IP Library Granted Patent US 12,292,964
Granted Patent B2
US 12,292,964 · App. 17/890,853 · Granted May 6, 2025

Security policy for a portion of resources on a machine

Inventors: Aleksandr Osipov (Tarrytown, NY); Jacob Kazakevich (Manalapan, NJ); David Matalon (Great Neck, NY); Alexander Chermyanin (Antalya, TR); Aleksandr Sedunov (Antalya, TR)
Assignee: Venn Technology Corporation
G06F21/53G06F9/547G06F21/16G06F21/316G06F21/577H04L63/10H04L63/102H04L63/105H04L63/20H04L63/205G06F21/1063G06F2221/033G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,292,964
App. No.
17/890,853
Granted
May 6, 2025
Kind
B2
Abstract

A computer stores, within a single user account, multiple supervised computing resources and multiple additional computing resources. The multiple supervised computing resources are associated with a security policy. The computer executes a first instance of a specified application that lacks read access and lacks write access to any and all of the multiple supervised computing resources. The computer executes, simultaneously with the first instance, a second instance of the specified application that accesses at least a portion of the multiple supervised computing resources. The computer applies rules from the security policy to the second instance of the specified application while foregoing applying the rules from the security policy to the first instance of the specified application.

Claims (47)

1. A method comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

causing, via a native computing environment of the computing machine, a display unit coupled with the computing machine to display, at a first display position, all or a portion of a specified supervised computing resource from among the multiple supervised computing resources;

causing the display unit to display, at a display position calculated based on the first display position, a visual indicator that the specified supervised computing resource is associated with the security policy, wherein the visual indicator comprises a border, wherein the border comprises pixels that are external to the first display portion and within a threshold distance from an edge of the first display portion, wherein multiple computing resources are displayed on the display unit, wherein each displayed computing resource is associated with a display priority value based on a time when the displayed computing resource was last selected, wherein the border comprises pixels that are not occupied by a computing resource that was selected after a last selection time of the specified supervised computing resource; and

applying security rules from the security policy to the specified supervised computing resource.

2. The method of claim 1 , wherein the additional computing resources comprise personal computing resources, wherein the supervised computing resources comprise business computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, cloud file storage access, applications or websites.

3. The method of claim 1 , wherein the additional computing resources comprise computing resources of a first type, wherein the supervised computing resources comprise computing resources of a second type for which an entity desires enhanced security, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, cloud file storage access, applications or websites.

4. The method of claim 1 , wherein the visual indicator comprises a badge proximate to an edge of the first display position, the badge indicating that the security policy is applicable to the specified supervised computing resource.

5. The method of claim 4 , further comprising:

receiving a signal representing a user selection of the badge; and

causing, in response to the user selection of the badge, the display unit to display information about the security policy applicable to the computing machine.

6. The method of claim 1 , wherein the border comprises pixels that are not occupied by a badge associated with the visual indicator.

7. The method of claim 1 , further comprising:

receiving, at processing circuitry of the computing machine, a signal representing dragging the specified supervised computing resource along the display unit;

recalculating, using the processing circuitry, a position of the border in a discrete manner once every n milliseconds or based on operating system window events, wherein n is a predetermined positive number.

8. The method of claim 1 , further comprising:

generating a pop-up or an on-display alert by the specified supervised computing resource; and

causing display of the border around the pop-up or the on-display alert.

9. The method of claim 1 , further comprising:

receiving, at the computing machine, a user request to perform an action that violates a security rule; and

permitting, based on a setting stored in conjunction with the security policy and provided by an administrator of the security policy, the user to perform the action that violates the security rule in response to an additional affirmative act by the user confirming that the user wishes to perform the action.

10. The method of claim 1 , further comprising:

causing, via the native computing environment of the computing machine, the display unit to display, at a second display position, all or a portion of a specified additional computing resource from among the multiple additional computing resources;

foregoing causing the display unit to display, in association with the specified additional computing resource, the visual indicator; and

foregoing applying security rules from the security policy to the specified additional computing resource.

