Secure Visual and Computational Boundaries for a Subset of Resources on a Computing Machine

A secure computing environment for mixed-use computers is achieved by separating personal and business resources through a security policy and visual indicators, effectively protecting business resources while maintaining privacy for personal resources.

JP7686145B2Active Publication Date: 2025-05-30ベン·テクノロジー·コーポレイション
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024510254
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-08-18
Filing Date
2022-08-19
Publication Date
2025-05-30
Estimated Expiration
2042-08-19

AI Technical Summary

Technical Problem

Existing technologies lack effective solutions for providing a secure computing environment for mixed-use computers, where both personal and business applications and files are stored, without compromising privacy or security.

Method used

The implementation of a system that separates personal and business computing resources by applying a security policy, which includes tracking and monitoring policies, and visually indicating which resources are subject to these policies, thereby restricting unauthorized access and operations.

Benefits of technology

This solution effectively enhances security by ensuring that business resources are protected while allowing personal resources to remain private, thereby maintaining a balance between security and privacy in a mixed-use computing environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007686145000001
    Figure 0007686145000001
  • Figure 0007686145000002
    Figure 0007686145000002
  • Figure 0007686145000003
    Figure 0007686145000003
Patent Text Reader

Abstract

A computer stores a plurality of managed computing resources and a plurality of additional computing resources within a single user account. The plurality of managed computing resources are associated with a security policy. The computer executes a first instance of a specified application that has no read and write access to any and all of the plurality of managed computing resources. The computer executes a second instance of the specified application concurrently with the first instance, the second instance of the specified application that accesses at least a portion of the plurality of managed computing resources. The computer applies rules from the security policy to the second instance of the specified application while refraining from applying rules from the security policy to the first instance of the specified application.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Priority Claim This application claims priority to U.S. Provisional Patent Application No. 63 / 260,408, filed on August 19, 2021, entitled "SECURE COMPUTING ENVIRONMENT FOR MIXED USE COMPUTER", and U.S. Patent Application No. 17 / 890,798, filed on August 18, 2022, entitled "TRACKING COMPUTING ACTIVITY WITH A SUBSET OF RESOURCES", the entire disclosures of which are incorporated herein by reference.

[0002] Embodiments relate to computer architecture. Some embodiments relate to a secure computing environment for a mixed use computer.

Background Art

[0003] Users of computers, such as employees of a company, may use the same computer for business use and personal use. The computer may store business applications or files along with personal applications or files. As indicated above, techniques for providing a secure computing environment for a mixed use computer may be desirable.

Brief Description of the Drawings

[0004]

Figure 1

Figure 2

Figure 3

Figure 4A

Figure 4B

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

[0005] The following description and drawings fully disclose specific embodiments to enable those skilled in the art to practice them. Other embodiments may incorporate structural, logical, electrical, process, and other variations. Portions and features of some embodiments may be included in or substituted for those of other embodiments. Embodiments shown in the claims encompass all available equivalents of these claims.

[0006] Aspects of the technology may be implemented as part of a computer system. The computer system may be a single physical machine or may be distributed among multiple physical machines, for example, by role or function or, in the case of a cloud computing distributed model, by process thread. In various embodiments, aspects of the technology can be configured to be executed in a virtual machine, and the virtual machine is executed on one or more physical machines. Those skilled in the art will understand that the features of the technology can be realized by various suitable machine implementations.

[0007] The system includes various engines, each constructed, programmed, configured, or otherwise adapted to perform a function or set of functions. As used herein, the term "engine" refers to a tangible device, component, or arrangement of components implemented using hardware such as an application specific integrated circuit (ASIC) or a field programmable gate array (FPGA), or as a combination of hardware and software by, for example, a processor-based computing platform and a set of program instructions that convert the computing platform into a dedicated device for implementing a particular function. An engine can be implemented as two combinations, one facilitated only by hardware for a particular function and the other facilitated by a combination of hardware and software for other functions.

[0008] In one example, software can exist on a tangible machine-readable storage medium in a form that is executable or non-executable. Software that exists in a non-executable form can be compiled, converted, or otherwise converted into an executable form before or during runtime. In an example, software causes hardware to perform specified operations when executed by the underlying hardware of an engine. Thus, an engine is physically constructed, or specially configured (e.g., hardwired), or temporarily configured (e.g., programmed) to operate in a particular manner or to perform some or all of any of the operations described herein in connection with that engine.

[0009] Considering an example where an engine is temporarily configured, each of the engines can be instantiated at various times. For example, if the engine includes a general-purpose hardware processor core configured using software, this general-purpose hardware processor core may be configured as different engines at different times. Thus, software can configure the hardware processor core, for example, to configure a specific engine at one time and another engine at a different time.

[0010] In some embodiments, at least a part of the engine, and in some cases all of it, may be executed on the processors of one or more computers that execute an operating system, system programs, and application programs, and where appropriate, further implement the engine using multitasking, multithreading, distributed (e.g., cluster, peer-to-peer, cloud, etc.) processing, or other such techniques. Thus, each engine can be realized in a wide variety of appropriate configurations and should generally not be limited to the specific embodiments exemplified herein unless a limitation to a particular embodiment exemplified herein is clearly stated.

[0011] In addition, an engine can itself be composed of two or more sub-engines, and each sub-engine can be regarded as an independent engine. Moreover, in the embodiments described herein, each of the various engines corresponds to a defined function; however, it should be understood that in other contemplated embodiments, each function can be distributed among two or more engines. Similarly, in other contemplated embodiments, multiple defined functions may be implemented by a single engine that performs these multiple functions, possibly in parallel with other functions, or may be distributed among a set of engines different from those specifically exemplified in the examples herein.

[0012] As used herein, the term "model" encompasses its ordinary and customary meaning. A model can include, among other things, one or more engines that receive an input and calculate an output based on this input. The output can be a classification. For example, an image file can be classified as showing a cat or not showing a cat. Alternatively, an image file may be assigned a numerical score indicating the likelihood that the image file shows a cat, and an image file having a score exceeding a threshold (e.g., 0.9 or 0.95) may be determined to show a cat.

[0013] This specification can refer to a particular number of things (e.g., "6 mobile devices"). Unless otherwise explicitly indicated, the numbers provided are merely examples and can be replaced with any positive integer, integer, or real number as appropriate for a given situation. For example, "6 mobile devices" can include, in alternative embodiments, any positive integer number of mobile devices. Unless otherwise indicated, an object referred to in the singular (e.g., "a computer" or "the computer") can include one or more objects (e.g., "computer" can refer to one or more computers).

[0014] FIG. 1 shows a circuit block diagram of a computing machine 100 according to some embodiments. In some embodiments, components of the computing machine 100 can be stored or integrated in other components shown in the circuit blocks of FIG. 1. For example, a portion of the computing machine 100 may be present within the processor 102 and may be referred to as a "processing circuit". The processing circuit can include processing hardware, such as one or more central processing units (CPUs), one or more graphics processing units (GPUs), and the like. In alternative embodiments, the computing machine 100 can operate as a stand-alone device or can be connected (e.g., networked) to other computers. In a networked deployment, the computing machine 100 can operate within the capacity of a server, a client, or both in a server-client network environment. In one example, the computing machine 100 can act as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. In this document, the phrases P2P, device-to-device (D2D), and sidelink can be used interchangeably. The computing machine 100 can be a dedicated computer, a personal computer (PC), a tablet PC, a personal digital assistant (PDA), a mobile phone, a smartphone, a web appliance, a network router, a switch or bridge, or any machine capable of executing instructions (sequentially or otherwise) that specify actions to be taken by that machine.

[0015] As described herein, an example may include logic or a number of components, modules, or mechanisms, or may operate on logic or a number of components, modules, or mechanisms. Modules and components are tangible entities (e.g., hardware) capable of performing specified operations and can be configured or arranged in a particular manner. In an example, a circuit may be arranged as a module in a particular manner (e.g., internally or with respect to external entities such as other circuits). In an example, all or part of one or more computer systems / apparatuses (e.g., stand-alone, client, or server computer systems) or one or more hardware processors may be configured by firmware or software (e.g., instructions, an application portion, or an application) as a module that operates to perform specified operations. In an example, software can reside on a machine-readable medium. In an example, when software is executed by the underlying hardware of a module, it causes the hardware to perform specified operations.

[0016] Accordingly, the terms "module" (and "component") are understood to include a physical constructed entity that is specifically configured (e.g., hardwired) or temporarily (e.g., ephemerally) configured (e.g., programmed) to operate in a particular manner or perform some or all of any of the operations described herein. Considering an example where a module is temporarily configured, each of the modules need not be instantiated at any given time. For example, if a module includes a general-purpose hardware processor configured using software, this general-purpose hardware processor may be configured as different modules at different times. Thus, software can configure a hardware processor, for example, to configure a particular module at one time and a different module at a different time.

[0017] As used herein, the term "application" encompasses its ordinary and customary meaning. An application can include software that is stored in a computing machine and executed on that computing machine. An application can include software that is executed on a computing machine but stored remotely or in the cloud. An application can include a website that includes software stored on a server or in the cloud for execution on a computing machine. In some cases, rather than being stored in software, an application can be hardwired to a computing machine or a remote server.

[0018] Computing machine 100 can include a hardware processor 102 (e.g., a central processing unit (CPU), a GPU, a hardware processor core, or any combination thereof), a main memory 104, and a static memory 106, and some or all of these components can communicate with each other via an interlink (e.g., a bus) 108. Although not shown, main memory 104 can include any or all of removable storage and non-removable storage, volatile memory or non-volatile memory. Computing machine 100 can further include a video display unit 110 (or other display unit), an alphanumeric input device 112 (e.g., a keyboard), and a user interface (UI) navigation device 114 (e.g., a mouse). In one example, display unit 110, input device 112, and UI navigation device 114 can be a touch screen display. Computing machine 100 can further include a storage device (e.g., a drive unit) 116, a signal generation device 118 (e.g., a speaker), a network interface device 120, and one or more sensors 121 such as a global positioning system (GPS) sensor, a compass, an accelerometer, or other sensors. Computing machine 100 can include an output controller 128 such as a serial (e.g., universal serial bus (USB)), parallel, or other wired or wireless (e.g., infrared (IR), near field communication (NFC), etc.) connection to communicate with or control one or more peripheral devices (e.g., a printer, a card reader, etc.).

[0019] The drive unit 116 (e.g., a storage device) can include a machine-readable medium 122, which stores one or more sets of data constructs or instructions 124 (e.g., software) that implement or are utilized by any one or more of the techniques or functions described herein. The instructions 124 may be entirely or at least partially present in the main memory 104, the static memory 106, or the hardware processor 102 while the instructions 124 are being executed by the computing machine 100. In one example, a combination of one or any combination of the hardware processor 102, the main memory 104, the static memory 106, or the storage device 116 can constitute a machine-readable medium.

[0020] Although the machine-readable medium 122 is shown as a single medium, the term "machine-readable medium" can include a single medium or a plurality of media (e.g., a central database or a distributed database, and / or associated caches and servers) configured to store one or more instructions 124.

[0021] The term "machine-readable medium" can include any medium that can store, encode, or carry instructions for execution by computing machine 100, cause computing machine 100 to perform any one or more of the techniques of the present disclosure, or store, encode, or carry data structures used by or associated with such instructions. Examples of non-limiting machine-readable media can include solid-state memory as well as optical and magnetic media. Specific examples of machine-readable media can include: non-volatile memory such as semiconductor memory devices (e.g., electrically programmable read-only memory (EPROM); electrically erasable and programmable read-only memory (EEPROM)) and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; random access memory (RAM); and CD-ROM and DVD-ROM disks. In some examples, the machine-readable medium can include a non-transitory machine-readable medium. In some examples, the machine-readable medium can include a machine-readable medium that is not a transitory propagated signal.

[0022] Command 124 may further be transmitted or received on communication network 126 using a transmission medium via network interface device 120 that utilizes any of several transfer protocols (e.g., frame relay, Internet Protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc.). Exemplary communication networks can include, among others, local area networks (LANs), wide area networks (WANs), packet data networks (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, and wireless data networks (e.g., the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard family known as Wi-Fi(R), the IEEE 802.16 standard family known as WiMax(R), the IEEE 802.15.4 standard family, the Long Term Evolution (LTE) standard family, the Universal Mobile Telecommunications System (UMTS) standard family, peer-to-peer (P2P) networks). In one example, network interface device 120 can include one or more physical jacks (e.g., Ethernet, coaxial cable, or telephone jack) or one or more antennas for connecting to communication network 126.

