IP Library Granted Patent US 11,848,935
Granted Patent B2
US 11,848,935 · App. 17/346,550 · Granted Dec 19, 2023

Dynamically generating restriction profiles for managed devices

Inventor: Bahram Ali Zadeh (Duluth, GA)
Assignee: VMware, Inc.
H04L63/102G06F8/71G06F21/577G06F21/6218G06Q10/0635H04L63/105H04W12/37H04L63/104H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,848,935
App. No.
17/346,550
Granted
Dec 19, 2023
Kind
B2
Abstract

Disclosed are various examples for dynamically generating restriction profiles for updated software platforms. A management system can determine that updated restrictions and/or settings are included in an updated or new version of a definition file. The updated settings identified and categorized according to risk for a given enterprise group without administrator input. An updated restriction profile can be generated according to the updated settings and distributed to managed devices.

Claims (39)

1. A system for dynamically generating restriction profiles for an updated software platform, the system comprising:

at least one computing device; and

at least one application executable in the at least one computing device, wherein the at least one application, when executed, causes the at least one computing device to:

identify a current version of a restriction definition file associated with the updated software platform;

determine that the current version of the restriction definition file differs from an applied version of the restriction definition file by identifying an updated restriction setting in the current version of the restriction definition file;

determine a risk level associated with the updated restriction setting for the enterprise group;

determine that a plurality of client devices require an updated restriction profile of the restriction definition file based at least in part on a restriction setting level associated with an enterprise group corresponding to the plurality of client devices, the updated restriction profile specifying at least one limit on hardware capabilities accessible through the updated software platform; and

cause the updated restriction profile to be distributed to the plurality of client devices.

2. The system of claim 1 , wherein, when executed, the at least one application further causes the at least one computing device to at least generate the updated restriction profile according to the updated restriction setting, the risk level, and the setting restriction level of the enterprise group.

3. The system of claim 1 , wherein, when executed, the at least one application further causes the at least one computing device to at least:

receive feedback from at least a subset of the plurality of client devices with respect to a restriction setting of the updated restriction profile; and

modify the updated restriction profile based at least in part on the feedback.

4. The system of claim 1 , wherein, when executed the at least one application further causes the at least one computing device to at least receive information from an original equipment manufacturer (OEM) of the updated software platform, wherein determining that the plurality of client devices require the updated restriction profile of the restriction definition file is further based on the information received from the OEM.

5. The system of claim 1 , wherein, when executed the at least one application further causes the at least one computing device to at least receive a request to subscribe to a service that automatically generates the updated restriction profile.

6. A computer-implemented method for dynamically generating restriction profiles for an updated software platform, the method comprising:

identifying a current version of a restriction definition file associated with the updated software platform;

determining that the current version of the restriction definition file differs from an applied version of the restriction definition file by identifying an updated restriction setting in the current version of the restriction definition file;

determining a risk level associated with the updated restriction setting for the enterprise group;

determining that a plurality of client devices require an updated restriction profile of the restriction definition file based at least in part on a restriction setting level associated with an enterprise group corresponding to the plurality of client devices, the updated restriction profile specifying at least one limit on hardware capabilities accessible through the updated software platform; and

causing the updated restriction profile to be distributed to the plurality of client devices.

7. The computer-implemented method of claim 6 , further comprising generating the updated restriction profile according to the updated restriction setting, the risk level, and the setting restriction level of the enterprise group.

8. The computer-implemented method of claim 6 , further comprising:

receiving feedback from at least a subset of the plurality of client devices with respect to a restriction setting of the updated restriction profile; and

modifying the updated restriction profile based at least in part on the feedback.

9. The computer-implemented method of claim 6 , further comprising:

receiving information from an original equipment manufacturer (OEM) of the updated software platform, and

wherein determining that the plurality of client devices require the updated restriction profile of the restriction definition file is further based on the information received from the OEM.

10. The computer-implemented method of claim 6 , further comprising receiving a request to subscribe to a service that automatically generates the updated restriction profile.

11. A non-transitory computer-readable medium embodying executable instructions, which, when executed by a processor, cause at least one computing device to at least:

identify a current version of a restriction definition file associated with an updated software platform;

determine that the current version of the restriction definition file differs from an applied version of the restriction definition file by identifying an updated restriction setting in the current version of the restriction definition file;

determine a risk level associated with the updated restriction setting for the enterprise group;

determine that a plurality of client devices require an updated restriction profile of the restriction definition file based at least in part on a restriction setting level associated with an enterprise group corresponding to the plurality of client devices, the updated restriction profile specifying at least one limit on hardware capabilities accessible through the updated software platform; and

cause the updated restriction profile to be distributed to the plurality of client devices.

12. The non-transitory computer-readable medium of claim 11 , wherein, when executed, the executable instructions further cause the at least one computing device to at least generate the updated restriction profile according to the updated restriction setting, the risk level, and the setting restriction level of the enterprise group.

13. The non-transitory computer-readable medium of claim 11 , wherein, when executed, the executable instructions further cause the at least one computing device to at least:

receive feedback from at least a subset of the plurality of client devices with respect to a restriction setting of the updated restriction profile; and

modify the updated restriction profile based at least in part on the feedback.

14. The non-transitory computer-readable medium of claim 11 , wherein when executed the executable instructions further cause the at least one computing device to at least receive information from an original equipment manufacturer (OEM) of the updated software platform, wherein determining that the plurality of client devices require the updated restriction profile of the restriction definition file is further based on the information received from the OEM.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →