-
公开(公告)号:US11017109B1
公开(公告)日:2021-05-25
申请号:US16404538
申请日:2019-05-06
Applicant: Apple Inc.
Inventor: Kelly B. Yancey , Richard J. Cooper , Richard L. Hagy , Pierre-Olivier Martel , David P. Remahl , Jonathan A. Zdziarski
Abstract: Embodiments described herein provide techniques to limit programmatic access to privacy related user data and system resources for applications that execute outside of a sandbox or other restricted operating environment while enabling a user to grant additional access to those applications via prompts presented to the user via a graphical interface. In a further embodiment, techniques are applied to limit the frequency in which a user is prompted by learning the types of files or resources to which a user is likely to permit or deny access.
-
公开(公告)号:US12074849B2
公开(公告)日:2024-08-27
申请号:US17353690
申请日:2021-06-21
Applicant: Apple Inc.
Inventor: Ivan Krstic , Damien P. Sorresso , David P Remahl , Elliot C. Liskin , Justin S. Hogg , Kevin J. Lindeman , Lucia E. Ballard , Nicholas J. Circosta , Richard J. Cooper , Ryan A. Williams , Steven C. Vittitoe , Zachariah J. Riggle , Patrick R. Metcalfe , Andrew T. Whitehead
IPC: H04L29/06 , H04L9/40 , H04L51/212
CPC classification number: H04L63/0245 , H04L51/212
Abstract: The subject disclosure provides systems and methods for application-specific network data filtering. Application-specific network data filtering may be performed by a sandboxed process prior to providing the network data to an application to which the network data is directed. Any malicious or otherwise potentially harmful data that is included in the network data may be removed by the application-specific network data filter or may be allowed to corrupt the application specific network data filtering operations within the sandbox, thereby preventing the malicious or harmful data from affecting the application or other portions of an electronic device. In one or more implementations, a first process such as an application-specific network data filtering process may request allocation of memory for the first process from second process, such as an application, that is separate from a memory manager of the electronic device.
-