[0023] Users of computers among employees of an enterprise, etc. may use the same computer for business use and personal use. The computer may store business applications or files that a business may wish to be subject to its security policy, and personal applications or files that a user does not wish to share with the business. Alternatively, users of non-business computers may wish to separate applications or files used for specific purposes (e.g., investment management, family purposes, dating, etc.) for different treatment with respect to the security policy. As described above, techniques for providing a secure computing environment for mixed-use computers may be desirable.

[0024] As used herein, the phrase "mixed-use computer" (alternatively, mixed-use computing machine, mixed-use computing device, etc.) encompasses its ordinary and customary meaning. A mixed-use computer can store computing resources (e.g., applications, files, cloud file storage access, email, videos, photos, etc.), some of which are associated with a security policy and some of which are not. For example, a user may use a computer for both personal and business use. The computer may store business computing resources (e.g., patent applications, examiner notification responses, client pitches, and business email messages that the user uses for business purposes) and personal computing resources (e.g., personal email messages, personal letters, photos, and videos) in the same user profile (e.g., a user account associated with a login identifier and, in some cases, a password for accessing resources on the computer). A business may enforce business security and tracking policies for business computing resources while refraining from applying business security policies to personal computing resources in order to protect the privacy of the user. Alternatively, the present invention may be used to separate any type of computing resource to which a security policy is applied / not applied that is not necessarily a business / personal computing resource.

[0025] As discussed above, a mixed-use computer can store both personal and business computing resources (e.g., applications or files). It may be desirable to notify the user which computing resources are (or are not) subject to security policies and / or tracking.

[0026] As used herein, the term "security policy" encompasses its ordinary and customary meaning. A security policy defines authorized and unauthorized actions with respect to a set of computing resources (e.g., business computing resources in a computing machine, or any computing resources), and prevents a computing machine from taking unauthorized actions. A security policy can include various access permissions (e.g., by antivirus software or other software), and computing resource sharing permissions. A security policy may require that certain actions (e.g., password entry, verification of user identification by fingerprint or face scan, etc.) be taken before accessing computing resources covered by the security policy, or before sharing computing resources covered by the security policy (e.g., by a messaging service).

[0027] In some cases, a security policy can include a tracking policy or a monitoring policy. For example, a tracking policy or a monitoring policy can enable an administrator (e.g., in a remote computing machine) to monitor the activities of a user of a computing machine with respect to computing resources covered by the tracking policy or the monitoring policy. A tracking policy or a monitoring policy can record the activities of a user of a computing machine with respect to computing resources in a server or data repository accessible to the administrator.

[0028] Computing resources covered by a security policy and computing resources not covered (e.g., business resources and personal resources) can be separated in various ways. For example, computing resources covered by a security policy may exist in a different directory in the file system from resources not covered by the security policy. Alternatively, computing resources having a specific file type (e.g., a file type associated with a word processor such as a.docx file) or created by a specific software can be covered by a security policy, while files having other file types (e.g., a file type associated with a photograph such as a.jpg file) or created by other software may not be covered by the security policy regardless of the directory in which the files exist.

[0029] A computing machine can have multiple security policies. For example, a computing machine can have an antivirus security policy for all computing resources on the computing machine. A computing machine can also have a business computing resource security policy that applies specific rules to business computing resources but not to other computing resources.

[0030] Computing resources can include, for example, files, applications, network interface overlays (e.g., network tunnels), windows, etc. Computing resources can be stored in the memory of a computing machine.

[0031] FIG. 2 shows an exemplary system 200 that can use a hybrid-use computing machine. As shown, system 200 includes a computing machine 202 and a tracking service 210. As shown, computing machine 202 is a laptop computer. However, in alternative embodiments, computing machine 202 can be any computing machine that includes a processing circuit and memory, such as a desktop computer, mobile phone, tablet computer, smart watch, personal digital assistant (PDA), etc. Computing machine 202 can include all or a portion of the components of computing machine 100. As shown, tracking service 210 is a cloud service. Tracking service 210 can include one or more of a cloud-based tracking service, one or more servers, an administrator computing device associated with a security policy implemented in computing machine 202, etc.

[0032] Computing machine 202 can store a plurality of personal computing resources and a plurality of business computing resources. Some of these resources, such as personal computing resource 208 and business computing resource 204, can be displayed via a display unit (e.g., a screen or monitor) of computing machine 202. Both business computing resource 204 and personal computing resource 208 can be displayed via the native computing environment of computing machine 202, rather than by accessing a remote virtual machine or physical machine.

[0033] Personal computing resources and business computing resources can be separated in various ways. In some embodiments, personal computing resources and business computing resources are present in a specified pre-defined location of the file system. For example, a particular directory can be associated with business computing resources, and a particular other directory can be associated with personal computing resources. In some embodiments, personal computing resources are associated with personal file types (e.g.,.jpg or.mp3), while business computing resources are associated with business file types (e.g.,.doc or.xls). In some embodiments, personal computing resources are generated by a particular application (e.g., a camera application), while business computing resources are generated by a particular other application (e.g., a word processor, a spreadsheet program, or a slide presentation program).

[0034] As used herein, the term "native computing environment" encompasses its ordinary and customary meaning. A computing resource (e.g., an application, a file, or a window) is executed in a native computing environment when it is executed directly in an operating system (e.g., without any external software layer and without requiring access to a virtual machine or virtualization software, on a physical computing machine that stores the computing resource, or alternatively directly on a virtual machine).

[0035] In some embodiments, a "managed zone" (which may also be referred to as a "business zone" or a "work zone") can be defined within the native computing environment of a computing machine. The managed zone can include computing resources that exist as part of the file system of the computing machine or of a cloud storage unit. The managed zone can also include a network interface overlay (e.g., a network tunnel) for accessing a network. The managed zone can include specific applications. In some embodiments, a security policy can be applied to computing resources within the managed zone rather than to computing resources external to the managed zone.

[0036] The computing machine 202 can store a security policy that applies to business computing resources rather than personal computing resources. The security policy can restrict screen captures of business computing resources, sharing of business computing resources, copying data from business computing resources, etc. The security policy can also enable the tracking of the use of business computing resources by a tracking service 210 in the computing machine 202. During enforcement of the security policy, the tracking service 210 may not track users of personal computing resources on the computing device.

[0037] As shown in FIG. 2, computing machine 202 displays business computing resources 204 and personal computing resources 208 on a combined display unit. Visual indicator 206 adjacent to business computing resources 204 indicates that business computing resources 204 are subject to tracking by security policy and tracking service 210. Since personal computing resources 208 are not subject to the security policy and not subject to tracking by tracking service 210, there is no such visual indicator. As shown, visual indicator 206 is a border line. However, in other embodiments, visual indicator 206 can include one or more of a border line, a badge, etc.

[0038] In some embodiments, visual indicator 206 is a border line. The border line can claim points outside business computing resources 204 within a distance of no more than n pixels (n is a positive integer) from business computing resources 204, provided that these pixels are not occupied by other computing resources (such as windows) that are more dominant than business computing resources 204 in the computing resource stack. Other computing resources can be more dominant, for example, if they have been used more recently than business computing resources 204. This is shown, for example, in FIGS. 4A through 4B and is discussed in more detail below.

[0039] As discussed above, business computing resources are subject to security policies and tracking. Personal computing resources are not subject to security policies and tracking. However, in alternative embodiments, different computing resources than personal / business may be used. For example, a computing machine may be provided to a child by a parent, having some resources (e.g., web browser, video player) that the parent wishes to track and / or manage, and other resources (e.g., word processor, chess play application stored in memory) that the parent does not wish to track and / or manage. Alternatively, an investor may wish that his / her investment advisor be able to track and / or manage resources (e.g., investment company website, investment company application) used for investment management purposes, but not other resources (e.g., other websites, applications, or files).

[0040] FIG. 3 is a flowchart of an exemplary process 300 associated with providing a visual tracking indicator. In some embodiments, one or more process blocks of FIG. 3 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more process blocks of FIG. 3 may be performed by another device, or a group of devices separate from or including the computing machine. Additionally or alternatively, one or more process blocks of FIG. 3 may be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128, etc.

[0041] As shown in FIG. 3, process 300 can include storing, in a computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy (block 310). For example, as described above, a computing machine can store a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy.

[0042] As further shown in FIG. 3, process 300 can include simultaneously displaying, on a display unit coupled to the computing machine via the native computing environment of the computing machine, all or a portion of the designated managed computing resources and all or a portion of the designated additional computing resources (block 320). For example, as described above, a computing machine can simultaneously display, on a display unit coupled to the computing machine via the native computing environment of the computing machine, all or a portion of the designated managed computing resources and all or a portion of the designated additional computing resources.

[0043] As further shown in FIG. 3, process 300 can include applying security rules from a security policy to specified managed computing resources, and applying the security rules includes promoting tracking of the activities of the computing machine with respect to at least the specified managed computing resources (block 330). For example, as described above, the computing machine can apply security rules from a security policy to specified managed computing resources, and applying the security rules includes promoting tracking of the activities of the computing machine with respect to at least the specified managed computing resources.

[0044] As further shown in FIG. 3, process 300 can include commensurating promoting tracking of the activities of the computing machine with respect to activities on a computing machine related to specified additional computing resources and not associated with one or more of a plurality of managed computing resources (block 340). For example, as described above, the computing machine can commensurate promoting tracking of the activities of the computing machine with respect to activities on a computing machine related to specified additional computing resources and not associated with one or more of a plurality of managed computing resources.

[0045] Process 300 can include additional embodiments such as any single embodiment or any combination of embodiments related to one or more other processes described below and / or elsewhere in this specification.

[0046] In the first embodiment, the additional computing resources include personal computing resources, the managed computing resources include business computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites. Cloud file storage access can include access to a network-based file storage system (e.g., OneDrive for Business(R) developed by Microsoft of Redmond, Washington).

[0047] In the second embodiment, process 300 includes aligning a security rule from a security policy to apply to a specified additional computing resource.

[0048] In the third embodiment, process 300 includes displaying a visual indicator associated with a specified managed computing resource that indicates that tracking is in progress.

[0049] In the fourth embodiment, the visual indicator includes a badge or border adjacent to the area of the display unit occupied by the specified managed computing resource, the visual indicator is established when the managed computing resource is launched, and the visual indicator is removed when exiting the managed computing resource or when the user of the computing machine logs out. For example, a user can access a web page associated with his / her employer in a web browser. A visual indicator may appear around the web browser when logging in to an account via the web page. At a later time, the visual indicator can be removed when the user logs out of the account via the web page or closes the web browser.

[0050] In a fifth embodiment, the activities of the computing machine related to the specified managed computing resources and the activities of the computing machine related to the specified additional computing resources include network traffic.

[0051] In a sixth embodiment, the activities of the computing machine related to the specified managed computing resources and the activities of the computing machine related to the specified additional computing resources include Internet browsing.

[0052] In a seventh embodiment, the activities of the computing machine related to the specified managed computing resources and the activities of the computing machine related to the specified additional computing resources include camera or microphone input activities.

[0053] In an eighth embodiment, process 300 includes storing information sent from the computing machine to the tracking service and providing a visual representation of the information sent from the computing machine to the tracking service in response to a user request.

[0054] In a ninth embodiment, the tracking service includes one or more of a cloud-based tracking service, one or more servers, and an administrator computing device associated with a security policy.

[0055] In a tenth embodiment, the security rule includes one or more rules that block a set of operations from a specified managed computing resource to a specified additional computing resource, where the set of operations includes at least one of a drag-and-drop operation, a copy-and-paste operation, a cut-and-paste operation, a keylogging operation, a file download operation, a file upload operation, a file attachment operation, a print operation, an operation to open a specific website, an operation to open a category of websites, an application launch operation, or a screenshot operation. In other words, the security rule can prevent specific operations from a specified managed computing resource to a specified additional computing resource. For example, a user may not be able to drag-and-drop, copy-and-paste, or cut-and-paste content from a specified managed computing resource to a specified additional computing resource. A user may not be able to perform keylogging within a specified managed computing resource and access the logged keys from a specified additional computing resource. A user may not be able to take a screenshot of a specified managed computing resource and place this screenshot within a specified additional computing resource (or view the screenshot via a specified additional computing resource).

