IP Library Granted Patent US 12,197,564
Granted Patent B2
US 12,197,564 · App. 17/891,382 · Granted Jan 14, 2025

Application access permissions in supervised zone

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); David Matalon (Great Neck, NY); Alexander Chermyanin (Antalya, TR); Aleksandr Sedunov (Antalya, TR)
Assignee: Venn Technology Corporation
G06F21/53G06F9/547G06F21/16G06F21/316G06F21/577H04L63/10H04L63/102H04L63/105H04L63/20H04L63/205G06F21/1063G06F2221/033G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,197,564
App. No.
17/891,382
Granted
Jan 14, 2025
Kind
B2
Abstract

A computer stores, within a single user account, multiple supervised computing resources and multiple additional computing resources. The multiple supervised computing resources are associated with a security policy. The computer executes a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources. The computer executes, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources. The computer applies rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application.

Claims (72)

1. A method comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy, wherein the multiple supervised computing resources reside within a supervised zone, the supervised zone comprising a portion of data associated with a native computing environment of the computing machine;

executing a first instance of a specified application externally to the supervised zone, wherein the first instance has read access and has write access to data outside the supervised zone, wherein the first instance lacks read access and lacks write access to data stored within the supervised zone; and

executing, simultaneously with the first instance, a second instance of the specified application within the supervised zone, wherein the second instance has read access and lacks write access to data outside the supervised zone, wherein the second instance has read access and has write access to data stored within the supervised zone, wherein the second instance runs separately and distinctly from the first instance, wherein:

the second instance of the specified application accesses a network via a supervised network interface, the security policy specifying networks or subnets accessible via the supervised network interface,

the supervised network interface isolates domain name system (DNS) traffic associated with the supervised zone,

the first instance of the specified application accesses the network via a native network interface of the computing machine and not via the supervised network interface, and

the supervised network interface restricts the multiple additional resources, residing externally to the supervised zone, from accessing network resources associated with the supervised zone.

2. The method of claim 1 , wherein the additional computing resources comprise personal computing resources, wherein the supervised computing resources comprise organizational computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files or applications.

3. The method of claim 1 , wherein:

the first instance of the specified application accesses a Component Object Model (COM) of the computing machine, and

the second instance of the specified application accesses an emulated COM of the supervised zone that is different from the COM of the computing machine.

4. The method of claim 1 , wherein:

the first instance of the specified application accesses, for interprocess communication, a remote procedure call (RPC) subsystem of the computing machine, and

the second instance of the specified application accesses, for interprocess communication, an emulated RPC subsystem of the supervised zone that is different from the RPC subsystem of the computing machine.

5. The method of claim 1 , wherein:

the first instance of the specified application accesses common app platform application programming interfaces (APIs) available to universal applications of the computing machine,

the second instance of the specified application accesses emulated common app platform APIs available to universal applications on the supervised zone that is different from the common app platform APIs available to universal applications of the computing machine.

6. The method of claim 1 , wherein:

the first instance of the specified application accesses common app platform application programming interfaces (APIs) available to universal applications of the computing machine,

the second instance of the specified application accesses emulated common app platform APIs available to universal applications of the supervised zone that is different from the common app platform APIs available to universal applications features of the computing machine,

the common app platform features comprise at least one of: Shell Infrastructure Host (sihost), State Repository Service, Background Task Infrastructure, User Manager Service, Azure Active Directory (AAD) Broker, and Windows Credentials Manager,

the Background Task Infrastructure comprises Host Activity Manager, and

the User Manager Service comprises Application Activation Manager and View Manager.

7. The method of claim 1 , wherein:

the computing machine stores, externally to the supervised zone, a set of global objects,

the computing machine stores, within the supervised zone, an emulated set of global objects emulating the set of global objects,

the first instance of the specified application accesses the set of global objects, and

the second instance of the specified application accesses the emulated set of global objects.

8. The method of claim 1 , wherein:

the computing machine stores, externally to the supervised zone, a computing machine registry representing settings comprising of hardware device configurations, installed application settings, and operating system settings,

the computing machine stores, within the supervised zone, an emulated registry emulating the computing machine registry for applications executing within the supervised zone,

the first instance of the specified application accesses the computing machine registry, and

the second instance of the specified application accesses the emulated registry.

9. The method of claim 1 , wherein:

the specified application is a file manager application,

the first instance is for access to files from the multiple additional computing resources, and

the second instance is for access to files from the multiple supervised computing resources and read-only access to the multiple additional computing resources.

10. The method of claim 1 , further comprising:

accessing, via a file explorer of the computing machine, a request to open a selected file, wherein the file explorer executes externally to the supervised zone, wherein the file has an associated application, wherein the file explorer provides access to both files external to the supervised zone and files internal to the supervised zone;

determining whether the selected file is from among the multiple supervised computing resources;

upon determining that the selected file is from among the multiple supervised computing resources: opening the selected file using an instance of the associated application executing within with the supervised zone; and

upon determining that the selected file is not from among the multiple supervised computing resources: opening the selected file using an instance of the associated application not executing within the supervised zone.

