IP Library Granted Patent US 11,687,644
Granted Patent B2
US 11,687,644 · App. 17/890,798 · Granted Jun 27, 2023

Secure visual and computational boundary for a subset of resources on a computing machine

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); David Matalon (Great Neck, NY); Alexander Chermyanin (Nizhni Novgorod, RU); Aleksandr Sedunov (Nizhni Novgorod, RU)
Assignee: Venn Technology Corporation
H04L63/205H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,687,644
App. No.
17/890,798
Granted
Jun 27, 2023
Kind
B2
Abstract

A computer stores, within a single user account, multiple supervised computing resources and multiple additional computing resources. The multiple supervised computing resources are associated with a security policy. The computer executes a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources. The computer executes, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources. The computer applies rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application.

Claims (44)

1. A method comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

causing, via a native computing environment of the computing machine, a display unit coupled with the computing machine to display simultaneously, all or a portion of a visual representation of a specified supervised computing resource and all or a portion of a visual representation of a specified additional computing resource, wherein the visual representation of the specified supervised computing resource comprises data generated during execution of software associated with the specified supervised computing resource, wherein the visual representation of the specified additional computing resource comprises data generated during execution of software associated with the specified additional computing resource;

applying security rules from the security policy to the specified supervised computing resource, wherein applying the security rules comprises at least facilitating tracking, by a supervision service, activity of the computing machine with respect to the specified supervised computing resource;

forgoing facilitating tracking, by the supervision service, activity of the computing machine with respect to the specified additional computing resource and with respect to activity on the computing machine that is not associated with one or more of the multiple supervised computing resources; and

displaying, in association with the visual representation of the specified supervised computing resource, a visual indicator indicating that tracking is ongoing, the visual indicator comprising a border for the visual representation of the specified supervised computing resource, the border occupying points outside the visual representation of the specified supervised computing resource that are within a distance of n or fewer pixels from the visual representation of the specified supervised computing resource unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified supervised computing resource in a computing resource stack, wherein n is a positive integer.

2. The method of claim 1 , wherein the additional computing resources comprise personal computing resources, wherein the supervised computing resources comprise business computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, cloud file storage access, applications or websites.

3. The method of claim 1 , further comprising:

foregoing applying security rules from the security policy to the specified additional computing resource.

4. The method of claim 1 , wherein applying the security rules comprises blocking, by communicating with a hardware driver of the computing machine, copying data from the specified supervised computing resource to the specified additional computing resource.

5. The method of claim 1 , wherein the visual indicator comprises a badge adjacent to a region of the display unit occupied by the visual representation of the specified supervised computing resource.

6. The method of claim 1 , wherein the activity of the computing machine with respect to the specified supervised computing resource and the activity of the computing machine with respect to the specified additional computing resource comprise network traffic.

7. The method of claim 1 , wherein the activity of the computing machine with respect to the specified supervised computing resource and the activity of the computing machine with respect to the specified additional computing resource comprise internet browsing.

8. The method of claim 1 , wherein the activity of the computing machine with respect to the specified supervised computing resource and the activity of the computing machine with respect to the specified additional computing resource comprise camera or microphone input activity.

9. The method of claim 1 , further comprising:

storing information transmitted from the computing machine to the supervision service; and

providing for display, in response to a user request, of a visual representation of the information transmitted from the computing machine to the supervision service.

10. The method of claim 1 , wherein the supervision service comprises at least one of: a cloud-based supervision service, one or more servers, or an administrator computing device associated with the security policy.

11. The method of claim 1 , wherein the security rules comprise one or more rules blocking a set of operations from the specified supervised computing resource to the specified additional computing resource, wherein the set of operations comprises at least one of: a drag and drop operation, a copy and paste operation, a cut and paste operation, a key log operation, a file download operation, a file upload operation, a file attachment operation, a printing operation, an opening a specific website operation, opening a category of website operation, an application launching operation or a screenshot operation.

12. The method of claim 1 , wherein applying the security rules comprises blocking, by communicating with a controller of the computing machine, copying data from the specified supervised computing resource to the specified additional computing resource.

