IP Library Granted Patent US 12,475,213
Granted Patent B2
US 12,475,213 · App. 17/891,357 · Granted Nov 18, 2025

Visual indicator of application of security policy

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); David Matalon (Great Neck, NY); Alexander Chermyanin (Antalya, TR); Aleksandr Sedunov (Antalya, TR)
Assignee: Venn Technology Corporation
G06F21/53G06F9/547G06F21/16G06F21/316G06F21/577H04L63/10H04L63/102H04L63/105H04L63/20H04L63/205G06F21/1063G06F2221/033G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,213
App. No.
17/891,357
Granted
Nov 18, 2025
Kind
B2
Abstract

A computer stores, within a single user account, multiple supervised computing resources and multiple additional computing resources. The multiple supervised computing resources are associated with a security policy. The computer executes a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources. The computer executes, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources. The computer applies rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application.

Claims (50)

1 . A method comprising:

receiving, via a user account at a computing machine, a request to access a specified computing resource residing on the computing machine, wherein the specified computing resource is a website, an application or a file;

providing access to the specified computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

determining that the specified computing resource is associated with a security policy, wherein the user account at the computing machine is associated with multiple computing resources residing on the computing machine, a first subset of the multiple computing resources being associated with the security policy and a second subset of the multiple computing resources not being associated with the security policy, wherein the specified computing resource is a member of the first subset of the multiple computing resources;

causing, in response to determining that the specified computing resource is associated with the security policy, a display unit to display, in association with a region of the display unit displaying a visual representation of the specified computing resource, a visual indication that the specified computing resource is associated with the security policy, the visual indication comprising a border for the region, the border occupying points outside the region that are within a distance of n or fewer pixels from the region unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified computing resource in a computing resource stack, wherein n is a positive integer; and

applying security rules from the security policy to the specified computing resource, wherein the security policy causes tracking, by a tracking service, of use of the first subset of the multiple computing resources, while forgoing causing tracking, by the tracking service, of use of the second subset of the multiple computing resources, wherein the tracking service comprises a cloud-based tracking service that executes externally to the computing machine.

2 . The method of claim 1 , wherein the computing machine is one of: a laptop computer, a desktop computer, a mobile phone or a tablet computer.

3 . The method of claim 1 , wherein the security policy is an organizational security policy, wherein the computing machine stores an organizational set of computing resources associated with the organizational security policy and a personal set of computing resources not associated with the organizational security policy.

4 . The method of claim 1 , wherein the security rules from the security policy comprise one or more of: blocking sharing of the specified computing resource, logging a reason for sharing of the specified computing resource, receiving a user confirmation before sharing of the specified computing resource, logging keystrokes while the specified computing resource is selected, and locking the specified computing resource in response to the computing machine being idle for at least a threshold time period.

5 . The method of claim 4 , wherein sharing comprises one or more of printing, screensharing, transmitting via email or a messaging service, dragging and dropping, cutting and pasting, downloading, uploading, attaching, accessing a specific website, accessing a category of websites, launching an application or taking a screenshot.

6 . The method of claim 1 , further comprising:

deactivating one or more security rules from the security policy with respect to the specified computing resource in response to a user request; and

logging a reason for the user request.

7 . The method of claim 1 , further comprising:

receiving, via a graphical user interface (GUI), an indication of a selection of the visual indication; and

providing for display, in response to the selection of the visual indication, information regarding permissions of a user of the computing machine with respect to the specified computing resource or information regarding the security policy.

8 . The method of claim 1 , further comprising:

causing the display unit to simultaneously display the specified computing resource associated with the security policy and an additional computing resource not associated with the security policy, both the specified computing resource and the additional computing resource executing through the native computing environment of the computing machine.

9 . The method of claim 1 , wherein the visual indication is displayed on or adjacent to a boundary of the region of the display unit displaying the specified computing resource.

10 . The method of claim 1 , wherein the second subset of the multiple computing resources accesses first common app platform application programming interfaces available to applications of the computing machine that use at least one of registry, remote procedure call, global objects, component object model, or universal application programming interfaces, wherein the first subset of the multiple computing resources accesses second common app platform application programming interfaces associated with the security policy that is different from the first common app platform application programming interfaces.

11 . The method of claim 10 , wherein the first common app platform application programming interfaces comprise a universal platform.

12 . The method of claim 10 , wherein the first common app platform application programming interfaces comprise at least one of a shell infrastructure host service, a repository service, a background task infrastructure service, a user management service, a directory authentication broker service, or a directory credentials manager service.