[0056] In one exemplary use case, a user opens, on her desktop computer, a work file (a word processing document containing a draft of a real estate purchase contract for a client) and a personal file (a word processing document containing a letter to the user's grandmother). The real estate purchase contract is surrounded by a green border line and has an oval badge indicating that it is a work file, a computing resource that is being managed. The letter to the grandmother is not surrounded by such a border line. The user attempts to copy text from one part of the draft of the real estate purchase contract to another part of the draft of the real estate purchase contract and is able to do so. Next, the user opens the letter to the grandmother and presses a shortcut key for paste (e.g., CTRL+V). However, due to the blocking of such pasting by a security rule in the security policy, the text from the draft of the real estate purchase contract is not pasted into the letter to the grandmother. According to some embodiments, the security policy communicates with the driver of the desktop computer, whereby a security rule is enforced to block the pasting of text from the draft of the real estate purchase contract to the letter to the grandmother because the draft of the real estate purchase contract is a computing resource that is being managed and the letter to the grandmother is not a computing resource that is being managed. Using similar techniques, other operations from a managed computing resource to an additional (unmanaged) computing resource can be blocked.

[0057] Figure 3 shows exemplary blocks of process 300, but in some embodiments, process 300 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in Figure 3. Additionally or alternatively, two or more of the blocks of process 300 may be executed in parallel.

[0058] Figures 4A-4B show exemplary screens 400A and 400B that visually depict resources that are (e.g., by a security policy) tracked and resources that are not tracked. Although screens 400A and 400B are shown, it should be noted that other display devices or display units (e.g., projectors, monitors, etc.) may be used instead of a screen.

[0059] As shown in FIG. 4A, screen 400A displays business computing resource 402A and personal computing resource 404A. Business computing resource 402A is tracked based on the security policy of the associated business, while personal computing resource 404A is not tracked and is not covered by the security policy. As shown in FIG. 4A, business computing resource 402A is the dominant computing resource (e.g., because it is the last selected computing resource) and partially obscures personal computing resource 404A. As shown, business computing resource 402A is surrounded by a boundary line 406A and has an adjacent badge 408A.

[0060] As shown in FIG. 4B, similar to FIG. 4A, screen 400B displays business computing resource 402B and personal computing resource 404B. However, in screen 400B, personal computing resource 404B is the dominant computing resource (e.g., because it is the last selected computing resource) and partially obscures business computing resource 404B. As shown, business computing resource 402B is surrounded by a boundary line 406B and has an adjacent badge 408B.

[0061] Computing resources (e.g., windows) that are open in a computing machine can be arranged in a dominance stack from the most dominant to the least dominant (e.g., in a last-in-first-out data structure, the last selected computing resource is the most dominant and is at the top of the stack, the second last selected computing resource is the second most dominant and is second from the top of the stack, etc.). The boundary lines 406A / 406B and / or badges 408A / 408B can have the same position in the dominance stack as the business computing resources 402A / 402B. Thus, as shown in FIG. 4A, when the business computing resource 402A covers the personal computing resource 404A (e.g., the business computing resource 402A is closer to the top of the stack because it was more recently selected), the boundary line 406A or badge 408A can also cover the personal computing resource 404A. As shown in FIG. 4B, when the personal computing resource 404B covers the business computing resource 402B (e.g., the personal computing resource 404B is closer to the top of the stack because it was more recently selected), the personal computing resource 404B can also cover the boundary line 406B or badge 408B.

[0062] Both the business computing resources 402A / 402B and the personal computing resources 404A / 404B can be associated with the native computing environment of the computing machine associated with the screen 400A / 400B.

[0063] The boundary lines 406A / 406B and / or badges 408A / 408B indicate that the security policy is applicable to the business computing resources 402A / 402B. Since the personal computing resources 404A / 404B do not have boundary lines and / or badges, viewers of the screens 400A / 400B can visually determine that the security policy is not applicable to the personal computing resources 404A / 404B.

[0064] In screen 400A, the boundary line 406A obscures the personal computing resource 404B because the business computing resource 402A is dominant over the personal computing resource 404B (e.g., in a stack of computing resources, e.g., in a window in some Microsoft(R) operating systems). However, in screen 400B, the personal computing resource 404B obscures the boundary line 406B because the personal computing resource 404B is dominant over the business computing resource 402B (e.g., in a stack of computing resources, e.g., in a window in some Microsoft(R) operating systems).

[0065] The business computing resource 402A is subject to a security policy (e.g., associated with the business), while the personal computing resources 404A / 404B are not subject to the security policy. For example, the business can be a law firm, and the business computing resource can be a contract being drafted by a lawyer in the law firm. The personal computing resource can be a personal photo of the lawyer's family. The boundary lines 406A / 406B identify the computing resources that are subject to the security policy. As a result, the user of the screens 400A / 400B can quickly identify which of the displayed computing resources are subject to the security policy and which are not.

[0066] When the badges 408A / 408B are selected (e.g., by a mouse click or a touch on a touch screen, or alternatively, by clicking the mouse while the cursor is positioned over the badges 408 / 408B), they display information regarding the security policy (e.g., what actions the user of the screens 400A / 400B is permitted or not permitted to take with respect to the business computing resources 402A / 402B).

[0067] In some embodiments, the boundary lines 406A / 406B occupy pixels outside the business computing resources 402A / 402B that are within a threshold distance (e.g., n pixels, where n is a positive integer) from the edges of the business computing resources 402A / 402B and not occupied by the badges 408A / 408B.

[0068] In some embodiments, the business computing resources 402A / 402B and the personal computing resources 404A / 404B displayed on the screens 400A / 400B are each associated with a display priority value (e.g., based on the time the displayed computing resource was last selected). The boundary lines 406A / 406B include pixels not occupied by computing resources having a higher priority value than the business computing resources 402A / 402B (e.g., selected after the last selection of the specified managed computing resource). For example, in screen 400A, the business computing resource 402A has a higher priority value than the personal computing resource 404A. As a result, the boundary line 406A covers the personal computing resource 404A. In contrast, in screen 400B, the business computing resource 402B has a lower priority value than the personal computing resource 404B. As a result, the personal computing resource 404B covers the boundary line 404B.

[0069] In some embodiments, the business computing resource 402A can be dragged along the screen 400A (e.g., the user can select the title bar of the business computing resource 402A using a mouse and move the mouse along the screen 400A. Alternatively, if the screen 400A is a touch screen, the user can select the title bar using a finger or a stylus on the touch screen 400A and move the finger or the stylus along the touch screen 400A). The processing circuitry in the computing machine associated with the screen 400A can recompute the position of the boundary line 406A and / or the badge 408A in a discrete manner once every n milliseconds or based on an operating system window event, where n is a predetermined positive number. As a result, the processing circuitry (e.g., a central processing unit or a graphics processing unit) cannot become overloaded by calculating the position of the boundary line 406A and / or the badge 408A each time the business computing resource 402A is dragged.

[0070] In conjunction with FIGS. 4A-4B, some embodiments are described where business computing resources are subject to a security policy and personal computing resources are not subject to the security policy. However, any pre-defined computing resource can be substituted for the business computing resources that are subject to the security policy and the personal computing resources that are not subject to the security policy.

[0071] For example, when a parent shows a movie to a child using screen sharing techniques, a security policy may not be applied to movies suitable for children under 13 years old (similar to the above-described personal computing resources), and a security policy may be applied to movies suitable for children aged 13 - 17 years old (similar to the above-described business computing resources). Using the techniques disclosed herein, a parent may be able to show a G-rated movie suitable for a child under 13 years old to the child without interference from the security policy. When a parent wishes to show a PG-13 rated movie suitable for a child aged 13 - 17 years old to the child, the security policy may be applied. The security policy can, for example, prevent showing a PG-13 movie, notify the other parent when showing a PG-13 rated movie, and require the parent to take additional affirmative steps (e.g., typing a password or the reason for showing a PG-13 movie in a pop-up window) to show a PG-13 movie.

[0072] As described above, the boundary lines 406A / 406B and badges 408A / 408B indicate that the resources associated with the boundary lines 406A / 406B and badges 408A / 408B are covered by the security policy. However, the boundary lines 406A / 406B and badges 408A / 408B may be used to separate other resources. For example, the boundary lines 406A / 406B and badges 408A / 408B may be used to separate business computing resources and personal computing resources, where the security policy is not applied to both business computing resources and personal computing resources. The computing machine that displays the screens 400A / 400B can identify a given computing resource as a personal computing resource or a business computing resource based on at least one of: the location of the computing resource in a directory of the file system, the cloud storage location, the application associated with the computing resource, the file type of the computing resource, or the source of the computing resource (e.g., email, browser, network-based storage, etc.).

[0073] FIG. 5 is a flowchart of an exemplary process associated with visually indicating a resource to be tracked. In some embodiments, one or more of the process blocks of FIG. 5 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more of the process blocks of FIG. 5 may be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more of the process blocks of FIG. 5 may be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128.

[0074] As shown in FIG. 5, process 500 can include storing, in a computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy (block 510). For example, as described above, a computing machine can store a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy.

[0075] As further shown in FIG. 5, process 500 can include causing a display unit coupled to a computing machine to display, at a first display position, all or a portion of a designated managed computing resource from among a plurality of managed computing resources, via the native computing environment of the computing machine (block 520). For example, as described above, a computing machine can cause a display unit coupled to the computing machine to display, at a first display position, all or a portion of a designated managed computing resource from among a plurality of managed computing resources, via the native computing environment of the computing machine.

[0076] As further shown in FIG. 5, process 500 can include causing the display unit to display a visual indicator that a designated managed computing resource is associated with a security policy at a display position calculated based on the first display position (block 530). For example, as described above, a computing machine can cause the display unit to display a visual indicator that a designated managed computing resource is associated with a security policy at a display position calculated based on the first display position.

[0077] As further shown in FIG. 5, process 500 can include applying a security rule from the security policy to the designated managed computing resource (block 540). For example, as described above, a computing machine can apply a security rule from the security policy to the designated managed computing resource.

[0078] Process 500 can include additional embodiments such as any single embodiment or any combination of embodiments related to one or more other processes described below and / or elsewhere in this specification.

[0079] According to some embodiments, additional computing resources can also be displayed on a display unit. The additional display unit may have no visual indicator. As a result, a user of a computing machine may be able to easily determine which computing resources are (or are not) associated with a security policy while browsing the display unit.

[0080] In a first embodiment, the additional computing resources include personal computing resources, the managed computing resources include business computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0081] In a second embodiment, the additional computing resources include a first type of computing resources, the managed computing resources include a second type of computing resources for which an entity (e.g., a user or an organization) desires enhanced security, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0082] In a third embodiment, the visual indicator includes a badge proximate to an edge of a first display location, and the badge indicates that the security policy is applicable to a managed computing resource specified.

[0083] In a fourth embodiment, process 500 includes receiving a signal representing a user selection of a badge and, in response to the user selection of the badge, causing a display unit to display information regarding a security policy applicable to a computing machine.

[0084] In a fifth embodiment, the visual indicator includes a boundary line, the boundary line includes pixels, the pixels are outside of a first display position and within a threshold distance from an edge of the first display position, and are not occupied by a badge associated with the visual indicator.

[0085] In a sixth embodiment, a plurality of computing resources are displayed on a display unit, each displayed computing resource is associated with a display priority value based on the time when the displayed computing was last selected, and the boundary line includes pixels not occupied by a computing resource selected after the last selection of a specified managed computing resource.

[0086] In a seventh embodiment, process 500 includes receiving, in a processing circuit of a computing machine, a signal representing dragging a specified managed computing resource along a display unit, and using the processing circuit to recalculate the position of the boundary line in a discrete manner once every n microseconds or based on an operating system window event, where n is a predetermined positive number.

[0087] In an eighth aspect, process 500 includes generating a pop-up or an alert on a display by a specified managed computing resource and causing a display of a boundary line around the pop-up or the alert on the display.

[0088] In a ninth embodiment, process 500 includes receiving, at a computing machine, a user request to perform an action that violates a security rule, and in response to an additional affirmative act by the user, which includes verifying that the user desires to perform the action based on settings stored in conjunction with a security policy and provided by an administrator of the security policy, permitting the user to perform the action that violates the security rule.

[0089] In a tenth embodiment, process 500 includes causing a display unit to display, at a second display location, all or a portion of a specified additional computing resource from among a plurality of additional computing resources via a native computing environment of the computing machine, causing the display unit to display a visual indicator in association with the specified additional computing resource, and causing a security rule from a security policy to be applied to the specified additional computing resource.

