IP Library Granted Patent US 12,380,204
Granted Patent B2
US 12,380,204 · App. 17/890,879 · Granted Aug 5, 2025

Indicator of security policy application for a portion of resources on a machine

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); David Matalon (Great Neck, NY); Alexander Chermyanin (Antalya, TR); Aleksandr Sedunov (Antalya, TR)
Assignee: Venn Technology Corporation
G06F21/53G06F9/547G06F21/16G06F21/316G06F21/577H04L63/10H04L63/102H04L63/105H04L63/20H04L63/205G06F21/1063G06F2221/033G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,380,204
App. No.
17/890,879
Filed
Aug 18, 2022
Granted
Aug 5, 2025
Kind
B2
Art Unit
2407
USPC
726/1
Abstract

A computer stores, within a single user account, multiple supervised computing resources and multiple additional computing resources. The multiple supervised computing resources are associated with a security policy. The computer executes a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources. The computer executes, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources. The computer applies rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application.

Claims (52)

1. A method comprising:

storing, within a single user account at a computing machine, multiple unsupervised computing resources and multiple supervised computing resources, wherein the multiple supervised computing resources are associated with a security policy;

receiving, from a user of the computing machine, a request to access a specified supervised computing resource from among the multiple supervised computing resources;

providing access to the specified supervised computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

causing a display unit to display, at a display position related to a region of the display unit displaying the specified supervised computing resource, an indicator that the specified supervised computing resource is associated with the security policy, the indicator comprising a border for the region, the border occupying points outside the region that are within a distance of n or fewer pixels from the region unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified supervised computing resource in a computing resource stack, wherein n is a positive integer; and

applying security rules from the security policy to the specified supervised computing resource.

2. The method of claim 1 , further comprising:

receiving, from the user of the computing machine, a request to access a specified unsupervised computing resource from among the multiple unsupervised computing resources;

providing access to the specified unsupervised computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

forgoing causing the display unit to display the indicator that the specified unsupervised computing resource is associated with the security policy; and

foregoing applying security rules from the security policy to the specified unsupervised computing resource.

3. The method of claim 1 , wherein the multiple unsupervised computing resources are not associated with the security policy.

4. The method of claim 1 , wherein an administrator computing device, external to the computing machine, has access to the multiple supervised computing resources residing at the computing machine and lacks access to the multiple unsupervised computing resources residing at the computing machine.

5. The method of claim 1 , wherein the security policy comprises the security rules restricting activity of the user of the computing machine with respect to the multiple supervised computing resources.

6. The method of claim 1 , wherein the security policy comprises a monitoring policy allowing a remote computing device to monitor activity of the user of the computing machine with respect to the multiple supervised computing resources.

7. The method of claim 1 , wherein the multiple unsupervised computing resources and the multiple supervised computing resources reside in separate and distinct directories of a filesystem of the computing machine or of a cloud storage unit.

8. The method of claim 1 , wherein the multiple unsupervised computing resources access first common app platform application programming interfaces available to applications of the computing machine that use at least one of registry, remote procedure call, global objects, component object model, or universal application programming interfaces, wherein the multiple supervised computing resources access second common app platform application programming interfaces associated with the security policy that is different from the first common app platform application programming interfaces.

9. The method of claim 8 , wherein the first common app platform application programming interfaces comprise a universal windows platform.

10. The method of claim 8 , wherein the first common app platform application programming interfaces comprise at least one of shell infrastructure host, state repository service, background task infrastructure, user manager service, azure active directory broker, azure active directory credentials manager, host activity manager, application activation manager, or view manager.

11. A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, within a single user account at a computing machine, multiple unsupervised computing resources and multiple supervised computing resources, wherein the multiple supervised computing resources are associated with a security policy;

receiving, from a user of the computing machine, a request to access a specified supervised computing resource from among the multiple supervised computing resources;

providing access to the specified supervised computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

causing a display unit to display, at a display position related to a region of the display unit displaying the specified supervised computing resource, an indicator that the specified supervised computing resource is associated with the security policy, the indicator comprising a border for the region, the border occupying points outside the region that are within a distance of n or fewer pixels from the region unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified supervised computing resource in a computing resource stack, wherein n is a positive integer; and

applying security rules from the security policy to the specified supervised computing resource.

