content while the restricted execution mode is activated. The restricted execution service may also allow shared device application access contained within the shared space to device content while the restricted execution mode is activated.
In an embodiment, when the device application calls the shared device application with a request for device content, the restricted execution service restricts the device application access to the device content through the shared device application while the restricted execution mode is activated. . Alternatively, while the restricted execution mode is activated based on a request token that a device application includes in a task call to the shared device application for device content, the restricted execution service is An application may allow the device application access to the device content. The request token indicates that the device application is allowed to access the device content through the shared device application in the shared space.
In embodiments, a device application may be implemented or designed such that a user can specify to allow device application access to device content if the device application is included in the shared space as a shared device application. Alternatively, the device application may be designed such that access to the device content is not allowed even if the device application is included in the shared space. Also, this type of device application may be implemented as not eligible for customization to be included in the shared space. A device application included in the shared space may initiate an action call to access device content. However, the restricted execution service limits access to device content based on one or more device application actions that are designated as restricted while the restricted execution mode is activated. The restricted execution service may also restrict the device application from the file system of the mobile device while the restricted execution mode is activated.
Embodiments of the restricted execution mode will be described with reference to the drawings below. The same number may be used throughout to designate reference marks such as elements and features shown in the drawings: 1 is a diagram illustrating an example of a restricted execution mode. 2 is a diagram illustrating an example of a system in which embodiments of a restricted execution mode may be implemented. 3 is a diagram illustrating an example of method(s) in a restricted execution mode in accordance with one or more embodiments. 4 is a diagram illustrating an example of method(s) in a restricted execution mode in accordance with one or more embodiments. 5 is a diagram illustrating an example of method(s) in a restricted execution mode in accordance with one or more embodiments. 6 is a diagram illustrating an example of a system in which embodiments of a private interaction hub may be implemented. 7 is a diagram illustrating an example of a system in which embodiments of limited execution mode and/or family coordination may be implemented. 8 is a diagram illustrating various client device services and features in accordance with one or more embodiments. 9 is a diagram illustrating examples of a family hub in accordance with one or more embodiments. 10 is a diagram illustrating an example of a system along with an example of a device that may implement embodiments of a restricted execution mode.
Embodiments of a limited execution mode are described to provide a limited execution service that may be implemented as a client device service or application, such as in a cell phone, portable tablet device, or other type of computing and/or communication device. The restricted execution mode enables the implementation of a shared space on the device where the user owner can contain device applications that guests or children can access without requiring a password, and the device applications can access other individuals' device content on the device. access is programmatically prevented.
There may be situations where the user owner of the device may wish to access some content or application on their phone without unlocking the phone with a PIN code or other authentication credential. The restricted execution mode allows the user owner to validate some experiences without password access and without compromising the security of sensitive personal or corporate data. In implementations, the restricted execution mode allows the application to run, but restricts access to sensitive data or experiences using several mechanisms such as security capabilities, blocked navigation, and application origin. If an application has special security capabilities, a runtime check is centralized when the application attempts to access a protected resource, and if the application is running in a restricted execution zone, an error is returned and handled by the application. can be When a device is running in a restricted execution mode, a device application may be said to be running in a restricted execution "zone".
For blocked navigation security capabilities, applications often use built-in tasks to complete user actions such as sending emails, making phone calls, and the like. When a restricted execution mode is activated in a device, the origination of the device application's task at runtime is taken into account in order to determine whether the device application and more specifically the task are permitted. An application operation, which is generally synonymous with an application programming interface (or API) call, may include aspects of a data access API call, but also includes a request to initiate a special action or operations different from data access, the operation request being a request It may also contain metadata related to the operation of the task. The level of functionality is provided on a per-task basis to determine if the operation or operations of the requested task are available in a restricted execution mode during the runtime start of the task request. A device application may be executed by the device, but some functions of the device application will be executed when a restricted execution mode is activated in the device.
Examples of limiting the functionality of a device application are preventing the device application from launching together or limiting API calls that are narrower than the normal set of API calls available to the application when the mobile device is running in normal user mode. It may include limiting the device application to only call a subset. Restricting access to device content may also include disallowing certain API calls that provide access to a particular set of data or content. In many instances, restricting functionality or access can be accomplished by analyzing an Access Control List (ACL), an Access Control Entry (ACE), or similar file system access control metadata maintained by the file system. does not include or change For example, a device application may be restricted from access to device content while a restricted execution mode is activated on the device.
When running in a restricted execution zone, all application-required navigations are checked and only navigation allowed by the system can continue. Other navigations fail backwards compatibility so that legacy applications do not need to be updated to run in a restricted execution zone. For application-origin security capabilities, only applications that initiate and/or download from a first-party provider may run (eg, execute) in a restricted execution mode. This ensures that applications that are not security checked and may access sensitive and/or private data on the device will not run without first unlocking the device by the user.
Although features and concepts of restricted execution mode may be implemented in any number of different devices, systems, environments, and/or configurations, embodiments of limited execution mode are described in the context of examples of devices, systems, and methods below.
1 illustrates an example of a user interface in a restricted execution mode. The example mobile device 100 may be any one or combination of a cell phone, a tablet device, a computing device, a communication, entertainment, gaming, navigation, and/or other type of portable electronic device. The shared space can be implemented for user access to functionality of device applications without a password, as well as for access to any applications, functions, and features of the mobile device 100 that are designated by the user in the shared space. .
An example of a mobile device 100 includes an integrated display device 102 on which a user interface may be displayed, such as a device lock screen 104 indicating that the device is locked at 106 . For example, the user owner of the mobile device 100 may lock the device when not in use and/or use a personal identification number (PIN) to prevent anyone else from accessing the full functionality of the application, such as email and text. , access the Internet through a browser application without providing authentication credentials such as login, or other authentication credentials.
The user owner of the mobile device 100 can allow others to use the phone and hand over the phone without having to unlock the device from the device lock screen 104 by entering a PIN or other credentials. . As shown in Example 108, the borrower of the phone may use a gesture ( gesture) input to swipe the device lock screen. The borrower does not enter a PIN or other credentials to access the shared space user interface. In implementations, the gesture input may be any type of user and/or gesture input in any direction on the integrated display device 102 of the mobile device. Alternatively or additionally, any type of device, button, and/or gesture input may be effectively used to transition from the device lock screen 104 to the shared space user interface 110 .
2 illustrates an example of a system 200 in which embodiments of a restricted execution mode may be implemented. An example of a system is as described with reference to FIG. 1 , having an integrated display device 102 on which a user interface such as a spatial user interface 110 representing a shared space on the integrated display device 102 can be displayed. It includes a mobile device 100 . In addition, mobile devices may include various components, such as processors and/or memory systems, as well as any number and combination of any number and combination as further described with reference to the example of the device shown in FIG. 10 to implement embodiments of limited execution modes. It can be implemented with different components.
The mobile device 100 includes a limited execution service 202 that may be implemented as a software application (eg, executable instructions) stored on a computer-readable storage medium such as any suitable memory device or electronic data storage device. do. Further, restricted execution service 202 may be executed by a processing system on a mobile device to implement embodiments of restricted execution mode as described herein. The restricted execution service 202 may be implemented as an independent device application executable on a device to interface with a number of applications, features, and functions of the device.
Examples of system 200 also include any type of cloud used to store or maintain accessible data 210 (eg, data accessible by a device application on mobile device 100 ). -based) (eg, network-based) data services 208 , which may include cloud storage and services 206 . Any of the devices and services (eg, implemented by a service device) described herein may communicate via a network 212 , which may be implemented to include wired and/or wireless networks. A network may also be implemented using any type of network topology and/or communication protocol, and may be shown to include an IP-based network and/or the Internet, or alternatively implemented as a combination of two or more networks. . Networks may also include mobile operator networks managed by mobile network operators and/or other network operators, such as communication service providers, cellular phone providers, and/or Internet service providers. Alternatively or additionally, peer-to-peer communication techniques may be used, such as multiple devices connected using a peer-to-peer communication network.