13. The method of claim 1 , further comprising:

causing the display unit to terminate display of the visual representation of the specified additional computing resource in response to a user input; and

causing the display unit to continue display of the visual representation of the specified supervised computing resource and the visual indicator indicating that tracking is ongoing.

14. A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

causing, via a native computing environment of the computing machine, a display unit coupled with the computing machine to display simultaneously, all or a portion of a visual representation of a specified supervised computing resource and all or a portion of a visual representation of a specified additional computing resource, wherein the visual representation of the specified supervised computing resource comprises data generated during execution of software associated with the specified supervised computing resource, wherein the visual representation of the specified additional computing resource comprises data generated during execution of software associated with the specified additional computing resource;

applying security rules from the security policy to the specified supervised computing resource, wherein applying the security rules comprises at least facilitating tracking, by a supervision service, activity of the computing machine with respect to the specified supervised computing resource;

forgoing facilitating tracking, by the supervision service, activity of the computing machine with respect to the specified additional computing resource and with respect to activity on the computing machine that is not associated with one or more of the multiple supervised computing resources; and

displaying, in association with the visual representation of the specified supervised computing resource, a visual indicator indicating that tracking is ongoing, the visual indicator comprising a border for the visual representation of the specified supervised computing resource, the border occupying points outside the visual representation of the specified supervised computing resource that are within a distance of n or fewer pixels from the visual representation of the specified supervised computing resource unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified supervised computing resource in a computing resource stack, wherein n is a positive integer.

15. The machine-readable medium of claim 14 , wherein the additional computing resources comprise personal computing resources, wherein the supervised computing resources comprise business computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, cloud file storage access, applications or websites.

16. The machine-readable medium of claim 14 , the operations further comprising:

foregoing applying security rules from the security policy to the specified additional computing resource.

17. The machine-readable medium of claim 14 , wherein the visual indicator comprises a badge adjacent to a region of the display unit occupied by the visual representation of the specified supervised computing resource.

18. The machine-readable medium of claim 14 , wherein the activity of the computing machine with respect to the specified supervised computing resource and the activity of the computing machine with respect to the specified additional computing resource comprise network traffic.

19. The machine-readable medium of claim 14 , wherein the activity of the computing machine with respect to the specified supervised computing resource and the activity of the computing machine with respect to the specified additional computing resource comprise internet browsing.

20. The machine-readable medium of claim 14 , wherein the activity of the computing machine with respect to the specified supervised computing resource and the activity of the computing machine with respect to the specified additional computing resource comprise camera or microphone input activity.

21. A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

causing, via a native computing environment of the computing machine, a display unit coupled with the computing machine to display simultaneously, all or a portion of a visual representation of a specified supervised computing resource and all or a portion of a visual representation of a specified additional computing resource, wherein the visual representation of the specified supervised computing resource comprises data generated during execution of software associated with the specified supervised computing resource, wherein the visual representation of the specified additional computing resource comprises data generated during execution of software associated with the specified additional computing resource;

applying security rules from the security policy to the specified supervised computing resource, wherein applying the security rules comprises at least facilitating tracking, by a supervision service, activity of the computing machine with respect to the specified supervised computing resource;

forgoing facilitating tracking, by the supervision service, activity of the computing machine with respect to the specified additional computing resource and with respect to activity on the computing machine that is not associated with one or more of the multiple supervised computing resources; and

displaying, in association with the visual representation of the specified supervised computing resource, a visual indicator indicating that tracking is ongoing, the visual indicator comprising a border for the visual representation of the specified supervised computing resource, the border occupying points outside the visual representation of the specified supervised computing resource that are within a distance of n or fewer pixels from the visual representation of the specified supervised computing resource unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified supervised computing resource in a computing resource stack, wherein n is a positive integer.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; MATALON, DAVID; CHERMYANIN, ALEXANDER; SEDUNOV, ALEKSANDR
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 060846/0947 →
Continuity (2)
Provisional Application 63260408 · Aug 19, 2021
Related Publication 20230056056A1 · Feb 23, 2023
Cited By (9)
US 12,197,564 US 12,282,541 US 12,292,964 US 12,292,965 US 12,380,204 US 12,475,213 US 12,518,030 US 12,682,040 US 12,719,870