12. The machine-readable medium of claim 11 , the operations further comprising:

receiving, from the user of the computing machine, a request to access a specified unsupervised computing resource from among the multiple unsupervised computing resources;

providing access to the specified unsupervised computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

forgoing causing the display unit to display the indicator that the specified unsupervised computing resource is associated with the security policy; and

foregoing applying security rules from the security policy to the specified unsupervised computing resource.

13. The machine-readable medium of claim 11 , wherein the multiple unsupervised computing resources are not associated with the security policy.

14. The machine-readable medium of claim 11 , wherein an administrator computing device, external to the computing machine, has access to the multiple supervised computing resources residing at the computing machine and lacks access to the multiple unsupervised computing resources residing at the computing machine.

15. The machine-readable medium of claim 11 , wherein the security policy comprises the security rules restricting activity of the user of the computing machine with respect to the multiple supervised computing resources.

16. The machine-readable medium of claim 11 , wherein the security policy comprises a monitoring policy allowing a remote computing device to monitor activity of the user of the computing machine with respect to the multiple supervised computing resources.

17. The machine-readable medium of claim 11 , wherein the multiple unsupervised computing resources and the multiple supervised computing resources reside in separate and distinct directories of a filesystem of the computing machine or of a cloud storage unit.

18. A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, within a single user account at a computing machine, multiple unsupervised computing resources and multiple supervised computing resources, wherein the multiple supervised computing resources are associated with a security policy;

receiving, from a user of the computing machine, a request to access a specified supervised computing resource from among the multiple supervised computing resources;

providing access to the specified supervised computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

causing a display unit to display, at a display position related to a region of the display unit displaying the specified supervised computing resource, an indicator that the specified supervised computing resource is associated with the security policy, the indicator comprising a border for the region, the border occupying points outside the region that are within a distance of n or fewer pixels from the region unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified supervised computing resource in a computing resource stack, wherein n is a positive integer; and

applying security rules from the security policy to the specified supervised computing resource.

19. The system of claim 18 , the operations further comprising:

receiving, from the user of the computing machine, a request to access a specified unsupervised computing resource from among the multiple unsupervised computing resources;

providing access to the specified unsupervised computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

forgoing causing the display unit to display the indicator that the specified unsupervised computing resource is associated with the security policy; and

foregoing applying security rules from the security policy to the specified unsupervised computing resource.

20. The system of claim 18 , wherein the multiple unsupervised computing resources are not associated with the security policy.

21. The system of claim 18 , wherein an administrator computing device, external to the computing machine, has access to the multiple supervised computing resources residing at the computing machine and lacks access to the multiple unsupervised computing resources residing at the computing machine.

22. The system of claim 18 , wherein the security policy comprises the security rules restricting activity of the user of the computing machine with respect to the multiple supervised computing resources.