Restricted Execution Service 202 may use shared space 216 , such as to limit and/or restrict shared device applications 220 and device applications 218 included in shared space 216 that are accessible without a PIN or authentication credentials. is implemented to manage the limited execution mode 214 of Device application 218 includes any type of software application running on the device, such as for messaging, gaming, media playback, document viewing, and user interaction with communication applications, and the device's It may include functions and features. Device applications may also include system-level components that are not normally accessed or used by users of the device, but typically run in the background while the device is operating. Shared device applications may include any subset of device applications and are designed as shared device applications when included in shared space 216 for limited and/or limited functionality when restricted execution mode 214 is activated on the device. do.
The user owner of the mobile device 100 may select device applications and features and/or device content that may be accessed and included in the shared space by a child or guest while the restricted execution mode is activated. Moreover, a device application may be allowed a limited level of functionality while running in a shared space (i.e., the application may run), nevertheless typically limited to the device file system as well as the contacts, email, and calendar databases. Device content 222 that is restricted from access, such as access, cannot be accessed.
Content databases, device file systems, Internet access, and other device content and features may be protected from device application access when restricted execution mode is activated. For example, a device application that has access to the Internet, email, contacts, etc. and is running in normal user mode when the device is unlocked can be used in the same way as when the device application is added to the shared space to allow limited functionality in the shared space. Restricted automatically when restricted execution mode is activated. As an example, a digital camera application added to a shared space may allow a user to take and view new photos, but previous photos are restricted from viewing when a restricted execution mode is activated on the device.
The shared space user interface 110 of the shared space may be customized by the user owner of the device. For example, a user owner may add applications such as games and music applications to a shared space so that the applications can be recognized and launched in the shared space, perhaps with limited functionality. However, applications that are not recognized in the shared space cannot be started in the shared space. For example, if a game application pinned or recognized in the shared space attempts to launch a browser application on itself (eg, as part of the game's execution), the restricted launch service 202 may cause the browser application Check if it is pinned and recognized in this shared space. If the browser application is not recognized in the shared space, the restricted execution service fails to start the application, or if the browser application is recognized in the shared space, the browser application may be started in the shared space by the game application.
As described with reference to FIG. 1 , an input such as a gesture input or a device selectable control input may be received, and the limited execution service 202 does not receive a PIN code or other authentication credentials entered on the device lock screen. Initiate a transition from displaying the device lock screen 104 to display the shared space user interface 110 of the shared space 216 without having to. The restricted execution service 202 is implemented to manage the shared space 216 when the restricted execution mode 214 is activated. The restricted execution service 202 may activate the restricted execution mode 214 of the mobile device 100 and, while the restricted execution mode is activated, limit the application to a limited set of functions or tasks and/or files on the mobile device. The system may restrict access of device applications 218 to device content 222 .
Shared space 216 may contain shared device applications 220 , and restricted execution services 202 may allow shared device applications access to device content 222 while restricted execution mode 214 is active. . Whether the restricted execution service 202 is implemented or designed so that when a device application is included in the shared space 216 as a shared device application, a user can specify that the device application 218 allows the device application access to device content. can be judged. Alternatively, the device application may be designed such that access to the device content is not allowed even if the device application is included in the shared space. In addition, this type of device application may also be implemented as not eligible for customization to be included in the shared space.
In the restricted mode, the configuration of the device application may be designed or programmed to indicate whether the device application is always allowed to run (eg, perform) in the restricted mode, regardless of user selection. For example, a confidential company application or other application downloaded from a third-party application store that may access personal company data may run (or perform) in any restricted mode, even if the user wishes to run it in any restricted mode. ) can be configured to never be allowed to do so. The configuration of some device applications is special, such as allowing a device application to play a game or a subset of applications in kid zone restricted mode, or to allow a subset of camera lens applications to run when the phone is locked. It may be user controlled to indicate whether or not it is allowed to run in restricted mode.
The restricted execution service 202 may be implemented to verify whether a given device application can be navigated regardless of reason for a navigation request, taking into account the current restricted mode and system and user configuration of the target application. . Also, separate navigation stacks may be maintained for the normal mode user experience and for the current limited mode of execution. The restricted execution service 202 also allows or disallows movement from the normal mode stack to the restricted mode stack or vice versa based on scenario requirements, and based on available resources and transitions to and from restricted mode. This is implemented to determine when to terminate the application on each stack.
The device application 218 may initiate an action call to the shared device application 220 upon a request for device content 222 , and the restricted execution service 202 may initiate a task call to the shared device while the restricted execution mode 214 is active. Applications can restrict device application access to device content. The device application may also initiate an action call to the operating system 204 to request access to device content, wherein the restricted execution service is based on one or more device applications that are designated to be restricted while the restricted execution mode is activated. access can be restricted.
Alternatively, device application 218 may initiate a job call to shared device application 220 with a request for device content 222 , which request causes the device application to request a shared device application within shared space 216 . contains a request token indicating that the device content is being accessed via The restricted execution service 202 may then allow the device application access to the device content via the shared device application based on the request token while the restricted execution mode is activated. The restricted execution service may also deactivate the restricted execution mode 214 in response to a PIN code or authentication credential entered on the device lock screen, and the device application 218 may have unrestricted access to the device content 222 . You can return to the normal user mode of the mobile device with access.
The restricted execution service 200 implements a mechanism for indicating that a device application can execute (eg, perform) based on a job information field of a device application job in a restricted mode. The job information field indicates whether a specific job can be allowed to run in the shared space when the restricted execution mode is activated. This new field is a bit mask used by the navigation server to compare with the navigation filter mask provided by the mobile UI when restricted mode is entered. They may have tasks that some party device applications may have allowed to function within a children's shared space (eg, Kid's Corner), but not all application functions are allowed while a restricted execution mode is activated on the device. Because it is not, it is marked per operation, not by the application. When a device application is allowed to run in the shared space, the constrained execution service is based on a token passed in accordance with the core system component that cannot determine whether the work call originated from a device application running in the shared space. An API action call can be traced through the application layer from the originator (eg, a device application) initiating the action call. The token can be used to determine if the job call is protected from restricted execution mode.
Examples 300 , 400 , and 500 of the method are described with reference to FIGS. 3-5 , respectively, in accordance with one or more embodiments of a restricted mode of execution. Typically, any one of the services, components, modules, methods, and acts described herein is implemented using software, firmware, hardware (eg, fixed logic circuitry), manual processing, or any combination thereof. can be Examples of methods may be described in the general context of executable instructions stored on computer-readable storage media that are local and/or remote to a computer processing system, and implementations may include software applications, programs, functions, and the like. .
3 illustrates an example 300 of method(s) in a restricted execution mode. The order in which the methods are described is not intended to be construed as limiting, and any number or combination of method acts may be combined in any order to implement the methods, alternative methods.
