IP Library Granted Patent US 12,099,689
Granted Patent B2
US 12,099,689 · App. 17/377,868 · Granted Sep 24, 2024

Remotely restricting client devices

Inventors: Kevin Marshall McKeithan, II (Fort Worth, TX); William DeWeese (Haltom City, TX)
Assignee: Omnissa, LLC
G06F3/0481G06F21/10H04L63/105H04W12/37H04L67/01H04W12/08H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,099,689
App. No.
17/377,868
Granted
Sep 24, 2024
Kind
B2
Abstract

Disclosed are various examples for remotely restricting client devices. A client device can be placed into a restricted mode in which application switching capabilities of the client device are disabled. Additionally, the client device can transmit screen capture data to a management service, which can provide the ability for an administrator user to monitor data shown on a display associated with the client device. The client device can also be removed from the restricted mode in response to a command sent from the management service to the client device.

Claims (62)

1. A method performed by at least one computing device to manage or oversee the operation of client devices, the method comprising:

obtaining, from a client device, a request to register the client device with the at least one computing device as a managed device;

in response to obtaining the request to register the client device, generating, in a user interface (UI) of the at least one computing device, an entry associated with the client device, wherein the generated entry identifies the client device or a user associated with the client device;

obtaining, via a selection of the generated entry in the UI, a request to place the client device in a restricted mode;

in response to obtaining the request to place the client device in the restricted mode, generating at least one restrict command to place the client device in the restricted mode, wherein the at least one restrict command identifies at least one permitted application, and the at least one restrict command includes an instruction to restrict an operating system (OS) of the client device to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device; and

transmitting the at least one restrict command to the client device to cause the client device to be placed in the restricted mode, wherein in the restricted mode, the client device restricts the OS to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device.

2. The method of claim 1 , wherein the at least one restrict command further includes an instruction to disable a file explorer or shell from executing on the client device or to disable a task manager from executing on the client device.

3. The method of claim 1 , further comprising:

after transmitting the at least one restrict command to the client device, obtaining, from the client device, a screen capture of a display of the client device; and

updating the UI to include a representation of the obtained screen capture.

4. The method of claim 1 , further comprising:

obtaining, via another selection of the generated entry, a request to remove the client device from the restricted mode;

in response to obtaining the request to remove the client device from the restricted mode, generating at least one remove command to remove the client device from the restricted mode, wherein the at least one remove command includes an instruction to stop restricting the OS of the client device to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device; and

transmitting the at least one remove command to the client device to cause the client device to be removed from the restricted mode, wherein based on the removal from the restricted mode, the client device stops restricting the OS to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device.

5. The method of claim 1 , wherein the at least one permitted application comprises a web browser application that the OS allows to execute while the client device is in the restricted mode.

6. The method of claim 5 , wherein the at least one restrict command further identifies a network whitelist comprising at least one network address that the web browser application is allowed to access while the client device is in the restricted mode.

7. The method of claim 1 , further comprising:

transmitting the UI to an administrative device separate from the client device, wherein the request to place the client device in the restricted mode is obtained from the administrative device based on a selection of the generated entry of the UI made at the administrative device.

8. The method of claim 1 , further comprising:

obtaining, from the client device, data that indicates a status of settings of the client device;

determining, based on the obtained data, that the client device is not compliant with one or more compliance rules; and

in response to determining that the client device is not compliant, transmitting a message to the client device that either causes the settings of the client device to change or erases data from the client device.

9. A non-transitory computer-readable medium comprising instructions that are executable by a remote computing device, wherein the instructions when executed cause the remote computing device to carry out a method to manage or oversee the operation of client devices, and wherein the method comprises:

obtaining, from a client device, a request to register the client device with the remote computing device as a managed device;

in response to obtaining the request to register the client device, generating, in a user interface (UI) of the remote computing device, an entry associated with the client device, wherein the generated entry identifies the client device or a user associated with the client device;

obtaining, via a selection of the generated entry in the UI, a request to place the client device in a restricted mode;

in response to obtaining the request to place the client device in the restricted mode, generating at least one restrict command to place the client device in the restricted mode, wherein the at least one restrict command identifies at least one permitted application, and the at least one restrict command includes an instruction to restrict an operating system (OS) of the client device to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device; and

transmitting the at least one restrict command to the client device to cause the client device to be placed in the restricted mode, wherein in the restricted mode, the client device restricts the OS to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device.