[0090] In an eleventh embodiment, process 500 includes causing a display unit coupled to the computing machine to display indicia of a plurality of computing resources open on the computing device at a predefined display location via a native computing environment of the computing machine, wherein the indicia of the managed computing resources is coupled with a visual symbol indicating that the managed computing resources are associated with a security policy.

[0091] In a twelfth embodiment, the indicia of the additional computing resources is not coupled with a visual symbol.

[0092] In a thirteenth embodiment, the displayed indicia of the plurality of computing resources includes a task bar or a dock.

[0093] FIG. 5 shows exemplary blocks of process 500, but in some embodiments, process 500 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in FIG. 5. Additionally or alternatively, two or more of the blocks of process 500 may be executed in parallel.

[0094] In some embodiments, multiple computing resources (e.g., windows or files) associated with the same application may be open simultaneously. For example, a user of a computing machine having a single word processing application (e.g., Microsoft Word(R) or Apache OpenOffice Writer(R)) may have two word processing files open simultaneously - a patent application document associated with a business security policy (or any other security policy), and a personal letter document not associated with the business security policy (e.g., the patent application document may be present in a business directory of the file system while the personal letter document may be present in a personal directory of the file system). The patent application document may be coupled with a visual indicator (e.g., a border or a badge), while the personal letter document may not be coupled with a visual indicator. Thus, the user may be able to easily determine which security settings apply to the resources he / she has open on the computing machine. Typically, a computing machine runs a single instance of an application. To create a separate instance of the same application, some embodiments force the computing machine to emulate all operating system processes and operating system resources (e.g., global objects, remote procedure calls, etc.) associated with the application separately for personal and business resources. This is shown, for example, in FIG. 10, where an emulated registry and emulated global objects are used instead of the native computing environment's default registry and global objects within the work zone.

[0095] In some embodiments, business computing resources and personal computing resources (or other computing resources covered / not covered by a security policy) can be visually separated (and, in some embodiments, separated in the file system). For example, a display unit coupled to a computing machine can display a business visual container (e.g., a box on the screen) from which business computing resources can be accessed. Personal computing resources may be displayed outside the business visual container or may be accessed via a start menu, file explorer, etc. Additionally, some business computing resources may also, in some cases, be accessed via a start menu, file explorer, etc. This can be done by emulating some subsystems that are intended to be shared by all user-mode applications. By creating an undocumented emulation subsystem at the kernel and user-mode levels and keeping compatibility for several years with different operating systems (e.g., Microsoft Windows(R)) applications, business computing resources are separated from personal computing resources while interacting with the native operating system concept (i.e., maintaining a familiar user experience when double-clicking a mouse when the cursor is hovering over an icon associated with a file). In some embodiments, the operations described herein are performed in real-time without affecting the performance of the application, the user experience, and the security of the application and operating system.

[0096] FIG. 6 shows an exemplary system 600 that can restrict operations according to a security policy, according to some embodiments. System 600 can include all or a portion of the components of computing machine 100 of FIG. 1.

[0097] As shown, system 600 stores a security policy 602 that includes security rules 604. The security policy is applicable to managed resources 614 (and other managed resources), but not to unmanaged resources 616 (and other unmanaged resources). Each of managed resources 614 and unmanaged resources 616 is a computing resource. Managed resources 614 and / or unmanaged resources 616 can be files and / or applications. Security policy 614 can be enforced using a security policy enforcement engine 610. As shown in FIG. 6, the system includes operating system (OS) resources 612. OS resources 612 can include a controller (e.g., a driver) associated with an input device or an output device coupled to system 600. OS resources 612 can be a driver or other hardware controller, such as a keyboard driver, a mouse driver, a touch screen driver, a display driver, etc. OS resources can be computing resources.

[0098] FIG. 6 shows the processing of operation requests 606 and 608. As shown, operation request 608 is associated with unmanaged resource 616, but not with managed resource 614. Operation request 608 is provided directly to OS resources 612 and / or unmanaged resource 616.

[0099] The action request 606 is associated with the managed resource 614 (and in some cases, also with the unmanaged resource 616). Based on the action request 606 being associated with the unmanaged resource 616, the action request 606 is intercepted by the security policy enforcement engine 610 and modified before being provided to the OS resource 612 and / or the managed resource 614 (and in some cases, the unmanaged resource 616). For example, as described in more detail in conjunction with FIG. 8, if the action request 606 is for a screen capture (e.g., screen sharing or screenshot) operation, the security policy enforcement engine 610 can cause a portion of the screen associated with the managed resource 614 to be obscured and / or watermarked within the captured image.

[0100] In some embodiments, the managed resources including the managed resource 614 are business resources. The unmanaged resources including the unmanaged resource 616 are personal computing resources. The managed resources and / or unmanaged resources include files and / or applications. The security rules 604 from the security policy 602 are applied to a plurality of managed resources and not applied to a plurality of unmanaged resources.

[0101] The managed resources can be mapped to a specific file type, file source, or directory within the file system. The unmanaged resources can include resources that are not mapped to these file types, file sources, or directories within the file system. The security policy 602 can include security rules 604 that prevent the system 600 from taking certain actions with respect to the managed resources (e.g., the managed resources may not be able to be copied in a screen capture operation without first receiving affirmative approval (e.g., via a pop - up window) from a user of the system 600).

[0102] System 600 receives a signal representing an operation request 606 or 608. The signal can be received via an input device of System 600, such as a keyboard, mouse, or touch screen. Alternatively, the signal may be received over a network.

[0103] When the signal is received, System 600 determines whether a specified operation is associated with a managed computing resource 614 among a plurality of managed computing resources, based on the active computing resources and other computing resources that are open in the computing machine. If not associated, operation request 608 is provided to OS resources 612 and / or unmanaged resources 616 without accessing the security policy enforcement engine 610.

[0104] In response to determining that the specified operation 606 is associated with a managed computing resource 614, System 600 provides a request for the specified operation 606 to the security policy enforcement engine 610. The security policy enforcement engine 610 intercepts the request. The security policy enforcement engine 610 adjusts the state of the operation request 606 or the managed resource 614 based on the security rules 604 in the security policy 602 before providing the request to the OS resources 612 and / or the managed resource 614.

[0105] In some cases, operation request 606 is associated with both a managed resource 614 and an unmanaged resource 616. After System 600 adjusts the state of operation request 606 or one or more of the plurality of managed resources including the managed resource 614, it provides the request to the OS resources 612, the managed resource 614, and the unmanaged resource 616.

[0106] In some embodiments, the operation request 606 is for a copy operation. The active computing resources in the system 100 are the managed resources 614. The security policy enforcement engine 610 intercepts the data copied by the copy operation based on the security rule 604 in the security policy 602. The intercepted data is accessible via a plurality of managed computing resources, but not via a plurality of unmanaged computing resources.

[0107] In response to a subsequent paste operation, the system 600 permits access to the intercepted data for responding to the paste operation request if the paste operation request is associated with one of the plurality of managed computing resources. The system 600 denies access to the intercepted data for responding to the paste operation request if the paste operation request is not associated with any of the plurality of managed computing resources.

[0108] In some embodiments, the operation request 606 is for keyboard input. The active computing resources are the managed resources 614. The security policy enforcement engine 610 blocks access to the keyboard input provided to the managed resource 616 by unmanaged resources including the unmanaged resource 616 based on the security rule 604 in the security policy 602.

[0109] In some embodiments, the operation request 606 is for a drag-and-drop operation. The active computing resources associated with the start of the drag-and-drop operation are the resources 614 to be managed. The security policy enforcement engine 610, based on the security rules 604 in the security policy 602, ensures that data copied by the drag-and-drop operation is accessible via a plurality of managed computing resources but not via a plurality of unmanaged computing resources.

[0110] The drag-and-drop operation can end at a destination computing resource. The security policy enforcement engine 610 grants access to respond to the drag-and-drop operation request if the destination computing resource is one of the plurality of resources to be managed. The security policy enforcement engine 610 denies access to respond to the drag-and-drop operation request if the destination computing resource is not one of the plurality of resources to be managed.

[0111] In some embodiments, the operation request 606 is for a screen capture (e.g., screenshot or screen sharing) operation. The security policy enforcement engine 610, based on the security rules 604 in the security policy 602, blocks or watermarks screen captures of screen areas associated with managed resources while allowing screen captures of screen areas not associated with managed resources. Watermarking includes covering the screen area associated with the computing resource with a representation of the security policy (e.g., the business logo associated with the security policy).

[0112] For example, the security policy enforcement engine 606 determines whether the managed resource 614 for which screen capture is to be blocked utilizes graphics processing unit (GPU) hardware acceleration. If the managed resource 614 utilizes hardware acceleration, the security policy enforcement engine 610 causes the GPU to obscure or watermark the area associated with the managed resource 614 on the display unit coupled to the system 600 during a screen capture operation. If the managed resource 614 does not utilize hardware acceleration, the security policy enforcement engine 610 obscures or waters down the representation of the managed resource 614 in the output of the screen capture operation. If the managed resource 614 does not utilize hardware acceleration, the security policy enforcement engine 610 suspends the obscuring and watermarking of the area associated with the managed resource 614 on the display unit.

[0113] As used herein, the term "hardware acceleration" can refer to a process that, among other things, enables an application to offload a particular computing task onto a dedicated hardware component within a computer system, allowing for higher efficiency than would be possible with software running solely on a general-purpose central processing unit (CPU). For example, a visualization process can be offloaded onto a GPU to enable faster and higher-quality playback of videos and games, while freeing up the CPU to perform other tasks.

[0114] In some embodiments, some computing resources (e.g., computing resources in a download or email attachment directory) can be separated (e.g., to prevent software in these computing resources from accessing other computing resources such as managed resources 614 and unmanaged resources 616 in system 600). When an operation request attempts to access a separated computing resource, the operation request can be processed by the security policy enforcement engine 610 before being provided to the OS resources 612 and / or the separated computing resource.

[0115] FIG. 7 shows a table 700 of operations that can be permitted or blocked by a security policy according to some embodiments. As shown, table 700 applies to copy / paste or drag-and-drop operations. As shown in FIG. 7, when the source computing resource is a managed computing resource and the destination computing resource is a managed computing resource, the operation is permitted. When the source computing resource is a managed computing resource and the destination computing resource is an unmanaged computing resource, the operation is blocked. When the source computing resource is an unmanaged computing resource and the destination computing resource is a managed computing resource, the operation is permitted. When the source computing resource is an unmanaged computing resource and the destination computing resource is an unmanaged computing resource, the operation is permitted.

[0116] FIG. 8 shows exemplary inputs and outputs of a screen capture operation according to some embodiments. As shown, the input to the screen capture operation is screen 800. Screen 800 displays visual output from managed computing resources 802 and unmanaged computing resources 804. As a result of the screen capture operation, an image 806 is obtained. As shown, image 806 includes a block 810 corresponding to the visual output from unmanaged resource 804. Block 808 corresponds to the visual output from managed computing resources 802. As shown, block 808 is obscured or watermarked. In some embodiments, block 808 can include all or a portion of a company logo or other visual information different from the visual output from managed resource 802. In some embodiments, block 808 can include the background of the screen as if the managed computing resources 802 were not open on the screen. As a result, the user can be prevented from obtaining a screen shot or screen sharing data from the managed resources. In some cases, the user may be able to override the obscuring or watermarking of the visual output from all or a portion of the managed resources.

[0117] FIG. 9 is a flowchart of an exemplary process 900 associated with operation constraints based on a security policy. In some embodiments, one or more of the process blocks of FIG. 9 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more of the process blocks of FIG. 9 may be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more of the process blocks of FIG. 9 may be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128.

[0118] As shown in FIG. 9, process 900 can include storing, in a computing machine, a plurality of managed computing resources and a plurality of unmanaged computing resources, where the plurality of managed computing resources are associated with a security policy (block 910). For example, as described above, a computing machine can store, in the computing machine, a plurality of managed computing resources and a plurality of unmanaged computing resources, where the plurality of managed computing resources are associated with a security policy.

[0119] As further shown in FIG. 9, process 900 can include receiving, in a computing machine, a signal representing a request for a specified operation (block 920). For example, a computing machine can receive, in the computing machine, a signal representing a request for a specified operation, as described above.