At 302 , the device lock screen is displayed on the integrated display device of the mobile device. For example, the mobile device 100 ( FIG. 1 ) displays the device lock screen 104 on the integrated display device 102 of the mobile device. At 304 , the display is transitioned from the device lock screen to display the shared space user interface of the shared space without a PIN code or other authentication credentials being entered on the device lock screen. For example, the input system of the mobile device 100 may receive an input, such as a gesture input or a device selectable control input, the input to the shared space 216 without a PIN code or other authentication credentials being entered on the device lock screen. effective in switching from displaying the device lock screen 104 to display the shared space user interface 110 of
At 306 , the restricted execution mode of the mobile device is activated. For example, the restricted execution service 202 at the mobile device 100 activates the restricted execution mode 214 of the mobile device in response to entering the shared space. At 308 , access of the device application to the device content is restricted while the restricted execution mode is activated. For example, restricted execution service 202 in mobile device 100 restricts access of device application 218 to device content 222 while restricted execution mode 214 is activated.
At 310, the restricted execution mode is deactivated in response to a PIN code or other authentication credential entered on the device lock screen. For example, the restricted execution service 202 in the mobile device 100 deactivates the restricted execution mode in response to a PIN code or other authentication credential entered on the device lock screen. At 312 , the device returns to the user mode of the mobile device where the device application has unrestricted access to the device content. For example, the restricted execution service 202 on the mobile device 100 returns to the user mode of the mobile device where the device application 218 has unrestricted access to the device content 222 .
4 illustrates an example 400 of method(s) in a restricted execution mode. The order in which the methods are described is not intended to be construed as limiting, and any number or combination of method acts may be combined in any order to implement the methods, alternative methods.
At 402 , the shared device application included in the shared space is allowed access to the device content while the restricted execution mode is activated. For example, in mobile device 100 , restricted execution service 202 ( FIG. 2 ) may access device content 222 for shared device application 220 included in shared space 216 while restricted execution mode is activated. Allow access.
At 404 , a device application that requires access to device content via a shared device application is restricted while a restricted execution mode is activated on the device. For example, in mobile device 100 , restricted execution service 202 calls a device application 218 action to shared device application 220 by requesting access to device content 222 while restricted execution mode is activated. to limit
At 406 , the device application indicates that access to the device content through the shared device application is restricted while the restricted execution mode is activated based on a request token that the device application includes in invoking an operation to the shared device application on the device content. is allowed For example, the restricted execution service 202 in the mobile device 100 may be configured to operate on a shared device while a restricted execution mode is activated based on a request token that the device application includes in an action call to the shared device application for device content. Allows access to device content 222 by device application 218 through the application. The request token indicates that the device application is allowed to access device content through the shared device application in the shared space.
5 illustrates an example 500 of method(s) in a restricted execution mode. The order in which the methods are described is not intended to be construed as limiting, and any number or combination of method acts may be combined in any order to implement the methods, alternative methods.
At 502 , access to the device content is restricted based on a device application task that is designated as restricted while the restricted execution mode is activated, wherein the device application initiates a task call to access the device content. For example, in mobile device 100 , restricted execution service 202 ( FIG. 2 ) may grant access to device content 222 based on device application actions that are designated as restricted while restricted execution mode 214 is active. limit, where the device application 218 initiates an action call to access the device content.
At 504 , the device application is restricted from the file system of the mobile device while the restricted execution mode is activated. For example, the restricted execution service 202 in the mobile device 100 restricts the device application 218 from the file system of the mobile device while the restricted execution mode is activated.
At 506 , the device application is determined as customized to allow device application access to device content in a restricted execution mode if the device application is included in the shared space as a shared device application. Alternatively, at 508 , it is determined that the device application is designed such that access to the device content is not allowed even if the device application is included in the shared space. For example, the restricted execution service 202 in the mobile device 100 may determine whether the device application is customized to allow device application access to device content in a restricted execution mode if the device application is included in the shared space as a shared device application. It can be determined whether The restricted execution service 202 may also determine that the device application is designated (eg, programmed) such that access to the device content is not allowed even if the device application is included in the shared space. Also, this type of programmed device application may be implemented as not eligible for customization to be included in the shared space.
Although described herein as a single restricted execution mode, in some instances, a first limited execution mode associated with a children's shared space to facilitate the device sharing the mobile device with children and more secure by the user of the mobile device. It provides a number of limited execution modes, such as a second limited execution mode associated with a safe driving shared space to facilitate driving. These various restricted execution modes may each impose a different set of restrictions on the functionality of the device. For example, a child-related execution mode may block access to email data, changes to device settings, or in-app purchases, while a second driving safety restricted execution zone focuses the driver from the road. It can also block graphical user interfaces that can degrade it.
From a lock screen displayed on the device, without entering a PIN or other authentication credentials, a user may be able to arrive at a different shared space, each having a different limited execution mode associated with it. For example, from the lock screen, the user may use a first gesture (eg, swipe left) to reach a first shared space with a first limited execution mode and a second different shared space with a second limited execution mode. You may also enter a second, different gesture (eg, swipe right) to reach . In some examples, the shared space associated with the restricted execution mode may be accessed from a different entry point than receiving input (eg, gesture input) on the lock screen.
The features and concepts described herein for restricted execution modes may be used to support and implement one or more restricted execution modes associated with a children's shared space of a device to facilitate sharing the device with children. This restricted run mode application incorporates US Patent Application Serial No. 13/726095, filed December 22, 2012, entitled "Mobile Device Child Share," the disclosure of which is hereby incorporated by reference. The specification is incorporated in its entirety. Mobile Device Child Sharing is a "Kids Corner" for parental control of any applications, data, features and features of a mobile device so that parents can allow children to play with the device without access to restricted applications, data, features and features. "(also referred to as a kids area or children's zone). The Kids Corner is a children's sharing space that provides a customary destination on mobile phones for children only and is a location where children "play" on the device. In a children's shared space, children's access is limited by a mode of execution restricted to only applications, games, music, videos, movies, and other content selected by the parent. All of the content and settings outside of the Kids' Corner are protected and purchases can be blocked while in the Kids' Corner. Blocked and/or restricted applications and features of mobile devices may include the ability to access the Internet, such as to make phone calls, send text or access email, and post to social networks or search the Internet. may be
The features and concepts described herein for a restricted execution mode may be used to support and implement one or more restricted execution modes associated with a safe driving shared space of a device that facilitates a safe driving mode. This restricted execution mode application incorporates US Patent Application Serial No. 13/726097, filed December 22, 2012, entitled "Mobile Device Safe Driving," the disclosure of which is hereby incorporated by reference. The specification is incorporated in its entirety. Mobile device safe driving enables the implementation of one or more safe driving modes to minimize the distraction of the driver from the mobile phone while driving the vehicle.
6 illustrates an example of a system 600 in which embodiments of a personal interaction hub and restricted access mode may be implemented. System 600 provides an example of a mobile device 602 that may be either a wired or wireless device, or a combination thereof, such as a cell phone, tablet, computing, communications, entertainment, gaming, media playback, and/or other type of device. include Any of the devices may be implemented with various components, such as processing systems and memory, as well as any number of different components and combinations thereof as further described with reference to the example of the device shown in FIG. 10 . As such, mobile device 602 may implement techniques described in whole or in part above, such as those described with reference to limited execution service 202 .
Mobile device 602 includes an integrated display device 604 on which a user interface such as a hub user interface 606 of a hub application 608 can be displayed. The hub user interface provides a unified interactive view of hub data 610 for a single, personal interaction hub, and the hub application 608 provides a hub application 608 with heterogeneous types of hub data originating from multiple member users of the personal interaction hub. (610) is recruited. For example, the hub user interface may provide a single, unified access point to shared hub messages, status updates, check-ins, hub calendar events, hub media, hub applications, and other types of hub content. As noted above, a personal interaction hub (ie, simply "hub") is a personal network or association of member users who voluntarily choose to cooperate with each other and interact personally in both directions. Hub data 610 includes any shared data or metadata used to facilitate interactions and collaborations between members of a personal interaction hub, including messaging, notes, contact management, documents, tasks, location updates, Sharing for other media content such as photos, calendar events, applications (including collaborative gaming applications) and/or any type of audio, music, video and/or image data available or accessible from any source It may contain data.