11. The method of claim 1 , wherein an operating system of the computing machine lacks access to the multiple supervised computing resources from outside the supervised zone.

12. The method of claim 1 , wherein a security program is able to access both the supervised zone and the unsupervised zone, wherein the security program comprises one or more of an antivirus program, an anti-malware program or a security auditing tool.

13. The method of claim 12 , further comprising:

identifying a program as the security program based on a data structure storing known security programs and a digital signature associated with the program; and

in response to the digital signature being associated with one of the known security programs in the data structures: transmitting, to a driver of the computing machine, a message indicating that the program is to be able to access both the supervised zone and the unsupervised zone.

14. The method of claim 1 , further comprising:

accessing, using a restricted instance of the specified application executing in a restricted zone, an unsecure computing resource;

blocking access, by the restricted instance of the specified application, to any and all of the multiple supervised computing resources and any and all of the multiple additional computing resources.

15. The method of claim 14 , wherein a security program is able to access the supervised zone, the unsupervised zone, and the restricted zone, wherein the security program comprises one or more of an antivirus program, an anti-malware program or a security auditing tool.

16. The method of claim 15 , further comprising:

identifying the unsecure computing resource based on the unsecure computing resource residing in a download memory region, a memory region associated with attachments for an email application, or a memory region associated with a web browser.

17. The method of claim 16 , wherein the download memory region comprises a download folder, wherein the memory region associated with the web browser comprises the download folder, wherein the memory region associated with the attachments for the email application comprises an attachment folder.

18. The method of claim 1 , further comprising:

opening, via the second instance, an additional application or webpage different from the specified application; and

executing the additional application or webpage within the supervised zone, wherein the additional application or webpage has read access and lacks write access to data outside the supervised zone, wherein the additional application or webpage has read access and has write access to data stored within the supervised zone.

19. A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy, wherein the multiple supervised computing resources reside within a supervised zone, the supervised zone comprising a portion of data associated with a native computing environment of the computing machine;

executing a first instance of a specified application externally to the supervised zone, wherein the first instance has read access and has write access to data outside the supervised zone, wherein the first instance lacks read access and lacks write access to data stored within the supervised zone; and

executing, simultaneously with the first instance, a second instance of the specified application within the supervised zone, wherein the second instance has read access and lacks write access to data outside the supervised zone, wherein the second instance has read access and has write access to data stored within the supervised zone, wherein the second instance runs separately and distinctly from the first instance, wherein:

the first instance of the specified application accesses a Component Object Model (COM) of the computing machine, and

the second instance of the specified application accesses an emulated COM of the supervised zone that is different from the COM of the computing machine.

20. A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy, wherein the multiple supervised computing resources reside within a supervised zone, the supervised zone comprising a portion of data associated with a native computing environment of the computing machine;

executing a first instance of a specified application externally to the supervised zone, wherein the first instance has read access and has write access to data outside the supervised zone, wherein the first instance lacks read access and lacks write access to data stored within the supervised zone; and

executing, simultaneously with the first instance, a second instance of the specified application within the supervised zone, wherein the second instance has read access and lacks write access to data outside the supervised zone, wherein the second instance has read access and has write access to data stored within the supervised zone, wherein the second instance runs separately and distinctly from the first instance, wherein:

the first instance of the specified application accesses a Component Object Model (COM) of the computing machine, and

