IP Library › Granted Patent US 11,665,166
Granted Patent B2
US 11,665,166 · App. 16/681,802 · Granted May 30, 2023

Secure computing platform

Inventors: Barry Ian Dynkin (Great Neck, NY); Benjamin Futernick Dynkin (Great Neck, NY); Semyon Dynkin (Great Neck, NY)
H04L63/101G06F21/6218H04L63/0853H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,665,166
App. No.
16/681,802
Granted
May 30, 2023
Kind
B2
Abstract

Apparatus, systems and methods for providing a limited capabilities computer which may operate on a network and be controlled, monitored and/or administered by a central network authority such as a VDI server.

Claims (32)

1. A function limited computer for accessing a network, comprising:

at least one memory, a processor and a graphical user interface (GUI), wherein the at least one memory and processor are configured to include:

(a) at least one access control that prevents unauthorized access to the network;

(b) at least one authentication control that prevents unauthorized access to the computer;

(c) at least one kernel level process control which predefines the universe of applications and processes that can run on the function limited computer, thereby preventing an unauthorized application or process from running on the function limited computer; and

(d) a connection broker configured to connect the GUI to a remote server and to receive a virtual desktop from the remoter server, subject to restrictions of the at least one access control, the at least one authentication control and the at least one kernel process control, and to display the virtual desktop on the GUI.

2. The function limited computer according to claim 1 , further including at least one list accessed by the kernel level process control.

3. The function limited computer according to claim 2 wherein the at least one list includes a whitelist of at least one approved application or process.

4. The function limited computer according to claim 2 wherein the at least one list includes a blacklist of at least one unauthorized application or process.

5. A method for employing the function limited computer as defined in claim 1 for accessing a network, the method comprising:

using the function limited computer for logging into a virtual desktop infrastructure (VDI) server via the connection broker;

employing the VDI server to provide via the connection broker, the virtual desktop to the computer;

using the virtual desktop to provide a preset number of functions to the function limited computer;

using the VDI server to connect the computer to an Internet Protocol (IP) address via a virtual private network and monitoring communications between the computer and the IP address.

6. The method according to claim 5 wherein the monitoring the communications includes using network security tools.

7. The method according to claim 5 further comprising utilizing the VDI server for logging and analyzing the communications and generating a report based on the communications.

8. The method according to claim 5 further including utilizing the VDI server for implementing a list of accepted IP addresses with which the computer may connect.

9. The method according to claim 5 further including utilizing the VDI server for implementing a list of unauthorized IP addresses with which the computer may not connect.

10. The method according to claim 5 wherein the preset number of functions in the step of using a virtual desktop is a single function.

11. The method according to claim 5 further including utilizing the VDI server for logging the computer out of the VDI server after a predetermined period of inactivity.

12. The method according to claim 5 further including encrypting a hard drive associated with the computer.

13. The method according to claim 5 further including utilizing the VDI server for authenticating all hardware connecting to the VDI sever.

14. The method according to claim 5 further including utilizing the VDI server for authenticating all software connecting to the VDI sever.

15. A non-transitory computer-readable medium comprising one or more computer executable instructions that, when executed by the function limited computer according to claim 1 , cause the limited function computer to:

login to a virtual desktop infrastructure (VDI) server via the connection broker;

receive from the VDI server, via the connection broker, the virtual desktop;

utilize the virtual desktop for providing a preset number of functions to the function limited computer; and,

connect to an Internet Protocol (IP) address via the VDI server and a virtual private network.

16. The non-transitory computer-readable according to claim 15 , wherein the preset number of functions is a single function.

17. The non-transitory computer-readable medium according to claim 15 , wherein the preset number of functions further cause the function limited computer not to run at least one of the applications or processes based on the at least one of the applications or processes being identified on a list of applications and processes.

18. The non-transitory computer-readable medium according to claim 15 , wherein the preset number of functions cause the function limited computer to run an application or a process based on applications and processes identified on a list of applications and processes.

19. The function limited computer according to claim 1 , wherein the at least one kernel level process limits a potential universe of applications and processes that can run on the function limited computer to one application and/or one process.

Continuity (2)
Provisional Application 62758195 · Nov 9, 2018
Related Publication 20200186532A1 · Jun 11, 2020
Cited By (1)
US 12,627,653