The basic functionality of the exemplary personal interaction hub is shown as a golf hub displayed in the hub user interface 606 of the hub application 608 . For example, the hub user interface may include several selectable user interface tiles 612 , such as member tiles that may be selected to initiate display of constituent members of the personal interaction hub. User interface tiles 612 may also include hub chat and/or message tiles to allow hub members to engage in shared messaging threads with other member users of the hub. For example, as shown, member "Bob" asked "Anyone up for a round right now?" User interface tile 612 may also include a photo album tile where any one of the hub members can select to view photos shared with the hub, and a shared notebook tile where hub members can view shared notes. For example, a golf hub may include a shared notes document that compiles a collective survey of hub members of new golf equipment. The hub user interface 606 may also display a shared calendar that allows members of the hub to view, edit, and post calendar events to share with all other hub members. For example, a calendar tile would display the St. Shows upcoming tee time at Andrews. When a user selects a group item (eg, a message from Bob) or a tile (eg, a messaging tile), additional details about the selected item or group item related to the selected tile may be displayed by the hub application itself or the hub application may invoke a different device application 636 (eg, a messaging application) to display additional details about the item(s).
When the user selects or otherwise relates to a displayed piece of hub data, such as a golf message from Bob, the hub application may provide the user with additional details or options, such that additional interactions with the hub data can work For example, the hub application can display controls so that the user can edit or respond to Bob's messages. Alternatively or additionally, when a user selects a displayed piece of hub data (eg, Bob's message) or otherwise relates to such data, the hub application may launch or invoke another device application so that the user It may also allow interaction with the hub data piece (eg, the hub application may call its own messaging application).
The hub user interface 606 of the hub application 608 may also include user selectable access to third-party applications, such as when the application is "pinned" to, or otherwise shared with, a personal interaction hub. can Pinned third-party applications may also use shared hub data, such as shared application preferences or shared application state data. For example, a golf hub displayed in the hub user interface 606 can be quickly accessed by members of the hub to check the weather forecast at their local golf club, such as when planning an upcoming golf outing. and a live tile displaying a third party weather application, which may be enabled. A user of mobile device 602 may customize display aspects of the hub user interface, such as how the content of the user interface and elements of the hub user interface are laid out. Another example of a hub user interface of the hub application 608 is a panoramic hub user interface, such as for a family-centric personal interaction hub, as shown and described in greater detail with reference to FIG. 9 .
Exemplary system 600 also includes a hub management service 614 and cloud storage and service 616 . A hub management service 614 manages the creation and maintenance of a personal interaction hub 618 . The hub management service may correlate or associate member users of the hub by associating the member's account identifier 620 with one or more of the personal interaction hubs. The member user's account identifier 620 may be associated with the identifier of the personal interaction hub 618 in a data table, where the hub management service maintains a hub member to correlate with one or more of the personal interaction hubs. do. The hub management service 614 may also associate a device corresponding to a hub member based on the device identifier. The account identifier 620 may include a membership identifier and/or sign-on credentials, such as an email and password combination or a username and password combination. Sign-on personal information may be single sign-on ("SSO") personal information used for authentication purposes in many web services, including cloud storage and services 616 .
Cloud storage and services 616 may include any type of cloud-based (eg, network-based) data and messaging service 622 . Messaging services may include any type of email, text (eg, SMS, MMS) and/or instant messaging service. The data service may be used to share any type of calendar, photo album, file or document sharing, location, mapping, music sharing, video sharing, gaming, contact management and/or laptop service as well as stored hub data 624 It may include any other type of service. The stored hub data is accessible from the mobile device 602 on request and/or data "push" from the device to the device and is archived to the personal interaction hub 618 in any form of messages, updates, events , content, media and information. Cloud storage and services 616 also stores stored hub metadata 626 including settings and information pertaining to personal interaction hub 618, such as the name of the hub, a background image or photo of the hub, and association of hub members. to keep
Although shown together as data and messaging service 622 , the various application data services and the various messaging services may operate on separate devices and/or by separate differentiated entities. Also, although hub management service 614 and cloud storage and service 616 are shown as independent services, these services may be implemented together as a single service. A service device (or group of service devices) may also include implementations of both the hub management service 614 and cloud storage and service 616, representing a single entity, which may be the same server system, company system, domain, etc. have.
The cloud storage and service 616 and its configuration data and messaging service 622 are stored between the mobile device associated with the member user of the personal interaction hub 618 and the stored hub data 624 and the stored hub metadata 626 . exchange the For example, a data and/or messaging service in cloud storage and service 616 may receive a copy of hub data 610 and/or hub metadata 628 from mobile device 602 used by a hub member. In addition, this hub data and hub metadata can be stored in the cloud storage as stored hub data 624 and stored hub metadata 626, respectively, so that the stored hub data and the stored hub metadata are stored in the same personal interaction hub. It can distribute to other mobile devices associated with other member users as well as other mobile devices associated with the same hub member. Stored hub metadata 626 includes membership information pertaining to member users of the personal interaction hub, a hub identifier correlating a piece of hub data to a particular personal interaction hub, a user identifier correlating a piece of hub data to a particular membership user, and date of modification. and/or other metadata.
Cloud storage and service 616 and its configuration data and messaging service 622 may use single sign-on ("SSO") personal information for authentication purposes, such that stored hub data 624 and stored hub metadata Dissemination of 626 may be limited to only authorized devices of the hub member. Further, any of the devices and services described herein (eg, implemented as a server device) may communicate over a network 630 , which may be implemented to include wired and/or wireless networks. A network may be implemented using any type of network topology and/or communication protocol, and may be represented as a combination of two or more networks or otherwise implemented to include IP-based networks and/or the Internet. can Networks may also include mobile operator networks managed by mobile network operators and/or other network operators, such as communication service providers, mobile phone providers, and/or Internet service providers.
Mobile device 602 may include an operating system 632 of the device, which is implemented to integrate cloud-based services, hub applications 608 , and local device applications 636 with the operating system to enable personal interaction. hub operating system service 634 that implements aspects of working hub 618 . Aspects that may be implemented include hub formation and membership maintenance, synchronizing hub data 610 on a mobile device with stored hub data 624 as well as synchronizing hub metadata 628 with stored hub metadata 626 and , cloud storage and services 616 , and provides access to hub data 610 and hub metadata 628 to hub application 608 and local device application 636 on mobile device 602 . can do. For example, hub operating system service 634 can directly access hub metadata 626 stored in cloud storage and services 616 .
The hub operating system service 634 (or alternatively the hub application 608 ) may also determine and maintain a local copy of the identity of the personal interaction hub and the membership association of the member user account identifier 620 . The hub operating system service 634 may also synchronize stored hub data 624 from cloud storage and services 616 with hub data 610 on the mobile device 602 , and may also synchronize stored hub data 624 from cloud storage and services 616 . Hub metadata 626 may be synchronized with hub metadata 628 at the mobile device. Hub operating system service 634 also synchronizes with cloud storage and service 616 (eg, by sending changes or additions to hub data 610 and hub metadata 628 to cloud storage and service 616 ). can do. Such data synchronization may occur in response to the user launching the hub application.