the second instance of the specified application accesses an emulated COM of the supervised zone that is different from the COM of the computing machine.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; MATALON, DAVID; CHERMYANIN, ALEXANDER; SEDUNOV, ALEKSANDR
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 061235/0939 →
Continuity (2)
Provisional Application 63260408 · Aug 19, 2021
Related Publication 20230057286A1 · Feb 23, 2023
References Cited (74)
US 5870543A · Ronning · 1999 [cited by applicant]
US 5874958A · Ludolph · 1999 [cited by applicant]
US 7162719B2 · Schmidt · 2007 [cited by applicant]
US 7779247B2 · Roegner · 2010 [cited by applicant]
US 8255280B1 · Kay et al. · 2012 [cited by applicant]
US 9021559B1 · Vetter et al. · 2015 [cited by applicant]
US 9307451B1 · Kodeswaran et al. · 2016 [cited by applicant]
US 9461978B2 · Mishra et al. · 2016 [cited by applicant]
US 9785341B2 · Stallings et al. · 2017 [cited by applicant]
US 10152197B1 · Xue · 2018 [cited by applicant]
US 10630716B1 · Ghosh et al. · 2020 [cited by applicant]
US 11687644B2 · Osipov et al. · 2023 [cited by applicant]
US 11704431B2 · Kraus et al. · 2023 [cited by applicant]
US 11750475B1 · Gonzalez et al. · 2023 [cited by applicant]
US 11902330B1 · Dods · 2024 [cited by applicant]
US 20040162781A1 · Searl et al. · 2004 [cited by applicant]
US 20050182750A1 · Krishna et al. · 2005 [cited by applicant]
US 20060236363A1 · Heard et al. · 2006 [cited by applicant]
US 20070033273A1 · White et al. · 2007 [cited by applicant]
US 20070186274A1 · Thrysoe · 2007 [cited by examiner]
US 20070239987A1 · Hoole et al. · 2007 [cited by applicant]
US 20080134071A1 · Keohane et al. · 2008 [cited by applicant]
US 20090187648A1 · Sunkammurali et al. · 2009 [cited by applicant]
US 20090328215A1 · Arzi et al. · 2009 [cited by applicant]
US 20100319053A1 · Gharabally · 2010 [cited by applicant]
US 20110113467A1 · Agarwal et al. · 2011 [cited by applicant]
US 20120030729A1 · Schwartz et al. · 2012 [cited by applicant]
US 20120233314A1 · Jakobsson · 2012 [cited by applicant]
US 20130031549A1 · Osmond · 2013 [cited by applicant]
US 20130160141A1 · Tseng et al. · 2013 [cited by applicant]
US 20130232238A1 · Cohn et al. · 2013 [cited by applicant]
US 20130291055A1 · Muppidi · 2013 [cited by examiner]
US 20130332996A1 · Fiala et al. · 2013 [cited by applicant]
US 20130339518A1 · Schimpfky et al. · 2013 [cited by applicant]
US 20140007184A1 · Porras · 2014 [cited by applicant]
US 20140380406A1 · Saidi et al. · 2014 [cited by applicant]
US 20160070626A1 · Raghavendra · 2016 [cited by applicant]
US 20160099972A1 · Qureshi et al. · 2016 [cited by applicant]
US 20160315967A1 · Trevathan et al. · 2016 [cited by applicant]
US 20170250919A1 · Kessel et al. · 2017 [cited by applicant]
US 20180191766A1 · Holeman et al. · 2018 [cited by applicant]
US 20190199808A1 · Gamache et al. · 2019 [cited by applicant]
US 20200036739A1 · Novikov et al. · 2020 [cited by applicant]
US 20200059492A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20200192867A1 · McBeath · 2020 [cited by applicant]
US 20200204576A1 · Davis et al. · 2020 [cited by applicant]
US 20200320454A1 · Almashor et al. · 2020 [cited by applicant]
US 20200356677A1 · Alexander et al. · 2020 [cited by applicant]
US 20220179983A1 · Kassa et al. · 2022 [cited by applicant]
US 20220215094A1 · Gupta · 2022 [cited by applicant]
US 20220365861A1 · DeFilippo et al. · 2022 [cited by applicant]
US 20230054350A1 · Osipov et al. · 2023 [cited by applicant]
US 20230056056A1 · Osipov et al. · 2023 [cited by applicant]
US 20230362651A1 · Lie · 2023 [cited by applicant]
US 20240184901A1 · Osipov et al. · 2024 [cited by applicant]
US 20240187414A1 · Osipov et al. · 2024 [cited by applicant]
CN 101513008B · 2012 [cited by applicant]
CN 103299658A · 2013 [cited by applicant]
CN 102365554B · 2015 [cited by applicant]
CN 106790231A · 2017 [cited by applicant]
CN 110727942A · 2020 [cited by applicant]
EP 2685750A1 · 2014 [cited by applicant]
KR 1020170035294A · 2017 [cited by applicant]
WO 2014113882A1 · 2014 [cited by applicant]
WO 2017147525A1 · 2017 [cited by applicant]
Towards Resource-aware Business Process development in the Cloud, Hachicha et al, Apr. 2015 (Year: 2015). [cited by applicant]
Notice of Allowance dated Feb. 7, 2023 for U.S. Appl. No. 17/890,798. [cited by applicant]
International Search Report and Written Opinion for PCT Patent Application No. PCT/US2022/040928 dated Nov. 29, 2022, 7 pages. [cited by applicant]
Non-Final Office Action dated Nov. 2, 2022 for U.S. Appl. No. 17/890,798. [cited by applicant]
Non-Final Office Action dated Aug. 28, 2024 for U.S. Appl. No. 17/891,399, 32 pp. [cited by applicant]
Non-Final Office Action dated Sep. 11, 2024 for U.S. Appl. No. 17/891,392. [cited by applicant]
Non-Final Office Action dated Nov. 7, 2024 for U.S. Appl. No. 18/438,775, 33 pp. [cited by applicant]
Non-Final Office Action dated Nov. 18, 2024 for U.S. Appl. No. 17/890,879, 38 pp. [cited by applicant]
Non-Final Office Action dated Nov. 4, 2024 for U.S. Appl. No. 17/890,853, 52 pp. [cited by applicant]