IP Library Granted Patent US 12,682,040
Granted Patent B2
US 12,682,040 · App. 17/891,370 · Granted Jul 14, 2026

Applying a security policy to an instance of an application

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); David Matalon (Great Neck, NY); Alexander Chermyanin (Nizhni Novgorod, RU); Aleksandr Sedunov (Nizhni Novgorod, RU)
Assignee: Venn Technology Corporation
G06F21/53G06F9/547G06F21/16G06F21/316G06F21/577H04L63/10H04L63/102H04L63/105H04L63/20H04L63/205G06F21/1063G06F2221/033G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,682,040
App. No.
17/891,370
Filed
Aug 19, 2022
Granted
Jul 14, 2026
Kind
B2
Art Unit
2438
USPC
726/22
Abstract

A computer stores, within a single user account, multiple supervised computing resources and multiple additional computing resources. The multiple supervised computing resources are associated with a security policy. The computer executes a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources. The computer executes, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources. The computer applies rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application.

Claims (48)

1 . A method comprising:

storing, within a single user account at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

executing a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources;

executing, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources;

applying rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application; and

causing display, by a display unit displaying a graphical user interface of the computing machine, of a visual indicator that the second instance of the specified application is associated with the security policy, wherein the visual indicator comprises a border for a portion of the display unit associated with the second instance, wherein the border comprises pixels that are external to the portion of the display unit associated with the second instance and within a threshold distance from an edge of the portion, wherein multiple computing resources are displayed on the display unit, wherein each displayed computing resource is associated with a display priority value based on a time when the displayed computing resource was last selected, wherein the border comprises pixels that are not occupied by a computing resource that was selected after a last selection time of the second instance, wherein the security policy causes tracking, by a tracking service, of use of the second instance of the specified application, while forgoing causing tracking, by the tracking service, of use of the first instance of the specified application.

2 . The method of claim 1 , further comprising:

identifying a computing resource as a supervised computing resource based on one or more of: a location of the computing resource in a directory or file system, a cloud storage location, a rule in the security policy, a process name or path, a uniform resource locator (URL) address, and whether the computing resource is launched from an application launcher associated with the multiple supervised computing resources.

3 . The method of claim 1 , wherein the multiple additional computing resources comprise personal computing resources, wherein the multiple supervised computing resources comprise organizational computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, applications or websites.

4 . The method of claim 1 , wherein the first instance of the specified application accesses least a portion of the multiple additional computing resources.

5 . The method of claim 1 , wherein the second instance of the specified application has read access and lacks write access to at least a portion of the multiple additional computing resources, wherein, when the second instance access the at least the portion of the multiple additional computing resources, application of the security policy is based on a setting associated with the computing machine.

6 . The method of claim 1 , further comprising:

accessing, using a third instance of the specified application, an unsecure computing resource;

blocking access, by the third instance of the specified application, to any and all of the multiple supervised computing resources and any and all of the multiple additional computing resources.

7 . The method of claim 6 , further comprising:

identifying the unsecure computing resource based on the unsecure computing resource residing in a download memory region, a memory region associated with attachments for an email application, or a memory region associated with a web browser.

8 . The method of claim 7 , wherein the download memory region comprises a download folder, wherein the memory region associated with the web browser comprises the download folder, wherein the memory region associated with the attachments for the email application comprises an attachment folder.

9 . A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, within a single user account at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

executing a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources;

executing, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources;

applying rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application; and

causing display, by a display unit displaying a graphical user interface of the computing machine, of a visual indicator that the second instance of the specified application is associated with the security policy, wherein the visual indicator comprises a border for a portion of the display unit associated with the second instance, wherein the border comprises pixels that are external to the portion of the display unit associated with the second instance and within a threshold distance from an edge of the portion, wherein multiple computing resources are displayed on the display unit, wherein each displayed computing resource is associated with a display priority value based on a time when the displayed computing resource was last selected, wherein the border comprises pixels that are not occupied by a computing resource that was selected after a last selection time of the second instance, wherein the security policy causes tracking, by a tracking service, of use of the second instance of the specified application, while forgoing causing tracking, by the tracking service, of use of the first instance of the specified application.

10 . The machine-readable medium of claim 9 , the operations further comprising:

identifying a computing resource as a supervised computing resource based on one or more of: a location of the computing resource in a directory or file system, a cloud storage location, a rule in the security policy, a process name or path, a uniform resource locator (URL) address, and whether the computing resource is launched from an application launcher associated with the multiple supervised computing resources.