13 . A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

receiving, via a user account at a computing machine, a request to access a specified computing resource residing on the computing machine, wherein the specified computing resource is a website, an application or a file;

providing access to the specified computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

determining that the specified computing resource is associated with a security policy, wherein the user account at the computing machine is associated with multiple computing resources residing on the computing machine, a first subset of the multiple computing resources being associated with the security policy and a second subset of the multiple computing resources not being associated with the security policy, wherein the specified computing resource is a member of the first subset of the multiple computing resources;

causing, in response to determining that the specified computing resource is associated with the security policy, a display unit to display, in association with a region of the display unit displaying a visual representation of the specified computing resource, a visual indication that the specified computing resource is associated with the security policy, the visual indication comprising a border for the region, the border occupying points outside the region that are within a distance of n or fewer pixels from the region unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified computing resource in a computing resource stack, wherein n is a positive integer; and

applying security rules from the security policy to the specified computing resource, wherein the security policy causes tracking, by a tracking service, of use of the first subset of the multiple computing resources, while forgoing causing tracking, by the tracking service, of use of the second subset of the multiple computing resources, wherein the tracking service comprises a cloud-based tracking service that executes externally to the computing machine.

14 . The machine-readable medium of claim 13 , wherein the computing machine is one of: a laptop computer, a desktop computer, a mobile phone or a tablet computer.

15 . The machine-readable medium of claim 13 , wherein the security policy is an organizational security policy, wherein the computing machine stores an organizational set of computing resources associated with the organizational security policy and a personal set of computing resources not associated with the organizational security policy.

16 . The machine-readable medium of claim 13 , wherein the security rules from the security policy comprise one or more of: blocking sharing of the specified computing resource, logging a reason for sharing of the specified computing resource, receiving a user confirmation before sharing of the specified computing resource, logging keystrokes while the specified computing resource is selected, and locking the specified computing resource in response to the computing machine being idle for at least a threshold time period.

17 . The machine-readable medium of claim 16 , wherein sharing comprises one or more of printing, screensharing, transmitting via email or a messaging service, dragging and dropping, cutting and pasting, downloading, uploading, attaching, accessing a specific website, accessing a category of websites, launching an application or taking a screenshot.

18 . The machine-readable medium of claim 13 , the operations further comprising:

deactivating one or more security rules from the security policy with respect to the specified computing resource in response to a user request; and

logging a reason for the user request.

19 . The machine-readable medium of claim 13 , the operations further comprising:

receiving, via a graphical user interface (GUI), an indication of a selection of the visual indication; and

providing for display, in response to the selection of the visual indication, information regarding permissions of a user of the computing machine with respect to the specified computing resource or information regarding the security policy.

20 . The machine-readable medium of claim 13 , the operations further comprising:

causing the display unit to simultaneously display the specified computing resource associated with the security policy and an additional computing resource not associated with the security policy, both the specified computing resource and the additional computing resource executing through the native computing environment of the computing machine.

21 . The machine-readable medium of claim 13 , wherein the visual indication is displayed on or adjacent to a boundary of the region of the display unit displaying the specified computing resource.

22 . A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

receiving, via a user account at a computing machine, a request to access a specified computing resource residing on the computing machine, wherein the specified computing resource is a website, an application or a file;

providing access to the specified computing resource locally on the computing machine and directly through a native computing environment of the computing machine;

determining that the specified computing resource is associated with a security policy, wherein the user account at the computing machine is associated with multiple computing resources residing on the computing machine, a first subset of the multiple computing resources being associated with the security policy and a second subset of the multiple computing resources not being associated with the security policy, wherein the specified computing resource is a member of the first subset of the multiple computing resources;

causing, in response to determining that the specified computing resource is associated with the security policy, a display unit to display, in association with a region of the display unit displaying a visual representation of the specified computing resource, a visual indication that the specified computing resource is associated with the security policy, the visual indication comprising a border for the region, the border occupying points outside the region that are within a distance of n or fewer pixels from the region unless those pixels are occupied by visual representations of other computing resources that are more dominant than the specified computing resource in a computing resource stack, wherein n is a positive integer; and

applying security rules from the security policy to the specified computing resource, wherein the security policy causes tracking, by a tracking service, of use of the first subset of the multiple computing resources, while forgoing causing tracking, by the tracking service, of use of the second subset of the multiple computing resources, wherein the tracking service comprises a cloud-based tracking service that executes externally to the computing machine.

