IP Library Granted Patent US 10,044,715
Granted Patent B2
US 10,044,715 · App. 14/834,220 · Granted Aug 7, 2018

Method and apparatus for presence based resource management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,715
App. No.
14/834,220
Granted
Aug 7, 2018
Kind
B2
Abstract

Methods and apparatus provide resource authorization based on a computer's presence information. Presence information may include information relating to a computer's operating environment. In some implementations, a presence detector on a computer determines presence information and provides the information to a resource manager. The computer may then generate a resource access request. A resource manager may then determine whether the resource request is authorized based, at least in part, on the presence information. The resource manager then responds to the resource access request, either granting or denying the request for resources.

Claims (53)

1. A method of managing a user's access to network resources, comprising:

receiving, from a computer over a network, first presence data of a user logged into the computer;

receiving a first network request by the logged in user from the computer for first resources external to the computer;

executing instructions on computer hardware to determine a first resource control policy to apply to the first network request based on the first presence data;

executing instructions on computer hardware to apply the first resource control policy to the first network request;

receiving, from the computer over the network, second presence data of the logged in user of the computer;

receiving a second network request by the logged in user from the computer for second resources external to the computer;

executing instructions on computer hardware to determine a second resource control policy to apply to the second network request based on the second presence data; and

executing instructions on computer hardware to apply the second resource control policy to the second network request,

wherein the first and second presence data indicate at least one of: (a) a first and second ambient light level at the computer, (b) first and second font sizes displayed on the user's computer, (c) first and second contrast levels displayed on the user's computer, and (d) first and second indications respectively of whether a privacy shield is installed on the user's display and wherein the first and second resource control policies are determined based on the first and second presence data.

2. The method of claim 1 , wherein the first and second presence data are received over the network from an agent running on the computer.

3. The method of claim 2 , wherein the first and second presence data further indicate a first and second interactivity level of the logged in user.

4. The method of claim 1 , wherein the first and second presence data further indicate first and second display settings of the user's display, and wherein the first and second resource control policies are determined based on the first and second display settings of the user's display.

5. The method of claim 1 , wherein the first and second presence data further indicate first and second display types of respective displays of the user and wherein the first and second resource control policies are determined based on the first and second display types of the user's displays.

6. The method of claim 1 , wherein the first and second presence data further indicates first and second physical locations of the user's computer,

wherein the first and second resource control policies are determined based on the first and second physical locations, and

wherein the first resource control policy indicates the user's network communication is not encrypted and the second resource control policy indicates the user's network communication is encrypted.

7. The method of claim 1 , wherein the first and second presence data further indicates first and second physical locations of the user's computer,

wherein the first and second resource control policies are determined based on the first and second physical locations, and

wherein the first resource control policy indicates a first rate at which the user's computer can send or receive network data and the second resource control policy indicates a second rate at which the user's computer can send or receive network data.

8. The method of claim 1 , wherein the first and second presence data further indicates first and second physical locations of the user's computer,

wherein the first and second resource control policies are determined based on the first and second physical locations, and

wherein the first resource control policy indicates a first email header or footer to include in email sent by the user and the second resource control policy indicates a second email header or footer to include in email sent by the user.

9. The method of claim 1 , wherein the first and second presence data further indicates first and second speeds of a network connection of the user's computer,

wherein the first and second resource control policies are determined based on the first and second speeds, and

wherein the first resource control policy indicates a first rate at which the user may send or receive data over the network connection and the second resource control policy indicates a second rate at which the user may send or receive data over the network connection.

10. The method of claim 1 , wherein the first and second presence data further indicates first and second security levels of a network connection of the user's computer,

wherein the first and second resource control policies are determined based on the first and second security levels, and

wherein the first resource control policy indicates data the user sends or receives over the network connection is encrypted and the second resource control policy indicates data the user sends or receives over the network connection is not encrypted.

11. An apparatus, comprising:

a memory;

one or more electronic hardware processors, configured to fetch instructions from the memory; and

a network interface, operatively coupled to the one or more electronic hardware processors,

wherein the memory stores instructions that configure the one or more processors to perform a method of managing a computer's access to network resources, the method comprising:

receiving, from the computer over a network, first presence data of a logged in user of the computer;

receiving a first network request by the logged in user from the computer for first resources external to the computer;

determining a first resource control policy to apply to the first network request by the logged in user based on the first presence data;

applying the first resource control policy to the first network request;

receiving, from the computer over the network, second presence data of the logged in user of the computer;

receiving a second network request by the logged in user from the computer for second resources external to the computer;

determining a second resource control policy to apply to the second network request based on the second presence data; and

applying the second resource control policy to the second network request,

wherein the first and second presence data indicate at least one of: (a) a first and second ambient light level at the computer, (b) first and second font sizes displayed on the user's computer, (c) first and second contrast levels displayed on the user's computer, and (d) first and second indications respectively of whether a privacy shield is installed on the user's display and wherein the first and second resource control policies are determined based on the first and second presence data.

12. A non-transitory computer readable storage medium comprising instructions that when executed cause one or more processors to perform a method of managing a user's access to network resources, the method comprising:

receiving, from a computer and over a network, first presence data of a logged in user of the computer;

receiving a first network request by the logged in user from the computer for first resources external to the computer;

determining a first resource control policy to apply to the first network request by the logged in user for the first resources external to the computer based on the first presence data;

applying the first resource control policy to the first network request;

receiving, from the computer over the network, second presence data of the logged in user of the computer;

receiving a second network request by the logged in user from the computer for second resources external to the computer;

determining a second resource control policy to apply to the second network request by the logged in user based on the second presence data; and

applying the second resource control policy to the second network request,

wherein the first and second presence data indicate at least one of: (a) a first and second ambient light level at the computer, (b) first and second font sizes displayed on the user's computer, (c) first and second contrast levels displayed on the user's computer, and (d) first and second indications respectively of whether a privacy shield is installed on the user's display and wherein the first and second resource control policies are determined based on the first and second presence data.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: WEBSENSE, LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0440 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM WEBSENSE LLC TO WEBSENSE, LLC PREVIOUSLY RECORDED ON REEL 039590 FRAME 0646. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Sep 8, 2016
From: WEBSENSE, INC.
To: WEBSENSE, LLC
Reel/Frame 039951/0904 →
CHANGE OF NAME Recorded Aug 5, 2016
From: WEBSENSE, INC.
To: WEBSENSE LLC
Reel/Frame 039590/0646 →