23. The system of claim 18 , wherein the security policy comprises a monitoring policy allowing a remote computing device to monitor activity of the user of the computing machine with respect to the multiple supervised computing resources.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; MATALON, DAVID; CHERMYANIN, ALEXANDER; SEDUNOV, ALEKSANDR
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 060847/0829 →
Continuity (2)
Provisional Application 63260408 · Aug 19, 2021
Related Publication 20230054350A1 · Feb 23, 2023
References Cited (102)
US 5870543A · Ronning · 1999 [cited by applicant]
US 5874958A · Ludolph · 1999 [cited by applicant]
US 6658571B1 · O'Brien et al. · 2003 [cited by applicant]
US 7162719B2 · Schmidt · 2007 [cited by applicant]
US 7779247B2 · Roegner · 2010 [cited by applicant]
US 7926086B1 · Violleau et al. · 2011 [cited by applicant]
US 8255280B1 · Kay et al. · 2012 [cited by applicant]
US 8495731B1 · Mar et al. · 2013 [cited by applicant]
US 9021559B1 · Vetter et al. · 2015 [cited by applicant]
US 9307451B1 · Kodeswaran et al. · 2016 [cited by applicant]
US 9461978B2 · Mishra et al. · 2016 [cited by applicant]
US 9519765B2 · Brown et al. · 2016 [cited by applicant]
US 9646152B2 · Lam et al. · 2017 [cited by applicant]
US 9785341B2 · Stallings et al. · 2017 [cited by applicant]
US 10152197B1 · Xue · 2018 [cited by examiner]
US 10254942B2 · Vranjes et al. · 2019 [cited by applicant]
US 10630716B1 · Ghosh et al. · 2020 [cited by applicant]
US 10657246B2 · Biswas et al. · 2020 [cited by applicant]
US 11086984B2 · Shannon · 2021 [cited by applicant]
US 11687644B2 · Osipov et al. · 2023 [cited by applicant]
US 11704431B2 · Kraus et al. · 2023 [cited by applicant]
US 11750475B1 · Gonzalez et al. · 2023 [cited by applicant]
US 11902330B1 · Dods · 2024 [cited by applicant]
US 20020178119A1 · Griffin et al. · 2002 [cited by applicant]
US 20040162781A1 · Searl et al. · 2004 [cited by applicant]
US 20050182750A1 · Krishna et al. · 2005 [cited by applicant]
US 20060041405A1 · Chen et al. · 2006 [cited by applicant]
US 20060236363A1 · Heard et al. · 2006 [cited by applicant]
US 20070033273A1 · White et al. · 2007 [cited by applicant]
US 20070094673A1 · Hunt et al. · 2007 [cited by applicant]
US 20070186274A1 · Thrysoe et al. · 2007 [cited by applicant]
US 20070239987A1 · Hoole et al. · 2007 [cited by applicant]
US 20080134071A1 · Keohane et al. · 2008 [cited by applicant]
US 20090177979A1 · Garbow et al. · 2009 [cited by applicant]
US 20090187648A1 · Sunkammurali et al. · 2009 [cited by applicant]
US 20090328215A1 · Arzi et al. · 2009 [cited by applicant]
US 20100319053A1 · Gharabally · 2010 [cited by applicant]
US 20110113467A1 · Agarwal et al. · 2011 [cited by applicant]
US 20120030729A1 · Schwartz et al. · 2012 [cited by applicant]
US 20120210333A1 · Potter et al. · 2012 [cited by applicant]
US 20120233314A1 · Jakobsson · 2012 [cited by applicant]
US 20130031549A1 · Osmond · 2013 [cited by applicant]
US 20130160141A1 · Tseng et al. · 2013 [cited by applicant]
US 20130232238A1 · Cohn et al. · 2013 [cited by applicant]
US 20130291055A1 · Muppidi et al. · 2013 [cited by applicant]
US 20130332996A1 · Fiala et al. · 2013 [cited by applicant]
US 20130339518A1 · Schimpfky et al. · 2013 [cited by applicant]
US 20140007184A1 · Porras · 2014 [cited by applicant]
US 20140095894A1 · Barton et al. · 2014 [cited by applicant]
US 20140380406A1 · Saidi et al. · 2014 [cited by applicant]
US 20150134735A1 · Momchilov et al. · 2015 [cited by applicant]