The mobile device 602 may include stored data managed by a user of the mobile device by any of the data and messaging services 622 in the hub data 610 , the user's personal data 638 , as well as cloud storage and services 616 . device application 636 that accesses, creates and/or alters hub data 624; Some or all of the device applications 636 may be implemented as client-side components or modules of any of the data and messaging services 622 , or may be implemented as standalone native applications (eg, local device applications) on the mobile device. may be Device application 636 is typically only a portion or subset of hub data 610 and personal data 638, such as only a single type of hub data and personal data (eg, only messaging data, but not calendar data). consumes each and provides access to them. The device application also provides the typically consumed hub data to the user in association with personal data 638 . Personal data is data or metadata that is not associated with the personal interaction hub and has not been shared with other members of the hub (eg, data that has not been shared via cloud storage and services 616 ).
Device application 636 on mobile device 602 may include a native or third-party messaging application that provides a user with messaging alerts and access to messaging threads. The messaging application provides access to both a private message thread and a shared message thread shared with the personal interaction hub between users of the mobile device and users who are not members of the hub. The messaging application also allows a user to send a message to all of the hub members without accessing the hub user interface of the hub application. A messaging application may not provide user access to other types of hub data 610 other than hub messages. For example, the messaging application may not provide access to the hub's shared calendar events or shared photo albums.
Device application 636 may also include a native or third-party calendaring application that provides access to a visual calendar and schedule alerts. The calendaring application provides user access to shared calendar events shared with hub members and personal calendar events (eg, exchange calendar events) that were not shared with other members of the hub. The calendaring application also allows users to create and/or share calendar events for all members of the hub without accessing the hub user interface of the hub application. The application may not provide user access to other types of hub data 610 other than hub calendar events. For example, a calendaring application may not provide access to the hub's shared message thread or shared photo album.
Device applications 636 may also include native or third-party media viewing and/or editing applications that provide access to photo albums or other digital media of digital photos. The media application provides user access to both shared media files (eg, photos, videos, and/or music) shared with the personal interaction hub and personal media files that were not shared with other members of the hub. The media application also allows users to share media files with all members of the hub without accessing the hub user interface of the hub application. The media application may not provide user access to other types of hub data 610 other than hub media files. For example, the media application may not provide access to the hub's shared message threads or shared calendar events.
Hub operating system services 634 provide one or more application programming interfaces ("APIs"), application binary interfaces, and/or other types of interfaces 640 to hub applications 608 on mobile device 602 and device applications ( 636 , so that these applications can access, create, and/or modify hub data 610 and/or hub metadata 628 as described herein. The hub operating system service 634 may be implemented as an integrated software component or module of the operating system 632 . The hub operating system service is provided to the mobile device 602 as executable instructions stored on a computer readable storage medium, such as any suitable memory device or electronic data store as described with reference to the exemplary device shown in FIG. 10 . can be maintained In addition, the hub operating system service may be performed from the mobile device to the processing system, implementing aspects of the personal interaction hub.
In embodiments, the hub operating system service 634 may initiate a hub management service 614 to provide a personal interaction hub 618 . A user of mobile device 602 may launch personal interaction hub 618 and may also invite other members to join an existing personal interaction hub. For example, the hub user interface 606 of the hub application 608 may provide existing hub members an option to add a new member to the hub, where the user may provide a mobile device number or one of their social networks or other contacts. Prospective members can be identified by selecting an existing contact from one.
The hub operating system service 634 may receive a request from an existing member user of the device, and in response, the hub operating system service 634 and/or the hub management service 614 may communicate the invitation to the registration site or Join the hub as an SMS, MMS or instant message sent to the prospect's mobile device, which may contain links to other registration commands. The hub operating system service 634 and/or the hub management service 614 receives permission for the invitation (eg, via a registration website), including at least an account identifier (such as SSO personal information) and the hub management service Join the personal interaction hub associating the new member with the existing hub at 614 . The updated membership information including the new member's account identifier 620 may also be propagated from the hub management service 614 to other members' other mobile devices in the personal interaction hub. When a new member user joins the hub, he (she) has access to the storage hub data 624 and storage hub metadata 626, such as any applications in the device application 636 and/or the hub application 608. You may be prompted to download and/or install various applications configured to provide access. The hub application 608 may also be an entry point from which a user may create a new hub and/or change the membership of an existing hub.
Personal interaction hub 618 may be provided to any related person, such as family members, colleagues, friends, neighbors, and any other person who may be related together in the hub. In addition, member users of one personal interaction hub may also be based on a single member sign-on that identifies the member to the hub operating system service 634 and/or hub management service 614 multiple hubs. can be a member of For example, a person may be a member of a family hub that associates members of his or her family as well as members of a neighborhood hub that associates members of his or her neighborhood, and members of a golf hub that associates his friends who often play golf together. may be
Due to the integration of the mobile device's operating system 632 with the hub application 608, the user of the device may view messages or updates in the hub user interface 606 and in the application user interface of the application related to the message or update. have. For example, the hub calendar is integrated with a calendar application (eg, device application 636 ) on mobile device 602 , and a user can select calendar updates displayed in hub user interface 606 , such that the calendar user interface of the calendar application You can start the update displayed in . Alternatively, the user may view the calendar user interface and may select calendar events associated with the personal interaction hub to initiate display of the hub calendar including calendar events for members of the hub. As another example, hub calendar events may be displayed in the hub user interface, and the device calendar application may access and display hub calendar events along with any personal data calendar events that only the user of the device accesses; It can be viewed from the user interface of the device calendar application. Both the hub application 608 and the device application 636 obtain the same hub calendar event data (eg, the same hub data 610 stored on the mobile device). Two different user interfaces (eg, a hub user interface and a device application user interface) display the same calendar event data.
As another example, hub message and chat features are integrated with a messaging application (eg, device application 636 ) on mobile device 602 , and send email, text, or instant messages displayed in hub user interface 606 to the mobile device ( 602), may initiate a configuration in which a message is displayed in a messaging application user interface. Alternatively, the user may view the latest message from a member of the personal interaction hub in the messaging application user interface, and may select a message to initiate display of the hub message interface, such as viewing a conversation thread related to the latest message. You may.
As an embodiment, the hub operating system service 634 on the mobile device 602 may also provide a public social service such as two or more of the hub's members (eg, FACEBOOK®, TWITTER® or LINKEDIN®). Member users of personal interaction hub 618 may receive social network updates, such as when they are "friends" on network sites. Social network updates may be pulled from social networking sites based on the established association of the hub member's account identifier 620 of the personal interaction hub 618 in the hub management service 614 . The hub operating system service 634 may then aggregate social network updates for that particular hub for display on the hub user interface 606 or on a home page "live tile" associated with the hub. The hub operating system service 634 at the mobile device 602 may also be implemented to coordinate a plurality of user interaction updates for events managed at the personal interaction hub. For example, several members of the hub may participate in a multi-player interactive game, with each successive interactive update from a member of the hub initiated by the member at each associated mobile device.
7 illustrates an example system 700 that may implement various embodiments of a personal interaction hub, limited execution mode, and/or family coordination. This example system may be any one or combination of a mobile phone 704 , a tablet device 706 , a computing device 708 , a communication, entertainment, gaming, navigation, and/or other type of portable electronic device. and a client device 702 with Any of the client devices 710 may be implemented with any number of different components in combination, as well as multiple components, such as processors and/or memory systems, as further described with reference to the example device shown in FIG. 10 . can be
The example system 700 includes a device related service 712 that associates or correlates a client device 710 by a device identifier 714 , a user identifier 716 , and/or any other type of identifiable association. do. Any of the devices and services may communicate via a network 718 , which may be configured to include wired and/or wireless networks. A network may also be implemented using any type of network topology and/or communication protocol, and may be represented as a combination of two or more networks or otherwise implemented, thereby providing an IP-based network and/or the Internet. may include The network may also include a mobile operator network managed by a mobile operator, such as a communication service provider, a cellular phone provider, and/or an Internet service provider. A mobile operator may facilitate mobile data and/or voice communications to any type of wireless device or mobile phone.