11. The method of claim 1 , further comprising:

causing, via a native computing environment of the computing machine, the display unit coupled with the computing machine to display, at a predefined display position, indicia of multiple computing resources open on the computing device, wherein indicia of supervised computing resources are coupled with a visual symbol indicating that the supervised computing resources are associated with the security policy.

12. The method of claim 11 , wherein indicia of additional computing resources are not coupled with the visual symbol.

13. The method of claim 11 , wherein the displayed indicia of the multiple computing resources comprise a task bar or a dock.

14. A non-transitory machine-readable medium storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

causing, via a native computing environment of the computing machine, a display unit coupled with the computing machine to display, at a first display position, all or a portion of a specified supervised computing resource from among the multiple supervised computing resources;

causing the display unit to display, at a display position calculated based on the first display position, a visual indicator that the specified supervised computing resource is associated with the security policy, wherein the visual indicator comprises a border, wherein the border comprises pixels that are external to the first display portion and within a threshold distance from an edge of the first display portion, wherein multiple computing resources are displayed on the display unit, wherein each displayed computing resource is associated with a display priority value based on a time when the displayed computing resource was last selected, wherein the border comprises pixels that are not occupied by a computing resource that was selected after a last selection time of the specified supervised computing resource; and

applying security rules from the security policy to the specified supervised computing resource.

15. The machine-readable medium of claim 14 , wherein the additional computing resources comprise personal computing resources, wherein the supervised computing resources comprise business computing resources, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, cloud file storage access, applications or websites.

16. The machine-readable medium of claim 14 , wherein the additional computing resources comprise computing resources of a first type, wherein the supervised computing resources comprise computing resources of a second type for which an entity desires enhanced security, wherein the multiple supervised computing resources and the multiple additional computing resources comprise files, cloud file storage access, applications or websites.

17. The machine-readable medium of claim 14 , wherein the visual indicator comprises a badge proximate to an edge of the first display position, the badge indicating that the security policy is applicable to the specified supervised computing resource.

18. The machine-readable medium of claim 17 , further comprising:

receiving a signal representing a user selection of the badge; and

causing, in response to the user selection of the badge, the display unit to display information about the security policy applicable to the computing machine.

19. A system comprising:

processing circuitry; and

a memory storing instructions that, when executed by processing circuitry, cause the processing circuitry to perform operations comprising:

storing, at a computing machine, multiple supervised computing resources and multiple additional computing resources, wherein the multiple supervised computing resources are associated with a security policy;

causing, via a native computing environment of the computing machine, a display unit coupled with the computing machine to display, at a first display position, all or a portion of a specified supervised computing resource from among the multiple supervised computing resources;

causing the display unit to display, at a display position calculated based on the first display position, a visual indicator that the specified supervised computing resource is associated with the security policy, wherein the visual indicator comprises a border, wherein the border comprises pixels that are external to the first display portion and within a threshold distance from an edge of the first display portion, wherein multiple computing resources are displayed on the display unit, wherein each displayed computing resource is associated with a display priority value based on a time when the displayed computing resource was last selected, wherein the border comprises pixels that are not occupied by a computing resource that was selected after a last selection time of the specified supervised computing resource; and