11 . The machine-readable medium of claim 9 , wherein the multiple additional computing resources comprise personal computing resources, wherein the multiple supervised computing resources comprise organizational computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, applications or websites.

12 . The machine-readable medium of claim 9 , wherein the first instance of the specified application accesses least a portion of the multiple additional computing resources.

13 . The machine-readable medium of claim 9 , wherein the second instance of the specified application has read access and lacks write access to at least a portion of the multiple additional computing resources, wherein, when the second instance access the at least the portion of the multiple additional computing resources, application of the security policy is based on a setting associated with the computing machine.

14 . The machine-readable medium of claim 9 , the operations further comprising:

accessing, using a third instance of the specified application, an unsecure computing resource;

blocking access, by the third instance of the specified application, to any and all of the multiple supervised computing resources and any and all of the multiple additional computing resources.

15 . The machine-readable medium of claim 14 , the operations further comprising:

identifying the unsecure computing resource based on the unsecure computing resource residing in a download memory region, a memory region associated with attachments for an email application, or a memory region associated with a web browser.

16 . The machine-readable medium of claim 15 , wherein the download memory region comprises a download folder, wherein the memory region associated with the web browser comprises the download folder, wherein the memory region associated with the attachments for the email application comprises an attachment folder.

17 . A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, within a single user account at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

executing a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources;

executing, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources;

applying rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application; and

causing display, by a display unit displaying a graphical user interface of the computing machine, of a visual indicator that the second instance of the specified application is associated with the security policy, wherein the visual indicator comprises a border for a portion of the display unit associated with the second instance, wherein the border comprises pixels that are external to the portion of the display unit associated with the second instance and within a threshold distance from an edge of the portion, wherein multiple computing resources are displayed on the display unit, wherein each displayed computing resource is associated with a display priority value based on a time when the displayed computing resource was last selected, wherein the border comprises pixels that are not occupied by a computing resource that was selected after a last selection time of the second instance, wherein the security policy causes tracking, by a tracking service, of use of the second instance of the specified application, while forgoing causing tracking, by the tracking service, of use of the first instance of the specified application.

18 . The system of claim 17 , the operations further comprising:

identifying a computing resource as a supervised computing resource based on one or more of: a location of the computing resource in a directory or file system, a cloud storage location, a rule in the security policy, a process name or path, a uniform resource locator (URL) address, and whether the computing resource is launched from an application launcher associated with the multiple supervised computing resources.

19 . The system of claim 17 , wherein the multiple additional computing resources comprise personal computing resources, wherein the multiple supervised computing resources comprise organizational computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, applications or websites.

20 . The system of claim 17 , wherein the first instance of the specified application accesses least a portion of the multiple additional computing resources.

21 . The method of claim 1 , wherein the first instance accesses first common app platform application programming interfaces available to applications of the computing machine that use at least one of registry, remote procedure call, global objects, component object model, or universal application programming interfaces, wherein the second instance accesses second common app platform application programming interfaces of the multiple supervised computing resources that is different from the first common app platform application programming interfaces, wherein the first common app platform application programming interfaces comprise a universal windows platform.