Each client device 710 may be associated with a different user, and the user is a limited member of the family 720 . Exemplary client device 702 represents several client devices 710 within a family. Any of the client devices in the family may include a service, such as a software application (eg, computer-executable instructions), that may be executed by a processor or processor system to implement the embodiments described herein. In this example, the client device 702 includes a family coordination architecture 722 that implements the characteristics of a family hub; a parental control service 724 that implements characteristics of the parent dashboard; family check-in service (726); device quiescent service 728 that implements the characteristics of quiet time and quiet zone; and a device sharing service 732 . The client device service is further described with reference to FIG. 8 .
Also, any of several client device services or a combination thereof may be extracted for implementation by a network service provider, such as a device related service 712 . For example, related client devices 710 in family 720 may be interconnected via a central computing device or system that may be located within or remote from multiple devices (eg, client device 710 ). may be one of them). By way of example, the central computing device may be a cloud service of one or more server computers that are connected to a plurality of devices via a network 718 or other communication link. Due to the interconnected architecture, functionality across multiple devices may provide a common and seamless experience for users of multiple devices. Each of the client devices may have different physical configurations and capabilities, and the central computing device implements a platform tailored to a particular device and still capable of delivering an experience common to all devices.
8 further illustrates several client device services described with reference to FIG. 7 . The client device 702 includes a family coordination architecture 722 , a parental control service 724 , a family check-in service 726 , a device suspension service 728 , a secure startup service 730 , and a device sharing service 732 . , and these services may be implemented as limited execution services 202 described with reference to FIGS. 1 to 6 . In embodiments, the family coordination architecture 722 may be implemented as a service as generally described herein. In general, any of the described services are software, firmware, hardware (eg, fixed logic circuits), manual processing, applications, routines, programs, objects, components, data structures, procedures, modules, functions, or any of these. It may be embodied and/or described in the general context of any combination. A software implementation represents program code that, when executed by a computer processor, executes particular tasks. In embodiments, any of the functions of processing, computation, filtering, code execution, etc. may be implemented in distributed computing services and/or devices, such as on client devices, server devices, and/or network-based services.
In this example of a client device service, family coordination architecture 722 includes family calendar 802 , family chat 804 , family shared contacts 806 , family journal and memory 808 , tasks and chores 810 , and a family hub manager 800 that implements, coordinates and/or manages various family characteristics, such as family height 812 and family budget 814 . Parental control service 724 implements features such as parental dashboard manager 816 , age-appropriate content control 818 , and secure social networking 820 . The device downtime service 728 implements features such as downtime 822 and downtime zone 824 . Several client device services and features are further described throughout this specification.
Any of the client device services may include, integrate with, or implement any of the other client device services and applications. For example, the family coordination architecture 722 may include any one of a parental control service 724 , a family check-in service 726 , a device stop service 728 , a secure drive service 730 , and a device sharing service 732 . or a combination thereof. In embodiments, a family coordination architecture may be implemented for coordination of time, messaging, data, activity, and any other shared services. A shared service may be any type of shared service and/or any client device service that may be associated with a service and/or multiple system operator (MSO) device. Additionally, parental control services may be implemented to reduce, extend, manage and/or reallocate data sharing of client device services.
Any of the family characteristics and/or applications of the family coordination architecture may be implemented as individuals, some private and some public, or individuals with additional user control, such that public third-party services and applications and information and data can share Similarly, any of the client device services and applications described herein may be private, public, sharable, user-controllable, and/or any combination thereof. In embodiments, the Family Coordination Architecture and/or Family Hub Manager is a collective embodiment of any of the client device services and/or applications that are exemplified together as a Family Coordination and/or Family Hub architecture and may be implemented for scalability. , integrated and/or implemented as an overall management architecture. Further, any of the client device services may include, integrate with or implement any of the other client device services and applications, and may be implemented collectively as a family hub and/or coordinating architecture or service. .
Device sharing service 732 implements a phone sharing feature so that a user can share his or her phone (eg, a mobile device) with others, but others' access to features, functions, and information on the phone. As can constrain the constrained execution service 202 described with reference to FIGS. 1-6 . For example, a user owner of a mobile phone can activate a restricted run mode on the device, and then share the phone with a stranger. In the restricted execution mode, only outgoing phone calls can be allowed, so the restricted execution mode forces task restrictions to limit incoming calls, but the origin of the outgoing calls is traced to the device phone application contained in the shared space ( traced) allows outgoing calls.
As an implementation, a parent can share his or her phone with a child so that they can play games on the phone, but the child can receive phone calls, read email, access texts, and access any other data and phone settings. access or initiate any type of financial transaction (eg, purchasing a phone app or music download). Similarly, a phone user can share a picture of him or her on his or her phone with a friend who has requested to view those pictures, but the friend does not have access to any other phone data or settings. The phone user may also share his or her phone with someone who needs to make phone calls, but may not provide access to any other phone data or settings.
Phone sharing, as a feature of restricted run mode, can be password-given, allowing only other people to access specified functions on the phone based on user-set restrictions. A phone sharing pass-code can be quickly initiated with a gesture, keystroke, or keystroke sequence. In addition, phone sharing profiles may be implemented for different types of individuals, such as friends, parents, strangers, kids, children, and the like. The phone sharing feature also applies to family calls within the home that any household member may have, such as when children go out to play with friends, parents send errands to the store, or are given to guests in the home to use during their stay. can be implemented.
Device sharing service 732 is also implemented to limit the communication capabilities of mobile device 1000 by limiting incoming phone calls and message display, but may allow outgoing phone calls for shared uses. Message displays may include email and text message displays, calendar events and alerts, instant messages, and any other messages that may be displayed to the user who owns the device (eg, not the temporarily sharing user). In the shared usage mode of the mobile device, the device sharing service 732 may also enable the user to execute purchase transactions, download music, purchase and download applications, and execute other types of financial transactions. may restrict access to applications that allow users to initiate financial transactions, such as through browsers, music and/or gaming applications. However, there may be instances where you might allow a child to access more money, such as catching a taxi in an emergency. Device sharing service 732 may also be implemented to limit a child's ability to pair his or her phone with a car or transfer items from a phone to a printer within the home. As the phone is NFC-enabled and the key can be replaced if the phone provides secure access, the device sharing service 732 may be implemented to limit a child's ability to open some doors using a phone device. can
9 is an example of a system 900 illustrating two different examples of hub user-interfaces 902 and 904 for a family-oriented hub. The description, layout of text, images, photos, graphics, links, data, information and display characteristics with reference to the hub user interface as well as any other user interface described herein and/or shown in the drawings. , orientation, characteristics, and configurations are merely examples and may vary in any configuration for various embodiments and/or implementations of mobile device check-in.
A hub is a central space for membership-oriented coordination of communication, activity, information and integration. Designated member relationships can be used to define how data and information are managed, and can be implemented to influence social contracts, such as between members of a defined family group in the illustrated example. In one or more implementations, the hub is implemented as a user interface (eg, via a client device application) for membership-oriented communication, aggregation and aggregation of activities and information. A hub can be implemented as a shared space of individuals among limited members. The hub contains links to other members' profiles and, based on limit settings, allows recruitment for visibility of some of the other members' data and information within the hub. A hub shares a group calendar that can be viewed and edited, a common text message window, a posting board, a shared photo album, check-in properties, and any other types of shared information.
A device and/or device account may be associated within a device or set of device accounts (eg, family phone account, user account, set of connected devices, etc.), wherein all or a subset of the device or account may communicate with another device or account. can Members of the hub may be defined by any number of different classes of people, such as teens, teens, moms, dads (or parents), grandparents, Nannys, life coaches, etc. for the illustrated example of a family. . Also, members of the family may be limited to distinguish a resident nanny from, for example, a babysitter.