[0120] As further shown in FIG. 9, process 900 can include determining (block 930) whether a specified action is associated with a managed computing resource from among a plurality of managed computing resources, based on the active computing resources and other computing resources that are open on the computing machine when the signal is received. For example, as described above, the computing machine can determine whether a specified action is associated with a managed computing resource from among a plurality of managed computing resources, based on the active computing resources and other computing resources that are open on the computing machine when the signal is received.

[0121] As further shown in FIG. 9, in response to determining that the specified action is associated with a managed computing resource, process 900 can include providing a request for the specified action to a security policy enforcement engine, and the security policy enforcement engine intercepts the request (block 940). For example, as described above, the computing machine can provide a request for the specified action to a security policy enforcement engine in response to determining that the specified action is associated with a managed computing resource, and the security policy enforcement engine intercepts the request.

[0122] As further shown in FIG. 9, process 900 can include adjusting the request or status of one or more specified operations of a plurality of managed computing resources before providing a request to an operating system resource or a managed computing resource, using a security policy enforcement engine and based on security rules in the security policy (block 950). For example, as described above, a computing machine can adjust the request or status of one or more specified operations of a plurality of managed computing resources before providing a request to an operating system resource or a managed computing resource, using a security policy enforcement engine and based on security rules in the security policy.

[0123] As further shown in FIG. 9, process 900 can include providing a request to an operating system resource or a managed computing resource (block 960). For example, as described above, a computing machine can provide a request to an operating system resource or a managed computing resource.

[0124] Process 900 can include additional embodiments, such as any single embodiment or any combination of embodiments related to one or more other processes described below and / or elsewhere in this specification.

[0125] In the first embodiment, the process 900 includes that the computing resources to be managed include organizational computing resources, the unmanaged computing resources include personal computing resources, the multiple managed computing resources and the multiple unmanaged computing resources include files, cloud file storage access, applications, or websites, and the security rules from the security policy are applied to the multiple managed computing resources and not applied to the multiple unmanaged computing resources.

[0126] In the second embodiment, the process 900 includes matching to adjust a request using a security policy enforcement engine in response to determining that a specified operation is not associated with a managed computing resource. In some cases, the process 900 can include providing a request directly to operating system resources without accessing the security policy enforcement engine in response to determining that a specified operation is not associated with a managed computing resource.

[0127] In the third embodiment, the process 900 includes determining that a specified operation is associated with both managed and unmanaged computing resources, and after adjusting the request or status of one or more specified operations of the multiple managed computing resources by the security policy enforcement engine, in response to determining that a specified operation is associated with both managed and unmanaged computing resources, providing the request to a device driver, the managed computing resources, and the unmanaged computing resources.

[0128] In a fourth embodiment, the operating system resources include a controller associated with an input device or an output device coupled to a computing machine.

[0129] In some embodiments, the security rules include one or more rules that block a set of operations from a specified managed computing resource to a specified additional computing resource. The set of operations includes at least one of: a drag-and-drop operation, a copy-and-paste operation, a cut-and-paste operation, a keylogging operation, a file download operation, a file upload operation, a file attachment operation, a print operation, an operation to open a specified website, an operation to open a category of websites, an application launch operation, or a screenshot operation.

[0130] In a fifth embodiment, process 900 includes that the specified operation includes a copy operation, the active computing resource is a managed computing resource, the security policy enforcement engine intercepts the data copied by the copy operation based on the security rules in the security policy, and the intercepted data is accessible via a plurality of managed computing resources and not accessible via a plurality of unmanaged computing resources.

[0131] In a sixth embodiment, process 900 responds to a paste operation request that follows a copy operation (e.g., in response to determining that the paste operation is associated with one of a plurality of managed computing resources) based on a security rule in a security policy, and permits access to intercepted data to respond to the paste operation request if the paste operation request is associated with one of a plurality of managed computing resources, and / or (e.g., in response to determining that the paste operation request is not associated with any of a plurality of managed computing resources) denies access to intercepted data to respond to the paste operation request if the paste operation request is not associated with any of a plurality of managed computing resources.

[0132] In a seventh embodiment, process 900 includes that the specified operation includes keyboard input, the active computing resource is a managed computing resource, and the security enforcement engine blocks access by a non-managed computing resource to the keyboard input provided to the managed computing resource based on a security rule in the security policy.

[0133] In an eighth embodiment, process 900 includes that the specified operation includes a drag-and-drop operation, the active computing resource associated with the start of the drag-and-drop operation is a managed computing resource, and the security policy enforcement engine causes the data copied by the drag-and-drop operation to be accessible via a plurality of managed computing resources but not via a plurality of unmanaged computing resources based on a security rule in the security policy.

[0134] In a ninth embodiment, the drag-and-drop operation ends at the destination computing resource, and the method permits access to respond to a drag-and-drop operation request (e.g., in response to determining that the destination computing resource is one of a plurality of managed computing resources) and / or denies access to respond to a drag-and-drop operation request (e.g., in response to determining that the destination computing resource is not one of a plurality of managed computing resources) when the destination computing resource is one of a plurality of managed computing resources.

[0135] In a tenth embodiment, process 900 includes that the specified operation includes a screen capture operation, and the security policy enforcement engine blocks or watermarks a screen capture of a screen area associated with a managed computing resource while permitting a screen capture of a screen area not associated with a managed computing resource based on a security rule in the security policy, and the watermarking includes covering the screen area associated with the computing resource with an expression of the security policy.

[0136] In an eleventh embodiment, the screen capture operation includes a screen shot operation or a screen sharing operation.

[0137] In a twelfth embodiment, process 900 includes determining whether a given managed computing resource, where screen captures are to be blocked, utilizes graphics processing unit (GPU) hardware acceleration. If the given managed computing resource utilizes GPU hardware acceleration (in response to determining that the given managed computing resource utilizes GPU hardware acceleration): Process 900 includes causing the GPU, by a security policy enforcement engine, to mask or watermark an area associated with the given managed computing resource on a display unit coupled to the computing machine during a screen capture operation. If the given managed computing resource does not utilize GPU hardware acceleration (in response to determining that the given managed computing resource does not utilize GPU hardware acceleration): Process 900 includes masking or watermarking the representation of the given managed computing resource in the output of the screen capture operation and omitting masking and watermarking of an area associated with the given managed computing resource on a display unit coupled to the computing machine.

[0138] FIG. 9 shows exemplary blocks of process 900, but in some embodiments, process 900 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in FIG. 9. Additionally or alternatively, two or more of the blocks of process 900 may be executed in parallel.

[0139] FIG. 10 is a block diagram of a computing machine 1000 having a work zone 1004 within a native computing environment 1002, according to some embodiments. As shown, the computing machine 1000 includes a native computing environment 1004. A portion of the native computing environment 1002 is the work zone 1004. As shown, the work zone 1004 is associated with a security policy 1016. The security policy is applied to computing resources within the work zone 1004, but not to computing resources outside the work zone 1004. The work zone 1004 also includes a work network interface engine 1018. The work network interface engine 1018 processes network access requests associated with the work zone 1004 via separate tunnels and / or separate Internet protocol (IP) addresses, based on the security policy 1016. The work network interface engine 1018 can provide a virtual private network (VPN) that computing resources within the work zone 1004 use to access the Internet. Computing resources outside the work zone 1004 may not use the VPN of the work network interface engine 1018.

[0140] As shown, the native computing environment 1002 includes applications such as the word processor app 1006.1 and the spreadsheet app 1008.1 shown outside the work zone 1004. When these applications are executed from the work zone 1004, separate instances of applications such as the word processor app 1006.2 and the spreadsheet app 1008.2 are created. The activities of the computing machine 1000 in the word processor app 1006.2 and the spreadsheet app 1008.2 (e.g., the user's activities) are managed by the security policy 1016. However, the activities of the computing machine in the word processor app 1006.1 and the spreadsheet app 1008.1 are not managed by the security policy 1016.

[0141] As shown, the native computing environment 1002 includes personal files / folders 1010.1 and work files / folders 1010.2. The work files / folders 1010.2 exist within the work zone 1004 and are managed by the security policy 1016. The personal files / folders 1010.1 exist outside the work zone 1004 and are not managed by the security policy 1016. According to some embodiments, the personal files / folders 1010.1 and the work files / folders 1010.2 can correspond to different locations in the file system. For example, the personal files / folders 1010.1 may be at C: / personal / *, and the work files / folders 1010.2 may be at C: / work / *, where * corresponds to part of the file address characters of the file system. The work zone 1004 can include the C: / work / * location of the file system where the work files / folders 1010.2 exist.

[0142] As shown, the native computing environment 1002 includes a registry 1014.1 external to the work zone 1004. Within the work zone 1004, the registry is emulated as an emulated registry 1014.2. Similarly, the native computing environment 1002 includes a global object 1012.1 external to the work zone 1004. Within the work zone 1004, the global object is emulated as an emulated global object 1012.2. At runtime, the applications 1006.2, 1008.2 within the work zone 1004 use the emulated registry 1014.2 and the emulated global object 1012.2 instead of the registry 1014.1 and the global object 1012.1. As a result, the objects and registry values accessed by the running applications 1006.2, 1008.2 within the work zone 1004 are managed by the security policy 1016, and separate instances of the applications 1006, 1008 are used both inside and outside the work zone 1004.

[0143] In some embodiments, computing machine 1000 stores within a single user account a plurality of managed computing resources (e.g., work file / folder 1010.2) and a plurality of additional computing resources (e.g., personal file / folder 1010.1). The managed computing resources are associated with security policy 1016, while the unmanaged computing resources are not associated with security policy 1016. Computing machine 1000 executes a first instance of a specified application (e.g., word processor app 1006.1 or spreadsheet app 1008.1) that has no read or write access to any of the plurality of managed computing resources. Computing machine 1000 simultaneously executes a second instance of a specified application (e.g., word processor app 1006.2 or spreadsheet app 1008.2) that accesses at least a portion of the plurality of managed computing resources. Computing machine 1000 applies rules from security policy 1016 to the second instance of the specified application, while refraining from applying rules from security policy 1016 to the first instance of the specified application.

[0144] In some embodiments, computing machine 1000 stores a plurality of managed computing resources (e.g., work file / folder 1010.2) and a plurality of additional computing resources (e.g., personal file / folder 1010.1). The plurality of managed computing resources are associated with security policy 1016. The plurality of managed computing resources are within a managed zone (e.g., work zone 1004). The managed zone includes a portion of data associated with the native computing environment 1002 of computing machine 1000. Computing machine 1000 executes a first instance of a specified application (e.g., word processor app 1006.1 or spreadsheet app 1008.1) outside of the managed zone. The first instance can have read and write access to data outside of the managed zone. The first instance cannot have read or write access to data stored in the managed zone. Computing machine 1000 executes a second instance of a specified application (e.g., word processor app 1006.2 or spreadsheet app 1008.2) within the managed zone at the same time as the first instance. The second instance can have read access to data outside of the managed zone, but cannot have write access. The second instance can have read and write access to data stored in the managed zone. The second instance is executed separately and differently from the first instance. For example, the second instance can utilize the emulated registry 1014.2 and emulated global object 1012.1 of work zone 1004, while the first instance can utilize the registry 1014.1 and global object 1012.1 of native computing environment 1002.

[0145] As used herein, a business can include a business, an organization, or any other entity type. A business can include an organization (e.g., a non-profit or charity), a government entity (e.g., a department dealing with vehicle-related matters or a town tax collector), or an individual entity (e.g., an individual babysitting entity or an individual financial planning entity). A business resource can be any resource that is desirably separated from personal resources by a business, an organization, a government entity, or an individual entity (e.g., a person who desires to separate his / her babysitting entity or computing resources related to financial planning or other types of computing resources).

[0146] FIG. 11 is a flowchart of an exemplary process 1100 associated with a secure computing environment for a mixed-use system of personal and business. In some embodiments, one or more process blocks of FIG. 11 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more process blocks of FIG. 11 may be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more process blocks of FIG. 11 may be performed by one or more components of a computing machine 100 such as a computing machine 100, such as a processor 102, a main memory 104, a static memory 106, a network interface device 120, a video display 110, an alphanumeric input device 112, a UI navigation device 112, a drive unit 116, a signal generation device 118, and an output controller 128.

[0147] As shown in FIG. 11, process 1100 can include storing, within a single user account on a computing machine, a plurality of unmanaged (e.g., personal) computing resources and a plurality of managed (e.g., organizational or business) computing resources, where the plurality of managed computing resources are associated with a security policy (block 1110). For example, as described above, a computing machine can store, within a single user account on the computing machine, a plurality of unmanaged computing resources and a plurality of managed computing resources, where the plurality of business computing resources are associated with a security policy (e.g., an organizational security policy or a business security policy).