22 . The method of claim 1 , wherein the first instance accesses first common app platform application programming interfaces available to applications of the computing machine that use at least one of registry, remote procedure call, global objects, component object model, or universal application programming interfaces, wherein the second instance accesses second common app platform application programming interfaces of the multiple supervised computing resources that is different from the first common app platform application programming interfaces, wherein the first common app platform application programming interfaces comprise at least one of shell infrastructure host, state repository service, background task infrastructure, user manager service, azure active directory broker, azure active directory credentials manager, host activity manager, application activation manager, or view manager.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; MATALON, DAVID; CHERMYANIN, ALEXANDER; SEDUNOV, ALEKSANDR
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 061233/0037 →
Continuity (2)
Provisional Application 63260408 · Aug 19, 2021
Related Publication 20230058203A1 · Feb 23, 2023
References Cited (120)
US 5870543A · Ronning · 1999 [cited by applicant]
US 5874958A · Ludolph · 1999 [cited by applicant]
US 6658571B1 · O'Brien · 2003 [cited by examiner]
US 7162719B2 · Schmidt · 2007 [cited by applicant]
US 7779247B2 · Roegner · 2010 [cited by examiner]
US 7926086B1 · Violleau · 2011 [cited by examiner]
US 7930273B1 · Clark · 2011 [cited by examiner]
US 8255280B1 · Kay et al. · 2012 [cited by applicant]
US 8495731B1 · Mar et al. · 2013 [cited by applicant]
US 9021559B1 · Vetter et al. · 2015 [cited by applicant]
US 9307451B1 · Kodeswaran et al. · 2016 [cited by applicant]
US 9461978B2 · Mishra · 2016 [cited by examiner]
US 9519765B2 · Brown et al. · 2016 [cited by applicant]
US 9646152B2 · Lam · 2017 [cited by examiner]
US 9785341B2 · Stallings · 2017 [cited by examiner]
US 10044757B2 · Qureshi et al. · 2018 [cited by applicant]
US 10152197B1 · Xue · 2018 [cited by applicant]
US 10254942B2 · Vranjes · 2019 [cited by examiner]
US 10630716B1 · Ghosh et al. · 2020 [cited by applicant]
US 10657246B2 · Biswas · 2020 [cited by examiner]
US 10728230B2 · Lawson et al. · 2020 [cited by applicant]
US 11086984B2 · Shannon · 2021 [cited by examiner]
US 11687644B2 · Osipov et al. · 2023 [cited by applicant]
US 11704431B2 · Kraus · 2023 [cited by examiner]
US 11750475B1 · Gonzalez et al. · 2023 [cited by applicant]
US 11902330B1 · Dods · 2024 [cited by applicant]
US 20020178119A1 · Griffin · 2002 [cited by examiner]
US 20040162781A1 · Searl et al. · 2004 [cited by applicant]
US 20050182750A1 · Krishna et al. · 2005 [cited by applicant]
US 20060041405A1 · Chen et al. · 2006 [cited by applicant]
US 20060236363A1 · Heard · 2006 [cited by examiner]
US 20070033273A1 · White · 2007 [cited by examiner]
US 20070094673A1 · Hunt · 2007 [cited by examiner]
US 20070186274A1 · Thrysoe et al. · 2007 [cited by applicant]
US 20070239987A1 · Hoole · 2007 [cited by examiner]
US 20080134071A1 · Keohane · 2008 [cited by examiner]
US 20090177979A1 · Garbow · 2009 [cited by examiner]
US 20090187648A1 · Sunkammurali et al. · 2009 [cited by applicant]
US 20090328215A1 · Arzi et al. · 2009 [cited by applicant]
US 20100122271A1 · Labour · 2010 [cited by examiner]
US 20100319053A1 · Gharabally · 2010 [cited by examiner]
US 20110113467A1 · Agarwal · 2011 [cited by examiner]
US 20120030729A1 · Schwartz et al. · 2012 [cited by applicant]
US 20120210333A1 · Potter · 2012 [cited by examiner]
US 20120233314A1 · Jakobsson · 2012 [cited by applicant]
US 20130031549A1 · Osmond · 2013 [cited by applicant]
US 20130160141A1 · Tseng et al. · 2013 [cited by applicant]
US 20130232238A1 · Cohn et al. · 2013 [cited by applicant]
US 20130291055A1 · Muppidi et al. · 2013 [cited by applicant]
US 20130332996A1 · Fiala et al. · 2013 [cited by applicant]
US 20130339518A1 · Schimpfky et al. · 2013 [cited by applicant]
US 20140007184A1 · Porras · 2014 [cited by examiner]
US 20140095894A1 · Barton · 2014 [cited by examiner]
US 20140380406A1 · Saidi et al. · 2014 [cited by applicant]
US 20140380414A1 · Saidi et al. · 2014 [cited by applicant]