Also, membership of the hub as well as use of the hub by members may be controlled by a selected set of users, such as one or two mobile phones by the relevant users of the client device. For example, one of the members in the hub may be a designated controller, such as a mother who does housework, an employer, and the like.
From a single configuration of members, hubs can be automatically provisioned, set up and propagated, for example. The hub's properties and configurations can be defaulted to automatic, easy-to-setup, but any rule, property, or configuration aspect can be easily changed by the user. Providing a hub may be based on an invoice, such as a family or company's billing plan. However, if the phone device is switched to, for example, a different carrier, the phone device may also receive texts related to the hub. Alternatively or additionally, providing a hub may be based on an email address, phone number, user account identifier, or any other identifier.
For example, a retailer selling a new phone package can easily identify each member for that new phone device and launch the illustrated hub. From a consumer point of view, this configuration just works, and members can set everything up outside the store and then come out. Both data and information can be shared with a single selection, so members do not need to share each item (eg, grocery list, photos, calendar, etc.) individually and separately.
The hub user interface may act as a shared space that is customizable and provides user-generated and shared content. Some information may be shared, others not. For example, mom's complete Christmas list cannot be viewed by other family members, but dad and children can add to the list (and only watch their contributions). Hub setup can be done "a la carte", meaning that members can select only the properties they want to display on the hub wall. For example, mom wants to see a shopping list, while dad doesn't shop and thus wants to avoid having the list displayed on his device, but dad still has access to the shopping list and can add items if desired. can do.
The hub user interface integrates functionality, calendar functionality, events and/or data summaries (ie, on a "month") as well as content shared between members of the hub (eg, lists, documents, etc.). For example, the hub user interface may include a "family check-in" or "check-in" option. The hub user interface may also include a chat section where location check-ins received in messages are displayed along with other messages exchanged between members of the hub. The hub "wall" represents an area that members of the group can add as desired, such as canteen bulletin boards, family refrigerators, and the like. In implementations, information may be gathered in pillars or columns as illustrated and displayed on a hub wall. The hub wall may also represent a temporal correlation between any of the data and information appearing on the wall and its placement. By setting the hub, the user can control which functions are integrated and displayed within the hub, such as on the wall.
Hub information can also be context related to members of the hub, and the calendar includes shared hub events. Calendar updates can be posted as notification events on the month, and the user can view the month to see upcoming hub events or events belonging to one or more other members of the hub. Private messaging may also be performed between members of the hub. A member can send an instant text (or other communication) to all other members within the hub. Texting, such as for a business meeting, can split each member's display on its respective device into separate screens for each member.
A hub may also be extended, allowing it to link to a hard drive on a home computer, or synchronize to just one of another device, administrator, or cloud control (eg, from a network-based service). The hub may also extend to third parties adding notes on the hub wall, such as implemented as an application program interface (API) for the ability to post data to the hub. However, third party applications will not have access to the context of the hub wall, such as obtaining or displaying hub data. Personal information and hub data may be encrypted and only decrypted by the phone device associated with the hub.
Thus, a hub supported by a hub coordination architecture may be considered as a central space for the coordination of communications, activities, information and integration of members of the hub. A hub may be defined to support a variety of different memberships, such as for family members, colleagues, friends, acquaintances, fan clubs, and the like. Therefore, although the following description discusses family-related examples, it should be apparent that the membership of the hub may be defined in a variety of other ways without departing from the spirit and scope of the present invention. Accordingly, the hub coordination architecture may be used to support a variety of different functions. An example of such functionality is described herein as a hub limited execution service, and additional aspects of a personal interaction hub are also described herein.
10 illustrates an example system 1000 that includes an example device 1002 that may implement embodiments of a restricted execution mode. The exemplary device 1002 may be described with reference to FIGS. 1-9 above, such as any type of client or mobile device, mobile phone, tablet, computing, communications, entertainment, gaming, media playback, and/or other type of device. It may be implemented as any of the devices, services and/or servers described. For example, the mobile device 100 shown in FIGS. 1 and 2 may be implemented as the example device 1002 .
Device 1002 includes a communication device 1004 that enables wired and/or wireless communication of device data 1006, such as media content and share messages, updates, and event data of the device. Media content may include any type of audio, video and/or image data. Communication device 1004 may also include a transceiver for cellular phone communications and/or network data communications.
Device 1002 also includes an input/output (I/O) interface 1008 , such as a data network interface that provides connectivity and/or communication links between the device, data networks, and other devices. The I/O interface may be used to couple the device to any type of component, peripheral, and/or auxiliary device. The I/O interface may also include any type of data, media content and/or data, such as any type of audio, video and/or image data received from any content and/or data source, as well as user input to the device. and a data input port allowing input to be received.
I/O interface 1008 may also be, such as any interface technology, capable of allowing a user to interact with a device in a "natural" manner free from artificial constraints imposed by input devices such as mice, keyboards, remote control devices, etc. Supports natural user interface (NUI) input to device 1002 . Examples of natural user interface input include voice recognition, touch and stylus recognition, gesture recognition near the device, on-screen and movement gesture recognition, head, eye and environment recognition, tracking, augmented reality and virtual reality systems, and user input. It may rely on any other type of auditory, visual, touch, gesture and/or machine intelligence capable of determining intent.
Device 1002 includes a processing system 1010, which may be implemented at least in part in hardware, such as via any type of microprocessor, controller, etc., that processes executable instructions. A processing system is a combination of integrated circuits such as processors and memory systems implemented as system-on-chip (SoC), programmable logic devices, logic devices formed using one or more semiconductors, and other implementations in silicon and/or hardware. It may contain components. Alternatively or additionally, the device may be implemented in any one or combination of fixed logic circuitry, which may be implemented in software, hardware, firmware, or processing and control circuitry. Device 1002 may further include any type of system bus or other data and instruction transfer system that couples the various components within the device. The system bus may include any one or combination of control and data lines as well as different bus structures and architectures.
Device 1002 may also be accessed by a computing device and provide permanent storage of data and executable instructions (eg, software applications, programs, functions, etc.), computer-readable storage media 1012 , such as data storage devices. ) is included. Examples of computer-readable storage media include volatile and non-volatile memory, fixed and removable media devices, and any suitable memory device or electronic data storage device that retains data for computing device access. Computer-readable storage media may include various implementations of random access memory (RAM), read-only memory (ROM), flash memory, and other types of storage media in various memory device configurations.
In general, computer readable storage media refers to media and/or devices that enable permanent and/or non-transitory storage of data as opposed to simple signal transmission, carrier waves, or the signal itself. Computer-readable signal medium may refer to a signal-bearing medium that transmits instructions, such as over a network. The signal medium may embody computer readable instructions, such as data in a modulated data signal, such as a carrier wave or other transport mechanism.
Computer-readable storage medium 1012 is a computer-readable storage medium that is maintained as software applications and is executed by processing system 1010 for storage of various device applications 1014 and device data 1006, such as an operating system. do. In this example, the device application also includes a device sharing service 1016 that implements an embodiment in a restricted execution mode, such as when the example device 1002 is implemented as the mobile device 100 shown in FIG. 1 . . An example of a device sharing service 1016 is a limited execution service 202 that is integrated with the operating system 204 in the mobile device 100 , as described with reference to FIG. 1 .
