IP Library Granted Patent US 11,380,428
Granted Patent B2
US 11,380,428 · App. 16/846,759 · Granted Jul 5, 2022

Location-based anticipatory resource provisioning

Inventor: Meinhard Dieter Ullrich (Lexington, MA)
Assignee: IMPRIVATA, INC.
G16H10/60G06F3/0482G16H40/20G16H40/67G16Z99/00H04L63/08H04L67/12H04L67/18H04L67/22H04W4/023H04W4/029H04W4/33H04W64/00H04W12/06H04W12/63H04W60/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,380,428
App. No.
16/846,759
Granted
Jul 5, 2022
Kind
B2
Abstract

In various embodiments, the predicted location of a user within an institutional space is associated with a node at or near that location, and a virtual desktop is prepared before a user has actually logged on and authenticated. Although users are not accorded access to applications and sensitive data until they have properly authenticated themselves, the virtual desktop and associated data are assembled and retrieved in the background in order to eliminate delay following log-on.

Claims (25)

1. A method of anticipatory provisioning of resources for mobile users in an institutional space, the method comprising:

providing a database storing records for a plurality of users, each of the records specifying, for one of the users, data specifying a provisioning policy for the user including at least one location-based triggering event;

detecting an electronically detected location-based triggering event indicative of departure of a first mobile user from a first network node at which the first mobile user accessed a first virtual desktop;

in response to the electronically detected location-based triggering event indicative of departure of the first mobile user from the first network node, predicting a second network node, within the institutional space, that the first mobile user is likely to access;

detecting unsuitability of the second network node for use by the first mobile user;

predicting a third network node, different from the second network node and within the institutional space, that the first mobile user is likely to access; and

delivering the first virtual desktop to the third network node prior to arrival of the first mobile user at the third network node.

2. The method of claim 1 , wherein detecting unsuitability of the second network node for use by the first mobile user comprises detecting use of the second network node by a mobile user other than the first mobile user.

3. The method of claim 2 , wherein the first virtual desktop is not delivered to the second network node before the first virtual desktop is delivered to the third network node.

4. The method of claim 1 , wherein detecting unsuitability of the second network node for use by the first mobile user comprises detecting movement of the first mobile user within the institutional space past the second network node without electronically detecting a location-based triggering event indicative of arrival of the first mobile user at the second network node.

5. The method of claim 4 , wherein (i) the first virtual desktop is delivered to the second network node before unsuitability of the second network node for use by the first mobile user is detected, and (ii) the first virtual desktop is revoked from the second network node after unsuitability of the second network node for use by the first mobile user is detected.

6. The method of claim 1 , further comprising, after arrival of the first mobile user at the third network node, receiving log-on credentials for the first mobile user, and, upon acceptance of the log-on credentials for the first mobile user, providing network-based access for the first mobile user to the first virtual desktop at the third network node.

7. The method of claim 1 , wherein each of the records in the database specifies, for one of the users, data specifying a privilege level for the user, the method further comprising:

detecting an electronically detected location-based triggering event indicative of departure of a second mobile user from a fourth network node at which the second mobile user accessed a second virtual desktop, the second mobile user having a privilege level different from the privilege level of the first mobile user;

only in response to an electronically detected location-based triggering event indicative of arrival of the second mobile user at a fifth network node, delivering the second virtual desktop to the fifth network node; and

receiving log-on credentials for the second mobile user, and, upon acceptance of the log-on credentials for the second mobile user, providing network-based access for the second mobile user to the second virtual desktop at the fifth network node.

8. The method of claim 1 , wherein at least one of the second network node or the third network node is predicted based on information accessed by the first mobile user at the first network node.

9. The method of claim 8 , wherein the information comprises patient information.

10. The method of claim 1 , wherein at least one of the second network node or the third network node is predicted based on a location history, within the institutional space, of the first mobile user.

11. The method of claim 1 , wherein the first virtual desktop is delivered to the third network node after a confidence level of the prediction of the third network node exceeds a threshold.

12. The method of claim 1 , wherein the at least one location-based triggering event in the provisioning policy for a particular user depends at least in part on an identity of the user.

13. The method of claim 1 , wherein the first virtual desktop comprises data from a previous session of the first mobile user.

14. The method of claim 1 , wherein the first virtual desktop, when delivered to the third network node, includes (i) data from a session of the first mobile user on the first network node when a default-restoration triggering event has not occurred prior to delivery of the first virtual desktop, or (ii) default data for the first mobile user when the default-restoration triggering event has occurred prior to delivery of the first virtual desktop.

15. The method of claim 14 , wherein the default-restoration triggering event comprises a log-off by the first mobile user from the first network node.

16. The method of claim 14 , wherein the default-restoration triggering event comprises a period of inactivity associated with the session of the first mobile user on the first network node.

Assignments (4)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 59644/0097 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0732 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2022
From: ULLRICH, MEINHARD DIETER
To: IMPRIVATA, INC.
Reel/Frame 059826/0744 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 8, 2022
From: IMPRIVATA, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059644/0097 →
SECURITY INTEREST Recorded Dec 22, 2020
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054836/0937 →
Continuity (5)
Continuation 16244587 · Jan 10, 2019
Continuation 14945658 · Nov 19, 2015
Provisional Application 62183793 · Jun 24, 2015
Provisional Application 62081820 · Nov 19, 2014
Related Publication 20200310606A1 · Oct 1, 2020