10. The non-transitory computer-readable medium of claim 9 , wherein the at least one restrict command further includes an instruction to disable a file explorer or shell from executing on the client device or to disable a task manager from executing on the client device.

11. The non-transitory computer-readable medium of claim 9 , wherein the method further comprises:

after transmitting the at least one restrict command to the client device, obtaining, from the client device, a screen capture of a display of the client device; and

updating the UI to include a representation of the obtained screen capture.

12. The non-transitory computer-readable medium of claim 9 , wherein the method further comprises:

obtaining, via another selection of the generated entry, a request to remove the client device from the restricted mode;

in response to obtaining the request to remove the client device from the restricted mode, generating at least one remove command to remove the client device from the restricted mode, wherein the at least one remove command includes an instruction to stop restricting the OS of the client device to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device; and

transmitting the at least one remove command to the client device to cause the client device to be removed from the restricted mode, wherein based on the removal from the restricted mode, the client device stops restricting the OS to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device.

13. The non-transitory computer-readable medium of claim 9 , wherein the at least one permitted application comprises a web browser application that the OS allows to execute while the client device is in the restricted mode, and wherein the at least one restrict command further identifies a network whitelist comprising at least one network address that the web browser application is allowed to access while the client device is in the restricted mode.

14. The non-transitory computer-readable medium of claim 9 , wherein the method further comprises:

transmitting the UI to an administrative device separate from the client device, wherein the request to place the client device in the restricted mode is obtained from the administrative device based on a selection of the generated entry of the UI made at the administrative device.

15. The non-transitory computer-readable medium of claim 9 , wherein the method further comprises:

obtaining, from the client device, data that indicates a status of settings of the client device;

determining, based on the obtained data, that the client device is not compliant with one or more compliance rules; and

in response to determining that the client device is not compliant, transmitting a message to the client device that either causes the settings of the client device to change or erases data from the client device.

16. A computer system comprising at least one computing device including a processor configured to manage or oversee the operation of client devices, wherein the processor is further configured to:

obtain, from a client device, a request to register the client device with the at least one computing device as a managed device;

in response to obtaining the request to register the client device, generate, in a user interface (UI) of the at least one computing device, an entry associated with the client device, wherein the generated entry identifies the client device or a user associated with the client device;

obtain, via a selection of the generated entry in the UI, a request to place the client device in a restricted mode;

in response to obtaining the request to place the client device in the restricted mode, generate at least one restrict command to place the client device in the restricted mode, wherein the at least one restrict command identifies at least one permitted application, and the at least one restrict command includes an instruction to restrict an operating system (OS) of the client device to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device; and

transmit the at least one restrict command to the client device to cause the client device to be placed in the restricted mode, wherein in the restricted mode, the client device restricts the OS to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device.

17. The computer system of claim 16 , wherein the processor is further configured to:

after transmitting the at least one restrict command to the client device, obtain, from the client device, a screen capture of a display of the client device; and

update the UI to include a representation of the obtained screen capture.

18. The computer system of claim 16 , wherein the processor is further configured to:

obtain, via another selection of the generated entry, a request to remove the client device from the restricted mode;

in response to obtaining the request to remove the client device from the restricted mode, generate at least one remove command to remove the client device from the restricted mode, wherein the at least one remove command includes an instruction to stop restricting the OS of the client device to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device; and

transmit the at least one remove command to the client device to cause the client device to be removed from the restricted mode, wherein based on the removal from the restricted mode, the client device stops restricting the OS to allow only the at least one permitted application to execute in the foreground and to receive inputs made into the client device.

19. The computer system of claim 16 , wherein the processor is further configured to:

transmit the UI to an administrative device separate from the client device, wherein the request to place the client device in the restricted mode is obtained from the administrative device based on a selection of the generated entry of the UI made at the administrative device.

20. The computer system of claim 16 , wherein the processor is further configured to:

obtain, from the client device, data that indicates a status of settings of the client device;

determine, based on the obtained data, that the client device is not compliant with one or more compliance rules; and

in response to determining that the client device is not compliant, transmit a message to the client device that either causes the settings of the client device to change or erases data from the client device.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
Continuity (2)
Continuation 14687564 · Apr 15, 2015
Related Publication 20220107710A1 · Apr 7, 2022