WO2014151256A1

Certificate based profile confirmation

Abstract

Disclosed are various embodiments for controlling access to resources in a network environment. Methods may include installing a profile on the device and installing a certificate included in or otherwise associated with the profile on the device. A request to execute an application, and/or access a resource using a particular application, is received and determination is made as to whether the certificate is installed on the device based on an identification of the certificate by the application. If the certificate is installed on the device, then execution of the application and/or access to the resource is allowed. If the certificate is not installed on the device, then the request for execution and/or access is refused.

WO2014151256A1, drawing sheet 1
Sheet 1 of 3

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 8 independent, 7 dependent

  1. 1
    CLAIMS 1. A method, comprising:installing a plurality of profiles (123) on a device (120);installing a plurality of certificates (135) associated with the profiles (123) on the device (120);receiving a plurality of requests to execute a plurality of applications (126) on the device (120);in response to the requests to execute the applications (126), determining whether at least one of the certificates (135) are accessible to the device (120);and responsive to a determination that at least one certain of the certificates (135) are accessible to the device (120), executing applications (126) associated with the certain certificates (135);responsive to a determination that at least one certain of the certificates (135) are not accessible to the device (120), refusing the requests to execute applications (126) associated with the certain certificates (135).
  2. 5
    The method of any of claims 1 -4, wherein the profile (123) is uniquely associated with the application (126) and the certificate (135) is uniquely associated with the profile (123).
  3. 6
    The method of any of claims 1 -5, wherein said installing the plurality of certificates associated with the profiles includes storing the plurality of certificates (1350 in a trust store of the device (120), and said determining whether at least one of the certificates are accessible to the device includes determining whether the at least one of the certificates (135) is installed on device (120).
  4. 8
    The method of any of claims 1 -7, wherein the profiles (1230 comprise at least one of a plurality of iOS profiles, a plurality of Android OS profiles, a plurality of Windows Mobile profiles, a plurality of Windows Phone profiles, a plurality of Windows 8 profiles, a plurality of Mac OS X profiles, and a plurality of Symbian OS profiles, and the certificates (1350 are at least one of a plurality of root certificate and a plurality of intermediate certificates.
  5. 9
    A method of managing an application (126) on a device (120) based on the presence of a plurality of profiles (123) on the device (120), comprising:receiving a plurality of requests to execute a plurality of applications (126) on the device (120);identifying a plurality of certificates (135) associated with the profiles (123) and the applications (126);in response to the requests to execute the applications (126), determining whether at least one of the certificates (135) is accessible to the device (120);and responsive to a determination that at least one certain of the certificates (135) are accessible to the device (120), executing applications (126) associated with the at least one certain certificate (135);responsive to a determination that at least one certain of the certificates (135) are not accessible to the device (120), refusing the requests to execute applications (126) associated with the at least one certain certificate (135).
  6. 12
    An apparatus, comprising:a computing device (120);a display;and a processor, configured to: install a plurality of profiles (123) and a plurality of certificates (135) associated with the profiles (123);receive a plurality of requests to execute a plurality of applications (126) on the apparatus (120);identify a plurality of required certificates (135) associated with the applications (126);in response to the requests to open the applications (126), determine whether at least one of the required certificates (135) are accessible to the apparatus (120);responsive to a determination that at least one certain of the certificates (135) are accessible to the apparatus (120), executing applications (126) associated with the certain certificates (135);responsive to a determination that at least one certain of the certificates (135) are not accessible to the apparatus (120), refusing the requests to execute applications (126) associated with the certain certificates (135).
  7. 14
    The apparatus of any of claims 12-13, wherein the profiles (123) include one or more settings operative to, at least one of:control data transfer between the apparatus (120) and a plurality of remote servers (150);enable at least one function of the apparatus (120);and disable at least one function of the apparatus (120).
  8. 15
    The apparatus of any of claims 12-14, wherein the profiles (123) includes one or more settings operative to disable at least one of a camera, a screen capture function, a communication function and an audio function of the apparatus.