applying security rules from the security policy to the specified supervised computing resource.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Nov 4, 2024
From: COMERICA BANK
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 069121/0211 →
SECURITY INTEREST Recorded Aug 31, 2023
From: VENN TECHNOLOGY CORPORATION
To: COMERICA BANK
Reel/Frame 064763/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2022
From: OSIPOV, ALEKSANDR; KAZAKEVICH, JACOB; MATALON, DAVID; CHERMYANIN, ALEXANDER; SEDUNOV, ALEKSANDR
To: VENN TECHNOLOGY CORPORATION
Reel/Frame 060847/0593 →
Continuity (2)
Provisional Application 63260408 · Aug 19, 2021
Related Publication 20230053983A1 · Feb 23, 2023
References Cited (96)
US 5870543A · Ronning · 1999 [cited by examiner]
US 5874958A · Ludolph · 1999 [cited by examiner]
US 6658571B1 · O'Brien et al. · 2003 [cited by applicant]
US 7162719B2 · Schmidt · 2007 [cited by applicant]
US 7779247B2 · Roegner · 2010 [cited by applicant]
US 7926086B1 · Violleau et al. · 2011 [cited by applicant]
US 8255280B1 · Kay · 2012 [cited by examiner]
US 9021559B1 · Vetter et al. · 2015 [cited by applicant]
US 9307451B1 · Kodeswaran · 2016 [cited by examiner]
US 9461978B2 · Mishra et al. · 2016 [cited by applicant]
US 9646152B2 · Lam et al. · 2017 [cited by applicant]
US 9785341B2 · Stallings et al. · 2017 [cited by applicant]
US 10152197B1 · Xue · 2018 [cited by applicant]
US 10254942B2 · Vranjes et al. · 2019 [cited by applicant]
US 10630716B1 · Ghosh · 2020 [cited by examiner]
US 10657246B2 · Biswas et al. · 2020 [cited by applicant]
US 11086984B2 · Shannon · 2021 [cited by applicant]
US 11687644B2 · Osipov et al. · 2023 [cited by applicant]
US 11704431B2 · Kraus et al. · 2023 [cited by applicant]
US 11750475B1 · Gonzalez · 2023 [cited by examiner]
US 11902330B1 · Dods · 2024 [cited by applicant]
US 20020178119A1 · Griffin et al. · 2002 [cited by applicant]
US 20040162781A1 · Searl · 2004 [cited by examiner]
US 20050182750A1 · Krishna · 2005 [cited by examiner]
US 20060041405A1 · Chen · 2006 [cited by examiner]
US 20060236363A1 · Heard et al. · 2006 [cited by applicant]
US 20070033273A1 · White et al. · 2007 [cited by applicant]
US 20070094673A1 · Hunt et al. · 2007 [cited by applicant]
US 20070186274A1 · Thrysoe et al. · 2007 [cited by applicant]
US 20070239987A1 · Hoole et al. · 2007 [cited by applicant]
US 20080134071A1 · Keohane et al. · 2008 [cited by applicant]
US 20090177979A1 · Garbow · 2009 [cited by examiner]
US 20090187648A1 · Sunkammurali · 2009 [cited by examiner]
US 20090328215A1 · Arzi · 2009 [cited by examiner]
US 20100319053A1 · Gharabally · 2010 [cited by applicant]
US 20110113467A1 · Agarwal et al. · 2011 [cited by applicant]
US 20120030729A1 · Schwartz · 2012 [cited by examiner]
US 20120210333A1 · Potter et al. · 2012 [cited by applicant]
US 20120233314A1 · Jakobsson · 2012 [cited by examiner]
US 20130031549A1 · Osmond · 2013 [cited by examiner]
US 20130160141A1 · Tseng et al. · 2013 [cited by applicant]
US 20130232238A1 · Cohn et al. · 2013 [cited by applicant]
US 20130291055A1 · Muppidi et al. · 2013 [cited by applicant]
US 20130332996A1 · Fiala · 2013 [cited by examiner]
US 20130339518A1 · Schimpfky · 2013 [cited by examiner]
US 20140007184A1 · Porras · 2014 [cited by applicant]