[0148] As further shown in FIG. 11, process 1100 can include receiving, from a user of the computing machine, a request to access a specified managed computing resource from among the plurality of managed computing resources (block 1120). For example, as described above, a computing machine can receive, from a user of the computing machine, a request to access a specified managed computing resource from among the plurality of managed computing resources.

[0149] As further shown in FIG. 11, process 1100 can include directly providing access to the specified managed computing resource locally on the computing machine, through the native computing environment of the computing machine (block 1130). For example, as described above, a computing machine can directly provide access to the specified managed computing resource locally on the computing machine, through the native computing environment of the computing machine.

[0150] As further shown in FIG. 11, process 1100 can include causing a display unit to display an indicator that a specified managed computing resource is associated with a security policy at a display position associated with an area of the display unit that displays the specified business computing resource (block 1140). For example, as described above, a computing machine can cause a display unit to display an indicator that a specified business computing resource is associated with a security policy at a display position associated with an area of the display unit that displays the specified managed computing resource.

[0151] As further shown in FIG. 11, process 1100 can include applying a security rule from the security policy to the specified managed computing resource (block 1150). For example, as described above, a computing machine can apply a security rule from the security policy to the specified managed computing resource.

[0152] Process 1100 can include additional embodiments, such as any single embodiment or any combination of embodiments related to one or more other processes described below and / or elsewhere in this specification.

[0153] In a first embodiment, process 1100 receives a request from a user of a computing machine to access a specified unmanaged computing resource from among a plurality of unmanaged computing resources, directly provides access to the specified unmanaged computing resource locally on the computing machine through the native computing environment of the computing machine, causes a display unit to display an indicator that the specified unmanaged computing resource is associated with a business security policy, and causes a security rule from the security policy to be applied to the specified unmanaged computing resource.

[0154] In a second embodiment, the plurality of computing resources are not associated with a security policy.

[0155] In a third embodiment, an administrative computing device external to the computing machine can access a plurality of managed computing resources present on the computing machine and cannot access a plurality of unmanaged computing resources present on the computing machine.

[0156] FIG. 11 shows exemplary blocks of process 1100, but in some embodiments, process 1100 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in FIG. 11. Additionally or alternatively, two or more of the blocks of process 1100 may be executed in parallel.

[0157] FIG. 12 is a flowchart of an exemplary process 1200 associated with a secure computing environment for a hybrid use system. In some embodiments, one or more process blocks of FIG. 12 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more process blocks of FIG. 12 may be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more process blocks of FIG. 12 may be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128.

[0158] As further shown in FIG. 12, process 1200 can include receiving a request (block 1210) to access computing resources existing on a computing machine via a user account in the computing machine. For example, as described above, a computing machine can receive a request to access computing resources existing on the computing machine via a user account in the computing machine.

[0159] As further shown in FIG. 12, process 1200 can include providing access to computing resources locally on a computing machine, directly through the native computing environment of the computing machine (block 1220). For example, as described above, a computing machine can provide access to computing resources locally on the computing machine, directly through the native computing environment of the computing machine.

[0160] As further shown in FIG. 12, process 1200 can include determining that a computing resource is associated with a security policy, where a user account on the computing machine is associated with a plurality of computing resources including the computing resources present on the computing machine, a first portion of the plurality of computing resources is associated with the security policy, and a second portion of the plurality of computing resources is not associated with the security policy (block 1230). For example, as described above, a computing machine can determine that a computing resource is associated with a security policy, where a user account on the computing machine is associated with a plurality of computing resources including the computing resources present on the computing machine, a first portion of the plurality of computing resources is associated with the security policy, and a second portion of the plurality of computing resources is not associated with the security policy.

[0161] As further shown in FIG. 12, in response to determining that a computing resource is associated with a security policy, process 1200 can include causing a display unit to display a visual indication that the computing resource is associated with the security policy, associated with an area of the display unit that displays the computing resource (block 1240). For example, as described above, a computing machine can cause a display unit to display a visual indication that the computing resource is associated with the security policy, associated with an area of the display unit that displays the computing resource, in response to determining that the computing resource is associated with the security policy.

[0162] As further shown in FIG. 12, process 1200 can include applying a security rule from the security policy to the computing resource (block 1250). For example, as described above, a computing machine can apply a security rule from the security policy to the computing resource.

[0163] Process 1200 can include additional embodiments such as any single embodiment or any combination of embodiments related to one or more other processes described below and / or elsewhere in this specification.

[0164] In a first embodiment, the computing resource is a website, application, or file, and the computing machine is one of a laptop computer, desktop computer, mobile phone, or tablet computer.

[0165] In a second embodiment, the security policy is an organizational security policy, and the computing machine stores a set of the organization's computing resources associated with the organizational security policy and a set of personal computing resources not associated with the organizational security policy.

[0166] In a third embodiment, the security rules from the security policy include one or more of blocking the sharing of computing resources, logging the reasons for sharing computing resources, receiving user authentication before sharing computing resources, logging keystrokes while computing resources are selected, and locking computing resources in response to the computing machine being idle for at least a threshold period.

[0167] In a fourth embodiment, sharing includes one or more of printing, screen sharing, transmitting via email or a messaging service, drag and drop, cut and paste, download, upload, attach, print, access a particular website, access a category of websites, launch an application, or take a screenshot.

[0168] In a fifth embodiment, process 1200 includes deactivating one or more security rules from a security policy regarding computing resources in response to a user request and logging the reason for the user request.

[0169] In a sixth embodiment, process 1200 includes receiving an indication of a selection of a visual indication via a graphical user interface (GUI), and in response to the selection of the visual indication, providing information regarding a user's permission for a computing machine to computing resources, or information regarding a security policy, for display.

[0170] In a seventh embodiment, process 1200 includes causing a display unit to simultaneously display computing resources associated with a security policy and additional computing resources not associated with the security policy, where both the computing resources and the additional computing resources are executed through a native computing environment of the computing machine.

[0171] In an eighth embodiment, the visual indicator is displayed on or adjacent to a boundary of an area of a display unit that displays the computing resources.

[0172] FIG. 12 shows exemplary blocks of process 1200, but in some embodiments, process 1200 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in FIG. 12. Additionally or alternatively, two or more of the blocks of process 1200 may be performed in parallel.

[0173] FIG. 13 is a flowchart of an exemplary process 1300 associated with applying a security policy to a portion of an execution instance of an application. In some embodiments, one or more of the process blocks of FIG. 13 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more of the process blocks of FIG. 13 can be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more of the process blocks of FIG. 13 can be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128.

[0174] As shown in FIG. 13, process 1300 can include storing, within a single user account in a computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy (block 1310). For example, as described above, a computing machine can store, within a single user account in the computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy.

[0175] As further shown in FIG. 13, process 1300 can include executing a first instance of a specified application that does not have read and write access to any of a plurality of managed computing resources (block 1320). For example, as described above, a computing machine can execute a first instance of a specified application that does not have read and write access to any of a plurality of managed computing resources.

[0176] As further shown in FIG. 13, process 1300 can include executing a second instance of a specified application that accesses at least a portion of a plurality of managed computing resources, in parallel with the first instance (block 1330). For example, as described above, a computing machine can execute a second instance of a specified application that accesses at least a portion of a plurality of managed computing resources, in parallel with the first instance.

[0177] As further shown in FIG. 13, process 1300 can include applying rules from a security policy to the second instance of the specified application, while withholding application of rules from the security policy to the first instance of the specified application (block 1340). For example, as described above, a computing machine can apply rules from a security policy to the second instance of the specified application, while withholding application of rules from the security policy to the first instance of the specified application.

[0178] Process 1300 can include additional embodiments, such as any single embodiment or any combination of embodiments, related to one or more other processes described below and / or elsewhere in this specification.

[0179] In a first embodiment, process 1300 includes identifying a computing resource as a managed computing resource based on one or more of a location of the computing resource in a directory or file system, a cloud storage location, a rule in a security policy, a process name or path, a Uniform Resource Locator (URL) address, and whether the computing resource is launched from an application launcher associated with a plurality of managed computing resources.

[0180] In a second embodiment, additional computing resources include personal computing resources, managed computing resources include organizational computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0181] In a third embodiment, a first instance of a specified application accesses at least a portion of a plurality of additional computing resources.

[0182] In a fourth embodiment, a second instance of a specified application can have read access but not write access to at least a portion of a plurality of additional computing resources, and when the second instance accesses at least a portion of the plurality of additional computing resources, application of the security policy is based on settings associated with the computing machine.

[0183] In a fifth embodiment, process 1300 includes accessing non-secure computing resources using a third instance of a specified application, and blocking access by the third instance of the specified application to any and all of a plurality of managed computing resources and any and all of a plurality of additional computing resources.

[0184] In a sixth embodiment, process 1300 includes identifying non-secure computing resources based on non-secure computing resources that exist in a download memory region, a memory region associated with an attachment of an email application, or a memory region associated with a web browser.

[0185] In a seventh embodiment, the download memory region includes a download folder, the memory region associated with the web browser includes a download folder, and the memory region associated with an attachment of the email application includes an attachment folder.

[0186] FIG. 13 shows exemplary blocks of process 1300, but in some embodiments, process 1300 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in FIG. 13. Additionally or alternatively, two or more of the blocks of process 1300 may be performed in parallel.

[0187] FIG. 14 is a flowchart of an exemplary process 1400 associated with executing the same application in managed and unmanaged zones. In some embodiments, one or more process blocks of FIG. 14 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more process blocks of FIG. 14 can be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more process blocks of FIG. 14 can be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128.

[0188] As shown in FIG. 14, process 1400 can include storing, in a computing machine, a plurality of managed computing resources and a plurality of additional computing resources (e.g., within a single user account), where the plurality of managed computing resources are associated with a security policy, the plurality of managed computing resources are within a managed zone, and the managed zone includes a portion of data associated with the native computing environment of the computing machine (block 1410). For example, as described above, a computing machine can store, in the computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy, the plurality of managed computing resources are within a managed zone, and the managed zone includes a portion of data associated with the native computing environment of the computing machine.

[0189] As shown in FIG. 14, process 1400 can include executing a first instance of a specified application outside of the zone to be managed, where the first instance can have read and write access to data outside of the zone to be managed, and the first instance cannot have read and write access to data stored within the zone to be managed (block 1420). For example, as described above, a computing machine can execute a first instance of a specified application outside of the zone to be managed, where the first instance can have read and write access to data outside of the zone to be managed, and the first instance cannot have read and write access to data stored within the zone to be managed.

[0190] As further shown in FIG. 14, process 1400 can include executing a second instance of a specified application within the zone to be managed, simultaneously with the first instance, where the second instance can have read access to data outside of the zone to be managed, but cannot have write access, and the second instance can have read and write access to data stored within the zone to be managed, and the second instance is executed separately and differently from the first instance (block 1430). For example, as described above, a computing machine can execute a second instance of a specified application within the zone to be managed, simultaneously with the first instance, where the second instance can have read access to data outside of the zone to be managed, but cannot have write access, and the second instance can have read and write access to data stored within the zone to be managed, and the second instance is executed separately and differently from the first instance.

[0191] Process 1400 can include additional embodiments such as any single embodiment or any combination of embodiments related to one or more other processes described below and / or elsewhere in this specification.

[0192] In a first embodiment, additional computing resources include personal computing resources, managed computing resources include organizational computing resources, and multiple managed computing resources and multiple additional computing resources include files, cloud file storage access, applications, or websites.

[0193] In a second embodiment, process 1400 includes that a second instance of a specified application accesses the network via a managed network interface, a security policy that designates a network or subnet is accessible via the managed network interface, and the managed network interface separates domain name system (DNS) traffic associated with a managed zone.

[0194] In a third embodiment, process 1400 includes that a first instance of a specified application accesses the network via a native network interface of a computing machine rather than a managed network interface, and the managed network interface restricts access by multiple additional resources existing outside the managed zone to network resources associated with the managed zone.

[0195] In a fourth embodiment, process 1400 includes the first instance of the specified application accessing the Component Object Model (COM) of the computing machine, and the second instance of the specified application accessing an emulated COM of a managed zone different from the COM of the computing machine. The COM can be a Distributed Component Object Model (DCOM).