Device applications 1014 may also include any of the services and applications 1018 implementing restricted execution mode embodiments. The example device 1002 may also be implemented in the general context of software, firmware, hardware (eg, fixed logic circuitry), or any combination thereof, allowing embodiments of limited execution modes and/or mobile device family coordination. It includes a family coordination architecture 1020 that can support. Device 1002 may also include a positioning system 1022, such as a GPS transceiver or similar positioning system component, which may be used to determine a global or navigational location of the device.
Device 1002 also includes an audio and/or video system 1024 that generates audio data for audio device 1026 and/or generates display data for display device 1028 . Audio devices and/or display devices include any device that processes, displays, and/or otherwise renders audio, video, display and/or image data. In an implementation, the audio device and/or display device are integrated components of the example device 1002 . Alternatively, the audio device and/or display device are external peripheral components to the exemplary device.
In embodiments, at least some of the techniques described for limited execution modes may be implemented in a distributed system, such as via a "cloud" 1030 on a platform 1032 . Cloud 1030 includes and/or represents a platform 1032 for services 1034 and/or resources 1036 . For example, services 1034 may include any of data services 208 and cloud storage and services 206 as described with reference to FIG. 1 . Resource 1036 may also include accessible data 210 as described with reference to FIG. 1 .
Platform 1032 summarizes the underlying functionality of hardware, such as server devices (e.g., included in server 1034) and/or software resources (e.g., included as resource 1036), and 1002) to other devices, servers, etc. Resources 1036 may also include applications and/or data that may be utilized, while computer processing is performed on a server remote from example device 1002 . Services 1034 and/or resources 1036 may also facilitate subscriber network services, such as over the Internet, a cellular network, or a Wi-Fi network. Platform 1032 also provides the ability to extract and scale resources to service demand for resources 1036 implemented through the platform, such as in an interconnected device embodiment with functionality distributed throughout system 1000 . can do. For example, the functionality may be implemented in part on the example device 1002 as well as via the platform 1032 that summarizes the functionality of the cloud 1030 .
Although embodiments of limited execution modes have been described in language specific to features and/or methods, the appended claims are not necessarily limited to the specific features or methods described. Rather, the specific features and methods are disclosed as example implementations of restricted modes of execution.
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| JP2009017239A | Cites | Japan | A | Search report | 1 |
| US2009303231A1 | Cites | United States of America | A | Search report | 1 |
| KR20100022509A | Cites | Republic of Korea | A | Search report | 1 |
| KR20100074218A | Cites | Republic of Korea | Y | Search report | 3,13,15 |
| KR20110066203A | Cites | Republic of Korea | A | Search report | 1 |
| KR20110100208A | Cites | Republic of Korea | A | Search report | 1 |
| KR20110102880A | Cites | Republic of Korea | Y | Search report | 1-20 |
| KR20110116383A | Cites | Republic of Korea | Y | Search report | 1-20 |
68 members in 7 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 61580147 | United States of America | – | |
| 201161580147 | United States of America | P | |
| 61695294 | United States of America | – | |
| 201261695294 | United States of America | P | |
| 13726099 | United States of America | – | |
| 201213726099 | United States of America | A | |
| 2012071557 | United States of America | W |
Members68
| Document | Office | Kind | |
|---|---|---|---|
| WO2013096943A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096944A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096947A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096949A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2013096950A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2013225151A1 | United States of America | A1 | |
| US2013225152A1 | United States of America | A1 | |
| US2013227431A1 | United States of America | A1 | |
| US2013295872A1 | United States of America | A1 | |
| US2013295913A1 | United States of America | A1 | |
| US2013298037A1 | United States of America | A1 | |
| US2013303143A1 | United States of America | A1 | |
| US2013305319A1 | United States of America | A1 | |
| US2013305354A1 | United States of America | A1 | |
| US2014068755A1 | United States of America | A1 | |
| WO2014035454A1 | World Intellectual Property Organization (WIPO) | A1 | |
| TW201415245A | Taiwan Province of China | A | |
| CN104011630A | China | A | |
| CN104012133A | China | A | |
| CN104012150A | China | A | |
| CN104012151A | China | A | |
| KR20140113985AThis record | Republic of Korea | A | |
| US8874162B2 | United States of America | B2 | |
| CN104126315A | China | A | |
| EP2795435A1 | European Patent Office (EPO) | A1 | |
| EP2795939A1 | European Patent Office (EPO) | A1 | |
| EP2795949A1 | European Patent Office (EPO) | A1 | |
| EP2795970A1 | European Patent Office (EPO) | A1 | |
| EP2795971A1 | European Patent Office (EPO) | A1 | |
| US2015011203A1 | United States of America | A1 | |
| EP2795949A4 | European Patent Office (EPO) | A4 | |
| EP2795970A4 | European Patent Office (EPO) | A4 | |
| JP2015508530A | Japan | A | |
| CN104584607A | China | A | |
| KR20150052035A | Republic of Korea | A | |
| EP2795939A4 | European Patent Office (EPO) | A4 | |
| EP2795971A4 | European Patent Office (EPO) | A4 | |
| EP2891353A1 | European Patent Office (EPO) | A1 | |
| EP2795435A4 | European Patent Office (EPO) | A4 | |
| US2015220712A1 | United States of America | A1 | |
| JP2015528674A | Japan | A | |
| US9230076B2 | United States of America | B2 | |
| US9325752B2 | United States of America | B2 | |
| EP2891353A4 | European Patent Office (EPO) | A4 | |
| US9363250B2 | United States of America | B2 | |
| US2016197968A1 | United States of America | A1 | |
| US9420432B2 | United States of America | B2 | |
| US2016248906A1 | United States of America | A1 | |
| US9467834B2 | United States of America | B2 | |
| US9491589B2 | United States of America | B2 | |
| US2016328902A1 | United States of America | A1 | |
| JP6058138B2 | Japan | B2 | |
| US9665702B2 | United States of America | B2 | |
| US9680888B2 | United States of America | B2 | |
| CN104011630B | China | B | |
| TWI588664B | Taiwan Province of China | B | |
| US9710982B2 | United States of America | B2 | |
| JP2017130960A | Japan | A | |
| US9736655B2 | United States of America | B2 | |
| EP2795971B1 | European Patent Office (EPO) | B1 | |
| EP2795949B1 | European Patent Office (EPO) | B1 | |
| JP6275650B2 | Japan | B2 | |
| CN104012150B | China | B | |
| EP2795939B1 | European Patent Office (EPO) | B1 | |
| CN104012133B | China | B | |
| CN104584607B | China | B | |
| US10249119B2 | United States of America | B2 | |
| KR102011177B1 | Republic of Korea | B1 |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of rejection after re-examinationX601 | X601 | |
| AmendmentAMND | AMND | |
| Decision to refuse applicationE601 | E601 | |
| Application refused [patent]X091 | X091 | |
| AmendmentAMND | AMND | |
| Notification of reason for refusalE902 | E902 | |
| Request for examinationA201 | A201 | |
| AmendmentAMND | AMND | |
| Notification of change of applicantN231 | N231 |
Numbers
- Publication
- 10-2014-0113985
- Application
- 1020147020747
Titles4
- Korean
- 제한된 실행 모드
- English
- RESTRICTED EXECUTION MODES
- Unlabeled
- 제한된 실행 모드{RESTRICTED EXECUTION MODES}
- Unlabeled
- RESTRICTED EXECUTION MODES
Classification
- CPC, 14
- G06F21/629
- G06F21/31
- H04W12/08
- H04W88/02
- H04L63/105
- G06F21/6218
- G06F21/6281
- H04W4/60
- G06F2221/2149
- H04W12/37
- H04W12/68
- H04W12/10
- G06F2221/2129
- G06F21/53
- IPC, 4
- H04W88 02
- H04W4 00
- G06F21 31
- H04W4 60