23 . The system of claim 22 , wherein the computing machine is one of: a laptop computer, a desktop computer, a mobile phone or a tablet computer.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; MATALON, DAVID; CHERMYANIN, ALEXANDER; SEDUNOV, ALEKSANDR
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 061233/0405 →
Continuity (2)
Provisional Application 63260408 · Aug 19, 2021
Related Publication 20230059726A1 · Feb 23, 2023
References Cited (111)
US 5870543A · Ronning · 1999 [cited by applicant]
US 5874958A · Ludolph · 1999 [cited by applicant]
US 6658571B1 · O'Brien et al. · 2003 [cited by applicant]
US 7162719B2 · Schmidt · 2007 [cited by applicant]
US 7779247B2 · Roegner · 2010 [cited by applicant]
US 7926086B1 · Violleau et al. · 2011 [cited by applicant]
US 7930273B1 · Clark et al. · 2011 [cited by applicant]
US 8255280B1 · Kay et al. · 2012 [cited by applicant]
US 8495731B1 · Mar et al. · 2013 [cited by applicant]
US 9021559B1 · Vetter et al. · 2015 [cited by applicant]
US 9307451B1 · Kodeswaran et al. · 2016 [cited by applicant]
US 9461978B2 · Mishra · 2016 [cited by examiner]
US 9519765B2 · Brown et al. · 2016 [cited by applicant]
US 9646152B2 · Lam et al. · 2017 [cited by applicant]
US 9785341B2 · Stallings et al. · 2017 [cited by applicant]
US 10044757B2 · Qureshi · 2018 [cited by examiner]
US 10152197B1 · Xue · 2018 [cited by examiner]
US 10254942B2 · Vranjes · 2019 [cited by examiner]
US 10630716B1 · Ghosh et al. · 2020 [cited by applicant]
US 10657246B2 · Biswas et al. · 2020 [cited by applicant]
US 11086984B2 · Shannon · 2021 [cited by applicant]
US 11687644B2 · Osipov et al. · 2023 [cited by applicant]
US 11704431B2 · Kraus et al. · 2023 [cited by applicant]
US 11750475B1 · Gonzalez et al. · 2023 [cited by applicant]
US 11902330B1 · Dods · 2024 [cited by applicant]
US 20020178119A1 · Griffin et al. · 2002 [cited by applicant]
US 20040162781A1 · Searl et al. · 2004 [cited by applicant]
US 20050182750A1 · Krishna et al. · 2005 [cited by applicant]
US 20060041405A1 · Chen et al. · 2006 [cited by applicant]
US 20060236363A1 · Heard et al. · 2006 [cited by applicant]
US 20070033273A1 · White et al. · 2007 [cited by applicant]
US 20070094673A1 · Hunt et al. · 2007 [cited by applicant]
US 20070186274A1 · Thrysoe et al. · 2007 [cited by applicant]
US 20070239987A1 · Hoole et al. · 2007 [cited by applicant]
US 20080134071A1 · Keohane · 2008 [cited by examiner]
US 20090177979A1 · Garbow et al. · 2009 [cited by applicant]
US 20090187648A1 · Sunkammurali et al. · 2009 [cited by applicant]
US 20090328215A1 · Arzi et al. · 2009 [cited by applicant]
US 20100122271A1 · Labour et al. · 2010 [cited by applicant]
US 20100319053A1 · Gharabally · 2010 [cited by applicant]
US 20110113467A1 · Agarwal et al. · 2011 [cited by applicant]
US 20120030729A1 · Schwartz et al. · 2012 [cited by applicant]
US 20120210333A1 · Potter · 2012 [cited by examiner]
US 20120233314A1 · Jakobsson · 2012 [cited by applicant]
US 20130031549A1 · Osmond · 2013 [cited by applicant]
US 20130160141A1 · Tseng et al. · 2013 [cited by applicant]
US 20130232238A1 · Cohn · 2013 [cited by examiner]
US 20130291055A1 · Muppidi et al. · 2013 [cited by applicant]
US 20130332996A1 · Fiala et al. · 2013 [cited by applicant]
US 20130339518A1 · Schimpfky et al. · 2013 [cited by applicant]
US 20140007184A1 · Porras · 2014 [cited by applicant]
US 20140095894A1 · Barton et al. · 2014 [cited by applicant]
US 20140380406A1 · Saidi · 2014 [cited by examiner]
US 20150134735A1 · Momchilov · 2015 [cited by examiner]
US 20160070626A1 · Raghavendra · 2016 [cited by applicant]
US 20160099972A1 · Qureshi · 2016 [cited by examiner]