US 20150134735A1 · Momchilov · 2015 [cited by examiner]
US 20160070626A1 · Raghavendra · 2016 [cited by applicant]
US 20160099972A1 · Qureshi · 2016 [cited by examiner]
US 20160255139A1 · Rathod · 2016 [cited by examiner]
US 20160315967A1 · Trevathan et al. · 2016 [cited by applicant]
US 20170041344A1 · Nandakumar · 2017 [cited by examiner]
US 20170250919A1 · Kessel et al. · 2017 [cited by applicant]
US 20180176661A1 · Varndell et al. · 2018 [cited by applicant]
US 20180191766A1 · Holeman et al. · 2018 [cited by applicant]
US 20180267696A1 · Peshkar · 2018 [cited by examiner]
US 20180341499A1 · Tse · 2018 [cited by examiner]
US 20190199808A1 · Gamache et al. · 2019 [cited by applicant]
US 20200036739A1 · Novikov et al. · 2020 [cited by applicant]
US 20200059492A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20200192867A1 · McBeath · 2020 [cited by applicant]
US 20200200892A1 · Rajab et al. · 2020 [cited by applicant]
US 20200204576A1 · Davis et al. · 2020 [cited by applicant]
US 20200233951A1 · Biswas · 2020 [cited by examiner]
US 20200244637A1 · Main · 2020 [cited by examiner]
US 20200320454A1 · Almashor et al. · 2020 [cited by applicant]
US 20200356677A1 · Alexander et al. · 2020 [cited by applicant]
US 20210051155A1 · Sloane · 2021 [cited by examiner]
US 20220012351A1 · Sanders et al. · 2022 [cited by applicant]
US 20220179983A1 · Kassa et al. · 2022 [cited by applicant]
US 20220215094A1 · Gupta · 2022 [cited by applicant]
US 20220269782A1 · Chang · 2022 [cited by examiner]
US 20220336078A1 · Wise · 2022 [cited by examiner]
US 20220365861A1 · DeFilippo et al. · 2022 [cited by applicant]
US 20230053983A1 · Osipov et al. · 2023 [cited by applicant]
US 20230054350A1 · Osipov et al. · 2023 [cited by applicant]
US 20230056056A1 · Osipov et al. · 2023 [cited by applicant]
US 20230058203A1 · Osipov · 2023 [cited by examiner]
US 20230059726A1 · Osipov · 2023 [cited by examiner]
US 20230101145A1 · Osipov · 2023 [cited by examiner]
US 20230308474A1 · Thompson · 2023 [cited by applicant]
US 20230362651A1 · Lie · 2023 [cited by applicant]
US 20240007506A1 · Cage et al. · 2024 [cited by applicant]
US 20240184901A1 · Osipov · 2024 [cited by examiner]
US 20240187414A1 · Osipov · 2024 [cited by examiner]
CN 101513008B · 2012 [cited by applicant]
CN 103299658A · 2013 [cited by applicant]
CN 102365554B · 2015 [cited by applicant]
CN 106790231A · 2017 [cited by applicant]
CN 110727942A · 2020 [cited by applicant]
EP 2685750A1 · 2014 [cited by applicant]
EP 2541402B1 · 2019 [cited by applicant]
KR 1020170035294A · 2017 [cited by applicant]
WO 2014113882A1 · 2014 [cited by applicant]
WO 2016144375A1 · 2016 [cited by applicant]
WO 2017147525A1 · 2017 [cited by applicant]
Non-Final Office Action dated Nov. 2, 2022 for U.S. Appl. No. 17/890,798. [cited by applicant]
International Search Report and Written Opinion for PCT Patent Application No. PCT/US2022/040928 dated Nov. 29, 2022, 7 pages. [cited by applicant]
Towards Resource-aware Business Process development in the Cloud, Hachicha et al., Apr. 2015 (Year: 2015). [cited by applicant]
Notice of Allowance dated Feb. 7, 2023 for U.S. Appl. No. 17/890,798. [cited by applicant]
Non-Final Office Action dated Sep. 11, 2024 for U.S. Appl. No. 17/891,392. [cited by applicant]
Non-Final Office Action dated Aug. 28, 2024 for U.S. Appl. No. 17/891,399, 32 pp. [cited by applicant]
Non-Final Office Action dated Nov. 18, 2024 for U.S. Appl. No. 17/890,879, 38 pp. [cited by applicant]
Non-Final Office Action dated Nov. 14, 2024 for U.S. Appl. No. 17/890,853, 52 pp. [cited by applicant]
Non-Final Office Action dated Nov. 7, 2024 for U.S. Appl. No. 18/438,775, 33 pp. [cited by applicant]
Final Office Action dated Feb. 12, 2025 for U.S. Appl. No. 17/891,357, 54 pp. [cited by applicant]
Notice of Allowance dated Feb. 26, 2025 for U.S. Appl. No. 17/890,853. [cited by applicant]
Notice of Allowance dated Jan. 29, 2025 for U.S. Appl. No. 17/891,392. [cited by applicant]
Extended European Search Report for European Patent Application No. EP22859234 dated Apr. 11, 2025, 10 pages. [cited by applicant]
1 Non-Final Office Action dated Jun. 23, 2025 for U.S. Appl. No. 17/891,357, 24 pp. [cited by applicant]
Notice of Allowance dated Nov. 18, 2025 for U.S. Appl. No. 18/441,519, 73 pp. [cited by applicant]