US 20140095894A1 · Barton et al. · 2014 [cited by applicant]
US 20140380406A1 · Saidi et al. · 2014 [cited by applicant]
US 20150134735A1 · Momchilov et al. · 2015 [cited by applicant]
US 20160070626A1 · Raghavendra · 2016 [cited by examiner]
US 20160099972A1 · Qureshi et al. · 2016 [cited by applicant]
US 20160255139A1 · Rathod · 2016 [cited by applicant]
US 20160315967A1 · Trevathan et al. · 2016 [cited by applicant]
US 20170041344A1 · Nandakumar et al. · 2017 [cited by applicant]
US 20170250919A1 · Kessel · 2017 [cited by examiner]
US 20180191766A1 · Holeman · 2018 [cited by examiner]
US 20190199808A1 · Gamache · 2019 [cited by examiner]
US 20200036739A1 · Novikov · 2020 [cited by examiner]
US 20200059492A1 · Janakiraman et al. · 2020 [cited by applicant]
US 20200192867A1 · McBeath · 2020 [cited by applicant]
US 20200204576A1 · Davis · 2020 [cited by examiner]
US 20200233951A1 · Biswas et al. · 2020 [cited by applicant]
US 20200320454A1 · Almashor et al. · 2020 [cited by applicant]
US 20200356677A1 · Alexander · 2020 [cited by examiner]
US 20210051155A1 · Sloane · 2021 [cited by examiner]
US 20220179983A1 · Kassa et al. · 2022 [cited by applicant]
US 20220215094A1 · Gupta · 2022 [cited by examiner]
US 20220336078A1 · Wise · 2022 [cited by examiner]
US 20220365861A1 · DeFilippo · 2022 [cited by examiner]
US 20230054350A1 · Osipov · 2023 [cited by examiner]
US 20230056056A1 · Osipov · 2023 [cited by examiner]
US 20230308474A1 · Thompson · 2023 [cited by examiner]
US 20230362651A1 · Lie · 2023 [cited by examiner]
US 20240007506A1 · Cage · 2024 [cited by examiner]
US 20240184901A1 · Osipov · 2024 [cited by examiner]
US 20240187414A1 · Osipov · 2024 [cited by examiner]
CN 101513008B · 2012 [cited by examiner]
CN 103299658A · 2013 [cited by examiner]
CN 102365554B · 2015 [cited by examiner]
CN 106790231A · 2017 [cited by examiner]
CN 110727942A · 2020 [cited by examiner]
EP 2685750A1 · 2014 [cited by examiner]
KR 1020170035294A · 2017 [cited by applicant]
WO WO2014113882A1 · 2014 [cited by examiner]
WO WO2017147525A1 · 2017 [cited by examiner]
Non-Final Office Action dated Nov. 2, 2022 for U.S. Appl. No. 17/890,798. [cited by applicant]
Non-Final Office Action dated Sep. 11, 2024 for U.S. Appl. No. 17/891,392. [cited by applicant]
Non-Final Office Action dated Aug. 28, 2024 for U.S. Appl. No. 17/891,399, 32 pp. [cited by applicant]
International Search Report and Written Opinion for PCT Patent Application No. PCT/US2022/040928 dated Nov. 29, 2022, 7 pages. [cited by applicant]
Towards Resource-aware Business Process development in the Cloud, Hachicha et al, Apr. 2015 (Year: 2015). [cited by applicant]
Notice of Allowance dated Feb. 7, 2023 for U.S. Appl. No. 17/890,798. [cited by applicant]
Non-Final Office Action dated Nov. 18, 2024 for U.S. Appl. No. 17/890,879, 38 pp. [cited by applicant]
Non-Final Office Action dated Nov. 7, 2024 for U.S. Appl. No. 18/438,775, 33 pp. [cited by applicant]
Final Office Action dated Jan. 24, 2025 for U.S. Appl. No. 17/891,370, 56 pp. [cited by applicant]
Notice of Allowance dated Jan. 29, 2025 for U.S. Appl. No. 17/891,392. [cited by applicant]
Final Office Action dated Feb. 12, 2025 for U.S. Appl. No. 17/891,357, 54 pp. [cited by applicant]