IP Library › Granted Patent US 12,248,557
Granted Patent B2
US 12,248,557 · App. 18/215,575 · Granted Mar 11, 2025

Automatic workstation functionality management based on login credentials

Inventors: Chad Philip McKenzie (London, CA); Benjamin James Allen Dougall (London, CA); Lori-Anne Carley (London, CA)
G06F21/44G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,557
App. No.
18/215,575
Granted
Mar 11, 2025
Kind
B2
Abstract

The present disclosure involves systems, software, and computer implemented methods for automatically controlling access and limiting functionality of a computer workstation based on which user is currently logged in. In some implementations, an overwatch application is installed on the workstations to be controlled and monitored. If an authorized, but limited, user logs in, the overwatch application can initiate a lockdown process on the workstation. In some instances, the lockdown process is managed by a dedicated lockdown application, which is initiated or notified from the overwatch application, and which can initiate a lockdown of particular applications, functionality, and allowed interactions on the workstation until the limited user has completed their task and a new user logs in.

Claims (59)

1. A system for controlling access to a computer, the system comprising:

a communications interface;

at least one memory storing instructions;

at least one hardware processor interoperably coupled with the at least one memory and the communications interface, the instructions instructing the at least one hardware processor, when executed, to perform operations comprising:

detecting a login attempt associated with the computer as initiated by a user, wherein the login attempt is associated with a set of credentials;

determining that the set of credentials are associated with a limited user, wherein the limited user is associated with a pre-defined set of authorized functionality and a pre-defined set of non-authorized functionality for use with the computer;

in response to determining that the set of credentials are associated with a limited user:

initializing a lockdown application;

identifying, by the lockdown application, one or more operating non-authorized functionalities;

terminating, by the lockdown application, the identified non-authorized functionalities; and

monitoring, by the lockdown application, attempted accesses of one or more functionalities at the computer by the limited user prior to allowing access to the one or more functionalities;

detecting, by the lockdown application, attempted access to a first functionality associated with the computer by the limited user, wherein the detection occurs prior to allowing access of the first functionality;

determining, by the lockdown application, whether the first functionality is included within the pre-defined set of non-authorized functionality; and

in response to determining that the first functionality is included in the pre-defined set of non-authorized functionality, preventing, by the lockdown application, access to the first functionality associated with the computer.

2. The system of claim 1 , wherein the set of credentials are associated with a particular user role, and wherein the limited user comprises a user associated with the particular user role.

3. The system of claim 1 , wherein the pre-defined set of authorized functionality is defined for a user role associated with the user.

4. The system of claim 1 , wherein the pre-defined set of authorized functionality is specifically associated with the user.

5. The system of claim 1 , wherein the pre-defined set of authorized functionality comprises a set of authorized applications allowed to execute at the computer.

6. The system of claim 1 , wherein the pre-defined set of authorized functionality comprises an allowed set of hardware inputs associated with at least one application executing or to be executed at the computer.

7. The system of claim 6 , wherein the first functionality is a hardware input not included in the pre-defined set of authorized functionality, and wherein preventing access to the first functionality associated with the computer comprises prohibiting the hardware input from being passed to a particular application or process.

8. The system of claim 1 , wherein initializing the lockdown application comprises:

identifying a set of currently executing applications and processes at the computer;

determining that at least one of the currently executing applications and processes at the computer is not included in the pre-defined set of authorized functionality associated with the limited user; and

terminating the at least one determined currently executing application and process at the computer.

9. A non-transitory, computer-readable medium storing computer-readable instructions executable by at least one processor and configured, when executed, to perform operations comprising:

detecting a login attempt associated with a computer as initiated by a user, wherein the login attempt is associated with a set of credentials;

determining that the set of credentials are associated with a limited user, wherein the limited user is associated with a pre-defined set of authorized functionality and a pre-defined set of non-authorized functionality for use with the computer;

in response to determining that the set of credentials are associated with a limited user:

initializing a lockdown application;

identifying, by the lockdown application, one or more operating non-authorized functionalities;

terminating, by the lockdown application, the identified non-authorized functionalities; and

monitoring, by the lockdown application, attempted accesses of one or more functionalities at the computer by the limited user prior to allowing access to the one or more functionalities;

detecting, by the lockdown application, attempted access to a first functionality associated with the computer by the limited user, wherein the detection occurs prior to allowing access of the first functionality;

determining, by the lockdown application, whether the first functionality is included within the pre-defined set of non-authorized functionality; and

in response to determining that the first functionality is included in the pre-defined set of non-authorized functionality, preventing, by the lockdown application, access to the first functionality associated with the computer.