US 20160070626A1 · Raghavendra · 2016 [cited by applicant]
US 20160099972A1 · Qureshi et al. · 2016 [cited by applicant]
US 20160255139A1 · Rathod · 2016 [cited by applicant]
US 20160315967A1 · Trevathan · 2016 [cited by examiner]
US 20170041344A1 · Nandakumar et al. · 2017 [cited by applicant]
US 20170250919A1 · Kessel et al. · 2017 [cited by applicant]
US 20180191766A1 · Holeman et al. · 2018 [cited by applicant]
US 20190199808A1 · Gamache et al. · 2019 [cited by applicant]
US 20200036739A1 · Novikov et al. · 2020 [cited by applicant]
US 20200059492A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20200192867A1 · McBeath · 2020 [cited by applicant]
US 20200204576A1 · Davis et al. · 2020 [cited by applicant]
US 20200233951A1 · Biswas et al. · 2020 [cited by applicant]
US 20200244637A1 · Main et al. · 2020 [cited by applicant]
US 20200320454A1 · Almashor et al. · 2020 [cited by applicant]
US 20200356677A1 · Alexander et al. · 2020 [cited by applicant]
US 20210051155A1 · Sloane et al. · 2021 [cited by applicant]
US 20220179983A1 · Kassa et al. · 2022 [cited by applicant]
US 20220215094A1 · Gupta · 2022 [cited by applicant]
US 20220336078A1 · Wise et al. · 2022 [cited by applicant]
US 20220365861A1 · DeFilippo et al. · 2022 [cited by applicant]
US 20230054350A1 · Osipov et al. · 2023 [cited by applicant]
US 20230056056A1 · Osipov et al. · 2023 [cited by applicant]
US 20230308474A1 · Thompson · 2023 [cited by applicant]
US 20230362651A1 · Lie · 2023 [cited by applicant]
US 20240007506A1 · Cage et al. · 2024 [cited by applicant]
US 20240184901A1 · Osipov et al. · 2024 [cited by applicant]
US 20240187414A1 · Osipov et al. · 2024 [cited by applicant]
CN 101513008B · 2012 [cited by applicant]
CN 103299658A · 2013 [cited by applicant]
CN 102365554B · 2015 [cited by applicant]
CN 106790231A · 2017 [cited by applicant]
CN 110727942A · 2020 [cited by applicant]
EP 2685750A1 · 2014 [cited by applicant]
EP 2541402B1 · 2019 [cited by applicant]
KR 1020170035294A · 2017 [cited by applicant]
WO 2014113882A1 · 2014 [cited by applicant]
WO 2017147525A1 · 2017 [cited by applicant]
Non-Final Office Action dated Nov. 2, 2022 for U.S. Appl. No. 17/890,798. [cited by applicant]
Towards Resource-aware Business Process development in the Cloud, Hachicha et al, Apr. 2015 (Year: 2015). [cited by applicant]
Notice of Allowance dated Feb. 7, 2023 for U.S. Appl. No. 17/890,798. [cited by applicant]
International Search Report and Written Opinion for PCT Patent Application No. PCT/US2022/040928 dated Nov. 29, 2022, 7 pages. [cited by applicant]
Non-Final Office Action dated Aug. 28, 2024 for U.S. Appl. No. 17/891,399, 32 pp. [cited by applicant]
Non-Final Office Action dated Sep. 11, 2024 for U.S. Appl. No. 17/891,392. [cited by applicant]
Non-Final Office Action dated Nov. 14, 2024 for U.S. Appl. No. 17/890,853, 52 pp. [cited by applicant]
Final Office Action dated Feb. 12, 2025 for U.S. Appl. No. 17/891,357, 54 pp. [cited by applicant]
Notice of Allowance dated Feb. 26, 2025 for U.S. Appl. No. 17/890,853. [cited by applicant]
Extended European Search Report for European Patent Application No. EP22859234 dated Apr. 11, 2025, 10 pages. [cited by applicant]
Final Office Action dated Jan. 24, 2025 for U.S. Appl. No. 17/891,370, 56 pp. [cited by applicant]
Notice of Allowance dated Jan. 29, 2025 for U.S. Appl. No. 17/891,392. [cited by applicant]
Non-Final Office Action dated Nov. 7, 2024 for U.S. Appl. No. 18/438,775, 33 pp. [cited by applicant]