Invention Application
- Patent Title: METHODS FOR RESTRICTING RESOURCES USED BY AN APPLICATION BASED ON A BASE PROFILE AND AN APPLICATION SPECIFIC PROFILE
-
Application No.: US15663432Application Date: 2017-07-28
-
Publication No.: US20180012017A1Publication Date: 2018-01-11
- Inventor: Pierre-Olivier J. Martel , Kelly B. Yancey , Richard L. Hagy
- Applicant: Apple Inc.
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F21/62

Abstract:
In response to a request for launching an application within an operating system of a data processing system, one or more extended entitlements are extracted from the application, where the one or more extended entitlements specify one or more resources the application is entitled to access. One or more security profile extensions corresponding to the one or more extended entitlements are dynamically generated. A security profile specifically for the application is created based on the one or more security profile extensions and a base security profile that has been previously compiled, where the base security profile specifies a list of a plurality of base resources. The application is then launched in a sandboxed operating environment that is configured based on the security profile specifically generated for the application.
Public/Granted literature
Information query