10. The computer-readable medium of claim 9 , wherein the set of credentials are associated with a particular user role, and wherein the limited user comprises a user associated with the particular user role.

11. The computer-readable medium of claim 9 , wherein the pre-defined set of authorized functionality is defined for a user role associated with the user.

12. The computer-readable medium of claim 9 , wherein the pre-defined set of authorized functionality is specifically associated with the user.

13. The computer-readable medium of claim 9 , wherein the pre-defined set of authorized functionality comprises a set of authorized applications allowed to execute at the computer.

14. The computer-readable medium of claim 9 , wherein the pre-defined set of authorized functionality comprises an allowed set of hardware inputs associated with at least one application executing or to be executed at the computer.

15. The computer-readable medium of claim 14 , wherein the first functionality is a hardware input not included in the pre-defined set of authorized functionality, and wherein preventing access to the first functionality associated with the computer comprises prohibiting the hardware input from being passed to a particular application or process.

16. The computer-readable medium of claim 9 , wherein initializing the lockdown application comprises:

identifying a set of currently executing applications and processes at the computer;

determining that at least one of the currently executing applications and processes at the computer is not included in the pre-defined set of authorized functionality associated with the limited user; and

terminating the at least one determined currently executing application and process at the computer.

17. A computerized method performed by one or more processors, the method comprising:

detecting a login attempt associated with the computer as initiated by a user, wherein the login attempt is associated with a set of credentials;

determining that the set of credentials are associated with a limited user, wherein the limited user is associated with a pre-defined set of authorized functionality and a pre-defined set of non-authorized functionality for use with the computer;

in response to determining that the set of credentials are associated with a limited user:

initializing a lockdown application;

identifying, by the lockdown application, one or more operating non-authorized functionalities;

terminating, by the lockdown application, the identified non-authorized functionalities; and

monitoring, by the lockdown application, attempted accesses user of one or more functionalities at the computer by the limited user prior to allowing access to the one or more functionalities;

detecting, by the lockdown application, attempted access to a first functionality associated with the computer by the limited user, wherein the detection occurs prior to allowing access of the first functionality;

determining, by the lockdown application, whether the first functionality is included within the pre-defined set of non-authorized functionality; and

in response to determining that the first functionality is [not] included in the pre-defined set of non-authorized functionality, preventing, by the lockdown application, access to the first functionality associated with the computer.

18. The method of claim 17 , wherein the set of credentials are associated with a particular user role, and wherein the limited user comprises a user associated with the particular user role.

19. The method of claim 17 , wherein the pre-defined set of authorized functionality is defined for a user role associated with the user.

20. The method of claim 17 , wherein the pre-defined set of authorized functionality is specifically associated with the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2023
From: MCKENZIE, CHAD PHILIP; DOUGALL, BENJAMIN JAMES ALLEN; CARLEY, LORI-ANNE
To: THE TORONTO-DOMINION BANK
Reel/Frame 064100/0484 →
Continuity (3)
Continuation 17658066 · Apr 5, 2022
Continuation 16778534 · Jan 31, 2020
Related Publication 20230342448A1 · Oct 26, 2023
References Cited (14)
US 5428683A · Indeck et al. · 1995 [cited by applicant]
US 7240360B1 · Phan · 2007 [cited by applicant]
US 11328052B2 · Mckenzie et al. · 2022 [cited by applicant]
US 11734410B2 · Mckenzie et al. · 2023 [cited by applicant]
US 20050273848A1 · Charles et al. · 2005 [cited by applicant]
US 20090158441A1 · Mohler et al. · 2009 [cited by applicant]
US 20090222914A1 · Ozawa · 2009 [cited by examiner]
US 20100325097A1 · Er · 2010 [cited by examiner]
US 20210240812A1 · Mckenzie et al. · 2021 [cited by applicant]
US 20220229897A1 · Mckenzie et al. · 2022 [cited by applicant]
Final Office Action in U.S. Appl. No. 17/658,066, dated Mar. 7, 2023, 15 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 16/778,534, dated Aug. 24, 2021, 11 pages. [cited by applicant]
Non-Final Office Action in U.S. Appl. No. 17/658,066, dated Nov. 25, 2022, 14 pages. [cited by applicant]
Office Action in Canadian Appln. No. 3,070,441, mailed on Feb. 1, 2024, 3 pages. [cited by applicant]