US 20160255139A1 · Rathod · 2016 [cited by applicant]
US 20160315967A1 · Trevathan · 2016 [cited by examiner]
US 20170041344A1 · Nandakumar et al. · 2017 [cited by applicant]
US 20170250919A1 · Kessel et al. · 2017 [cited by applicant]
US 20180191766A1 · Holeman et al. · 2018 [cited by applicant]
US 20180267696A1 · Peshkar · 2018 [cited by applicant]
US 20180341499A1 · Tse · 2018 [cited by examiner]
US 20190199808A1 · Gamache et al. · 2019 [cited by applicant]
US 20200036739A1 · Novikov et al. · 2020 [cited by applicant]
US 20200059492A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20200192867A1 · McBeath · 2020 [cited by applicant]
US 20200204576A1 · Davis et al. · 2020 [cited by applicant]
US 20200233951A1 · Biswas et al. · 2020 [cited by applicant]
US 20200244637A1 · Main et al. · 2020 [cited by applicant]
US 20200320454A1 · Almashor · 2020 [cited by examiner]
US 20200356677A1 · Alexander et al. · 2020 [cited by applicant]
US 20210051155A1 · Sloane et al. · 2021 [cited by applicant]
US 20220179983A1 · Kassa et al. · 2022 [cited by applicant]
US 20220215094A1 · Gupta · 2022 [cited by applicant]
US 20220269782A1 · Chang et al. · 2022 [cited by applicant]
US 20220336078A1 · Wise et al. · 2022 [cited by applicant]
US 20220365861A1 · DeFilippo et al. · 2022 [cited by applicant]
US 20230054350A1 · Osipov et al. · 2023 [cited by applicant]
US 20230056056A1 · Osipov et al. · 2023 [cited by applicant]
US 20230058203A1 · Osipov et al. · 2023 [cited by applicant]
US 20230059726A1 · Osipov et al. · 2023 [cited by applicant]
US 20230101145A1 · Osipov et al. · 2023 [cited by applicant]
US 20230308474A1 · Thompson · 2023 [cited by applicant]
US 20230362651A1 · Lie · 2023 [cited by applicant]
US 20240007506A1 · Cage et al. · 2024 [cited by applicant]
US 20240184901A1 · Osipov et al. · 2024 [cited by applicant]
US 20240187414A1 · Osipov et al. · 2024 [cited by applicant]
CN 101513008B · 2012 [cited by applicant]
CN 103299658A · 2013 [cited by applicant]
CN 102365554B · 2015 [cited by applicant]
CN 106790231A · 2017 [cited by applicant]
CN 110727942A · 2020 [cited by applicant]
EP 2685750A1 · 2014 [cited by applicant]
EP 2541402B1 · 2019 [cited by applicant]
KR 1020170035294A · 2017 [cited by applicant]
WO 2014113882A1 · 2014 [cited by applicant]
WO 2017147525A1 · 2017 [cited by applicant]
Towards Resource-aware Business Process development in the Cloud, Hachicha et al, Apr. 2015 (Year: 2015). [cited by applicant]
Notice of Allowance dated Feb. 7, 2023 for U.S. Appl. No. 17/890,798. [cited by applicant]
International Search Report and Written Opinion for PCT Patent Application No. PCT/US2022/040928 dated Nov. 29, 2022, 7 pages. [cited by applicant]
Non-Final Office Action dated Nov. 2, 2022 for U.S. Appl. No. 17/890,798. [cited by applicant]
Non-Final Office Action dated Nov. 18, 2024 for U.S. Appl. No. 17/890,879, 38 pp. [cited by applicant]
Non-Final Office Action dated Nov. 14, 2024 for U.S. Appl. No. 17/890,853, 52 pp. [cited by applicant]
Non-Final Office Action dated Sep. 11, 2024 for U.S. Appl. No. 17/891,392. [cited by applicant]
Non-Final Office Action dated Nov. 7, 2024 for U.S. Appl. No. 18/438,775, 33 pp. [cited by applicant]
Non-Final Office Action dated Aug. 28, 2024 for U.S. Appl. No. 17/891,399, 32 pp. [cited by applicant]
Notice of Allowance dated Feb. 26, 2025 for U.S. Appl. No. 17/890,853. [cited by applicant]
Notice of Allowance dated Jun. 18, 2025 for U.S. Appl. No. 17/891,370, 34 pp. [cited by applicant]
Final Office Action dated Jan. 24, 2025 for U.S. Appl. No. 17/891,370, 56 pp. [cited by applicant]
Notice of Allowance dated Jan. 29, 2025 for U.S. Appl. No. 17/891,392. [cited by applicant]