[0196] In a fifth embodiment, process 1400 includes the first instance of the specified application accessing the Remote Procedure Call (RPC) subsystem of the computing machine for inter-process communication, and the second instance of the specified application accessing an emulated RPC subsystem of a managed zone different from the RPC subsystem of the computing machine for inter-process communication.

[0197] In some embodiments, a first instance of a specified application accesses a common app platform application programming interface (API) available to universal applications on a computing machine (e.g., the Universal Windows Platform (UWP) developed by Microsoft of Redmond, Washington). A second instance of the specified application accesses a common app platform API of a managed zone that is different from the common app platform API available to universal applications on the computing machine. The common app platform API can include at least one of: a shell infrastructure host (sihost), a state repository service, a background task infrastructure, a user manager service, an Azure Active Directory (AAD) broker, and an AAD credential manager. The background task infrastructure includes a host activity manager. The user manager service includes an application activation manager and a view manager.

[0198] In a sixth embodiment, process 1400 includes the computing machine storing a set of global objects external to the managed zone, the computing machine storing an emulated set of global objects that emulate the set of global objects within the managed zone, a first instance of the specified application accessing the set of global objects, and a second instance of the specified application accessing the emulated set of global objects.

[0199] In a seventh embodiment, process 1400 includes the computing machine storing, external to the managed zone, a computing machine registry representing settings composed of a hardware device configuration, installed application settings, and operating system settings; the computing machine storing, within the managed zone, an emulated registry that emulates the computing machine registry for applications running within the managed zone; a first instance of a specified application accessing the computing machine registry; and a second instance of the specified application accessing the emulated registry.

[0200] In an eighth embodiment, process 1400 includes the specified application being a file manager application; the first instance being for access to files from a plurality of additional computing resources; and the second instance being for access to files from a plurality of managed computing resources and read-only access to a plurality of additional computing resources. The second instance is for access to files from a plurality of managed computing resources, and the read-only access to the plurality of additional computing resources can be based on a security policy.

[0201] In a ninth embodiment, process 1400 is to access a request to open a selected file via a file explorer of a computing machine, where the file explorer is executed externally to the zone being managed, the file has an associated application, and the file explorer provides access to both files external to the zone being managed and files internal to the zone being managed, determine whether the selected file is from among a plurality of managed computing resources, open the selected file using an instance of the associated application running within the zone being managed if it is determined that the selected file is from among a plurality of managed computing resources, and open the selected file using an instance of the associated application not running within the zone being managed if it is determined that the selected file is not from among a plurality of managed computing resources.

[0202] In a tenth embodiment, the operating system of a computing machine cannot access a plurality of managed computing resources from outside the zone being managed.

[0203] In an eleventh embodiment, the security program is capable of accessing both a managed zone and an unmanaged zone, and the security program includes one or more of an antivirus program, a malware countermeasure program, or a security auditing tool. In some cases, the computing machine identifies a program as a security program based on a data structure (e.g., in a database, another data repository, or the memory of the computing machine) storing known security programs and based on a digital signature associated with the program. In response to the digital signature being associated with one of the known security programs in the data structure, the application associated with the security program sends a message to the driver of the computing machine indicating that the program is capable of accessing both the managed zone and the unmanaged zone. Since a new security program may appear after the security policy is first implemented in the computing machine, the data structure can be dynamically updated based on the known security programs.

[0204] In a twelfth embodiment, process 1400 accesses non-secure computing resources using a restricted instance of a specified application running within a restricted zone, and blocks access by the restricted instance of the specified application to any of a plurality of managed computing resources and to any of a plurality of additional computing resources. The restricted zone can be used for computing resources (e.g., files, cloud file storage access, applications, or websites) that are downloaded from the Internet or received as an email message and are not known to be secure. The restricted zone can restrict access by computing resources within the restricted zone to specific software or hardware of the computing machine. When a computing resource is verified to be secure, the user may be able to move the computing resource from the restricted zone to an unmanaged zone.

[0205] In a thirteenth embodiment, the security program can access a managed zone, an unmanaged zone, and a restricted zone, and the security program includes one or more of an antivirus program, a malware protection program, or a security auditing tool.

[0206] In a fourteenth embodiment, process 1400 identifies non-secure computing resources based on non-secure computing resources present in a download memory area, a memory area associated with an attachment of an email application, or a memory area associated with a web browser.

[0207] In the 15th embodiment, the download memory area includes a download folder, the memory area associated with the web browser includes a download folder, and the memory area associated with the attachment of the email application includes an attachment folder.

[0208] In the 16th embodiment, the computing machine opens an additional application or a website different from the specified application via a second instance. The computing machine executes an additional application or a website within the managed zone. The additional application or the website can have read access to the data outside the managed zone but cannot have write access. The additional application or the website can have read and write access to the data stored in the managed zone.

[0209] In the 17th embodiment, the computing machine opens an additional application or a website different from the specified application via a first instance. The computing machine executes an additional application or a website outside the managed zone. The additional application or the website cannot have read and write access to the data within the managed zone.

[0210] In one exemplary use case, a user launches a spreadsheet application within a managed zone and views a business budget. Also, the user launches the same spreadsheet application outside the managed zone and views a personal ancestry table. Two separate and different instances of the spreadsheet application are opened, one within the managed zone and one outside the managed zone. The business budget includes hyperlinks for purchasing products from suppliers. When the user selects one of the hyperlinks for purchasing a product from a supplier, the computing machine opens the hyperlink within the managed zone in the default web browser for the managed zone. The personal ancestry table includes hyperlinks for the social media websites of the user's relatives. When the user selects a hyperlink for a social media website, the social media page is opened in the default web browser for the unmanaged zone. The managed zone and the unmanaged zone may have different default web browsers.

[0211] Alternatively, the managed zone and the unmanaged zone may have the same default web browser. If the managed zone and the unmanaged zone may have the same default web browser, two different windows of the web browser can be opened. One window (having a website for purchasing products from a provider) can operate within the managed zone, and one window (having a social media page) can operate within the unmanaged zone. The window having a website for purchasing products from a provider can have a stored version of a business credit card (stored within the managed zone, within a wallet application, or within the web browser) that can be used to purchase products. However, the window having a social media website can be made to not have a stored version of a business credit card, thereby preventing the user from accidentally using the business credit card for personal purchase orders placed within the unmanaged zone.

[0212] Figure 14 shows exemplary blocks of process 1400, but in some embodiments, process 1400 may include additional blocks, fewer blocks, different blocks, or blocks arranged differently than those shown in Figure 14. Additionally or alternatively, two or more of the blocks of process 1400 may be executed in parallel.

[0213] FIG. 15 is a flowchart of an exemplary process 1500 associated with displaying an organizational indicator for organizational computing resources according to some embodiments. In some embodiments, one or more of the process blocks of FIG. 15 can be performed by a computing machine (e.g., computing machine 100). In some embodiments, one or more of the process blocks of FIG. 15 may be performed by another device, or by a group of devices separate from or including the computing machine. Additionally or alternatively, one or more of the process blocks of FIG. 15 may be performed by one or more components of computing machine 100, such as processor 102, main memory 104, static memory 106, network interface device 120, video display 110, alphanumeric input device 112, UI navigation device 112, drive unit 116, signal generation device 118, and output controller 128.

[0214] In block 1510, the computing machine stores computing resources, including computing resources to be managed (e.g., organizational or business computing resources), in the memory of the computing machine (e.g., local memory). The computing machine can store both computing resources to be managed (e.g., business files or business software) and unmanaged computing resources (e.g., non-organizational or non-business computing resources such as personal files or personal software). In some examples, the memory of the computing machine stores both computing resources to be managed and unmanaged computing resources. In some cases, the computing resources to be managed and the unmanaged computing resources are mutually exclusive.

[0215] In block 1520, the computing machine receives a request to display computing resources from the computing resources stored in the memory. For example, a user can request to open a file for viewing (and optionally editing) via the graphical user interface of the computing machine.

[0216] In block 1530, the computing machine causes the display of the computing resources within the display area of the display device. The display area can include all or a portion of the display device. The display area can include all or a portion of the display space on the display device. The display area can include a window in some Windows(R) operating systems developed by Microsoft of Redmond, Washington, or a similar display area in another operating system.

[0217] In block 1540, the computing machine determines whether a computing resource is a computing resource for which computing resources are managed based on an identification criterion (e.g., an organizational identification criterion or a business identification criterion). The identification criterion can include at least one of: a computing resource existing in a directory in the file system of the computing machine or a cloud storage unit, the file type of the computing resource, an application associated with the computing resource, a website associated with the computing resource, or a computing resource provided or installed on the computing machine by a specified entity (e.g., an entity associated with an organization or a business). The identification criterion can include the existence of a computing resource within a predefined zone of memory (e.g., an organizational zone or a business zone of memory). The predefined zone has at least one security policy that is applicable to computing resources within the predefined zone and not applicable to computing resources outside the predefined zone. In some cases, the predefined zone has at least one network interface that is accessible to computing resources within the predefined zone and not accessible to computing resources outside the predefined zone. In some embodiments, the identification criterion includes a computing resource that is accessed via a managed launcher (e.g., an organizational launcher or a business launcher) in the computing machine or includes data from an additional managed computing resource. The additional managed computing resource can include at least one of: a file, an email, a software as a service (SaaS) application or website, or a network destination or subnet. As used herein, the term "subnet" encompasses its ordinary and customary meaning. A subnet can include a subnetwork that is a component of another network.

[0218] If the computing resource is a computing resource that is managed, process 1500 continues to block 1550. If the computing resource is not a resource that is managed, process 1500 continues to block 1560.

[0219] In block 1550, when it is determined that the computing resource is a computing resource that is managed, the computing machine causes an indicator (e.g., an organization indicator or a business indicator) adjacent to an edge of the display area to be displayed. The indicator indicates that the computing resource is a computing resource that is managed. The indicator can include a boundary line (e.g., boundary lines 406A, 406B) that occupies pixels outside the display area that are at a distance of n pixels or less from the display area, where n is a positive integer and the boundary line has a predefined color or design. The indicator can include a badge (e.g., badges 408A, 408B) having a circular or oval shape that covers a portion of the edge of the display area. After block 1550, process 1500 ends.

[0220] In block 1560, when it is determined that the computing resource is not a computing resource that is managed, the computing machine refrains from causing a managed indicator to be displayed. After block 1560, process 1500 ends.

[0221] Some embodiments are described as numbered examples (e.g., Example 1, 2, 3, etc.). These are provided merely as examples and do not limit the technology disclosed herein.

[0222] Example 1 involves: storing, in a computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy; displaying, on a display unit coupled to the computing machine via the native computing environment of the computing machine, all or a portion of the designated managed computing resources and all or a portion of the designated additional computing resources simultaneously; applying a security rule from the security policy to the designated managed computing resources, where applying the security rule includes at least facilitating tracking, by a tracking service, of the activities of the computing machine with respect to the designated managed computing resources; and causing the tracking service to track the activities of the computing machine with respect to the designated additional computing resources and with respect to activities on the computing machine that are not associated with one or more of the plurality of managed computing resources.

[0223] In Example 2, the subject matter of Example 1 includes that the additional computing resources include personal computing resources, the managed computing resources include business computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0224] In Example 3, the subject matter of Examples 1 - 2 includes causing a security rule from the security policy to be applied to the designated additional computing resources.

[0225] In Example 4, the subject matter of Examples 1 to 3 includes displaying a visual indicator that indicates that tracking is in progress, in association with the specified managed computing resource.

[0226] In Example 5, the subject matter of Example 4 includes that the visual indicator includes a badge or border adjacent to the area of the display unit occupied by the specified managed computing resource, the visual indicator is established when the managed computing resource is activated, and the visual indicator is removed when exiting the managed computing resource or when the user of the computing machine logs out.

[0227] In Example 6, the subject matter of Examples 1 to 5 includes that the activity of the computing machine related to the specified managed computing resource and the activity of the computing machine related to the specified additional computing machine include network traffic.

[0228] In Example 7, the subject matter of Examples 1 to 6 includes that the activity of the computing machine related to the specified managed computing resource and the activity of the computing machine related to the specified additional computing machine include Internet browsing.

[0229] In Example 8, the subject matter of Examples 1 to 7 includes that the activity of the computing machine related to the specified managed computing resource and the activity of the computing machine related to the specified additional computing machine include camera or microphone input activity.

[0230] In Example 9, the subject matter of Examples 1 through 8 includes storing information transmitted from a computing machine to a tracking service; and providing a visual representation of the information transmitted from the computing machine to the tracking service in response to a user request.

[0231] In Example 10, the subject matter of Examples 1 through 9 includes the tracking service including one or more of a cloud-based tracking service, one or more servers, and an administrator computing device associated with a security policy.

[0232] Example 11 is: in a computing machine, storing a plurality of managed computing resources and a plurality of additional computing resources, wherein the plurality of managed computing resources are associated with a security policy; displaying, on a display unit coupled to the computing machine via a native computing environment of the computing machine, all or a portion of a specified managed computing resource from among the plurality of managed computing resources at a first display position; displaying, on the display unit, at a display position calculated based on the first display position, a visual indicator that the specified managed computing resource is associated with a security policy; and applying a security rule from the security policy to the specified managed computing resource.

[0233] In Example 12, the subject matter of Example 11 includes the additional computing resources including personal computing resources, the managed computing resources including business computing resources, and the plurality of managed computing resources and the plurality of additional computing resources including files, cloud file storage access, applications, or websites.

[0234] In Example 13, the subject matter of Examples 11-12 includes that additional computing resources include a first type of computing resource, managed computing resources include a second type of computing resource for which an entity desires enhanced security, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0235] In Example 14, the subject matter of Examples 11-13 includes that a visual indicator includes a badge proximate an edge of a first display location, and the badge indicates that a security policy is applicable to a managed computing resource for which the security policy is specified.

[0236] In Example 15, the subject matter of Example 14 includes receiving a signal representing a user selection of a badge; and in response to the user selection of the badge, causing a display unit to display information regarding a security policy applicable to a computing machine.

[0237] In Example 16, the subject matter of Examples 11-15 includes that a visual indicator includes a border line, the border line includes pixels, the pixels are outside a first display location, within a threshold distance from an edge of the first display location, and are not occupied by a badge associated with the visual indicator.

[0238] In Example 17, the subject matter of Example 16 includes that a plurality of computing resources are displayed on a display unit, each displayed computing resource is associated with a display priority value based on a time at which the displayed computing resource was last selected, and the border line includes pixels not occupied by a computing resource selected after a last selection of a specified managed computing resource.

[0239] In Example 18, the subject matter of Examples 16 to 17 is to receive, in a processing circuit of a computing machine, a signal representing dragging a specified managed computing resource along a display unit; and to recalculate, using the processing circuit, the position of the boundary line in a discrete manner once every n microseconds or based on an operating system window event, where n is a predetermined positive number.

[0240] In Example 19, the subject matter of Examples 16 to 18 includes generating a pop-up or an alert on a display by a specified managed computing resource; and causing a display of a boundary line around the pop-up or the alert on the display.

[0241] In Example 20, the subject matter of Examples 11 to 19 is to receive, in a computing machine, a user request to perform an action that violates a security rule; and to allow the user to perform an action that violates a security rule in response to an additional affirmative action by the user, by confirming that the user desires to perform the action based on settings stored together with a security policy and provided by an administrator of the security policy.

[0242] In Example 21, the subject matter of Examples 11 to 20 is to cause a display unit to display all or a portion of a specified additional computing resource from among a plurality of additional computing resources at a second display position via a native computing environment of a computing machine; to cause the display unit to display a visual indicator in association with the specified additional computing resource; and to cause a security rule from a security policy to be applied to the specified additional computing resource.

[0243] In Example 22, the subject matter of Examples 11 to 21 includes causing a display unit coupled to a computing machine to display indicia of a plurality of computing resources open on a computing device at a predefined display position via a native computing environment of the computing machine, and the indicia of the managed computing resources is combined with a visual symbol indicating that the managed computing resources are associated with a security policy.

[0244] In Example 23, the subject matter of Example 22 includes that the indicia of additional computing resources are not combined with a visual symbol.

[0245] In Example 24, the subject matter of Examples 22 to 23 includes that the displayed indicia of the plurality of computing resources includes a task bar or a dock.

[0246] Example 25 is: storing, within a single user account on a computing machine, a plurality of unmanaged computing resources and a plurality of managed computing resources, wherein the plurality of managed computing resources are associated with a security policy; receiving, from a user of the computing machine, a request to access a specified managed computing resource from among the plurality of managed computing resources; directly providing access to the specified managed computing resource locally on the computing machine through the native computing environment of the computing machine; causing a display unit to display an indicator that the specified managed computing resource is associated with a security policy at a display position associated with a region of the display unit that displays the specified managed computing resource; and applying a security rule from the security policy to the specified managed computing resource.

[0247] In Example 26, the subject matter of Example 25 involves receiving, from a user of a computing machine, a request to access a specified unmanaged computing resource from among a plurality of unmanaged computing resources; directly providing access to the specified unmanaged computing resource locally on the computing machine through the native computing environment of the computing machine; causing a display unit to display an indicator that the specified unmanaged computing resource is associated with a security policy; and causing security rules from the security policy to be applied to the specified personal computing resource.

[0248] In Example 27, the subject matter of Examples 25 - 26 includes that a plurality of unmanaged computing resources are not associated with a security policy.

[0249] In Example 28, the subject matter of Examples 25 - 27 includes that an external administrator computing device of the computing machine can access a plurality of managed computing resources present in the computing machine, and cannot access a plurality of unmanaged computing resources present in the computing machine.

[0250] In Example 29, the subject matter of Examples 25 - 28 includes that the security policy includes security rules that restrict the activities of the user of the computing machine with respect to a plurality of managed computing resources.

[0251] In Example 30, the subject matter of Examples 25 - 29 includes that the security policy includes monitoring rules that enable a remote computing device to monitor the activities of the user of the computing machine with respect to a plurality of managed computing resources.

[0252] In Example 31, the subject matter of Examples 25 to 30 includes that a plurality of unmanaged computing resources and a plurality of managed computing resources are present in different separate directories of the file system of a computing machine or a cloud storage unit.

[0253] Example 32 includes: receiving a request to access a computing resource present on a computing machine via a user account in the computing machine; directly providing access to the computing resource locally on the computing machine through the native computing environment of the computing machine; determining that the computing resource is associated with a security policy, where the user account in the computing machine is associated with a plurality of computing resources including the computing resource present on the computing machine, a first portion of the plurality of computing resources is associated with the security policy, and a second portion of the plurality of computing resources is not associated with the security policy; in response to determining that the computing resource is associated with a security policy, causing a display unit to display a visual indication that the computing resource is associated with the security policy, associated with an area of the display unit that displays the computing resource; and applying a security rule from the security policy to the computing resource.

[0254] In Example 33, the subject matter of Example 32 includes that the computing resource is a website, an application, or a file, and the computing machine is one of a laptop computer, a desktop computer, a mobile phone, or a tablet computer.

[0255] In Example 34, the subject matter of Examples 32 to 33 is that the security policy is an organizational security policy, and the computing machine stores a set of organizational computing resources associated with the organizational security policy and a set of personal computing resources not associated with the organizational security policy.

[0256] In Example 35, the subject matter of Examples 32 to 34 includes one or more of: a security rule from the security policy blocks sharing of computing resources; logs the reason for sharing of computing resources; receives user confirmation prior to sharing of computing resources; logs keystrokes while a computing resource is selected; locks the computing resources in response to the computing machine being idle for at least a threshold period.

[0257] In Example 36, the subject matter of Example 35 includes one or more of: printing; screen sharing; transmitting via email or a messaging service; drag and drop; cut and paste; download; upload; attach; print; access a particular website; access a category of websites; launch an application; or take a screenshot.

[0258] In Example 37, the subject matter of Examples 32 to 36 includes deactivating one or more security rules from the security policy regarding computing resources in response to a user request; and logging the reason for the user request.

[0259] In Example 38, the subject matter of Examples 32 to 37 includes receiving an indication of a selection of a visual indication via a graphical user interface (GUI); and providing, in response to the selection of the visual indication, information regarding the user's permissions for computing resources of a computing machine, or information regarding a security policy, for display.

[0260] In Example 39, the subject matter of Examples 32 to 38 includes causing a display unit to simultaneously display computing resources associated with a security policy and additional computing resources not associated with the security policy, both the computing resources and the additional computing resources being executed through a native computing environment of a computing machine.

[0261] In Example 40, the subject matter of Examples 32 to 39 includes a visual indicator being displayed on or adjacent to a boundary of a region of a display unit that displays computing resources.

[0262] Example 41 involves storing, within a single user account in a computing machine, a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy; executing a first instance of a specified application that has no read or write access to any of the plurality of managed computing resources; executing a second instance of the specified application that accesses at least a portion of the plurality of managed computing resources, simultaneously with the first instance; and applying rules from the security policy to the second instance of the specified application while withholding application of the rules from the security policy to the first instance of the specified application.

[0263] In Example 42, the subject matter of Example 41 includes identifying a computing resource as a managed computing resource based on one or more of the location of the computing resource in a directory or file system, a cloud storage location, a rule in the security policy, a process name or path, a Uniform Resource Locator (URL) address, and whether the computing resource is launched from an application launcher associated with the plurality of managed computing resources.

[0264] In Example 43, the subject matter of Examples 41 - 42 includes that the additional computing resources include personal computing resources, the managed computing resources include organizational computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0265] In Example 44, the subject matter of Examples 41 to 43 includes that a first instance of a specified application accesses at least a portion of a plurality of additional computing resources.

[0266] In Example 45, the subject matter of Examples 41 to 44 includes that a second instance of a specified application can have read access but not write access to at least a portion of a plurality of additional computing resources, and that when the second instance accesses at least a portion of the plurality of additional computing resources, application of a security policy is based on settings associated with the computing machine.

[0267] In Example 46, the subject matter of Examples 41 to 45 includes accessing non-secure computing resources using a third instance of a specified application; and blocking access by a third instance of the specified application to any of the plurality of managed computing resources and to any of the plurality of additional computing resources.

[0268] In Example 47, the subject matter of Example 46 includes identifying non-secure computing resources based on non-secure computing resources present in a download memory area, a memory area associated with an attachment of an email application, or a memory area associated with a web browser.

[0269] In Example 48, the subject matter of Example 47 includes that the download memory area includes a download folder, the memory area associated with the web browser includes a download folder, and the memory area associated with an attachment of the email application includes an attachment folder.

[0270] Example 49 includes: in a computing machine, storing a plurality of managed computing resources and a plurality of additional computing resources, where the plurality of managed computing resources are associated with a security policy, the plurality of managed computing resources are within a managed zone, and the managed zone includes a portion of data associated with the native computing environment of the computing machine; executing a first instance of a specified application outside the managed zone, where the first instance can read from and write to data outside the managed zone and cannot read from or write to data stored within the managed zone; and executing a second instance of the specified application within the managed zone simultaneously with the first instance, where the second instance can read from but not write to data outside the managed zone, the second instance can read from and write to data stored within the managed zone, and the second instance is executed separately and differently from the first instance.

[0271] In Example 50, the subject matter of Example 49 includes that the additional computing resources include personal computing resources, the managed computing resources include organizational computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites.

[0272] In Example 51, the subject matter of Examples 49 - 50 includes that the second instance of the specified application accesses the network via a managed network interface, and the managed network interface separates Domain Name System (DNS) traffic associated with the managed zone.

[0273] In Example 52, the subject matter of Example 51 includes that the first instance of the specified application accesses the network via the native network interface of the computing machine rather than the managed network interface, and the managed network interface restricts access to network resources associated with the managed zone by a plurality of additional resources that exist outside the managed zone.

[0274] In Example 53, the subject matter of Examples 49 to 52 includes that the first instance of the specified application accesses the Component Object Model (COM) of the computing machine, and the second instance of the specified application accesses an emulated COM of a managed zone different from the COM of the computing machine.

[0275] In Example 54, the subject matter of Examples 49 to 53 includes that the first instance of the specified application accesses the Remote Procedure Call (RPC) subsystem of the computing machine for inter-process communication, and the second instance of the specified application accesses an emulated RPC subsystem of a managed zone different from the RPC subsystem of the computing machine for inter-process communication.

[0276] In Example 55, the subject matter of Examples 49 to 54 includes that the computing machine stores a set of global objects externally to the managed zone, the computing machine stores an emulated set of global objects that emulates the set of global objects within the managed zone, the first instance of the specified application accesses the set of global objects, and the second instance of the specified application accesses the emulated set of global objects.

[0277] In Example 56, the subject matter of Examples 49 through 55 is that a computing machine stores, external to a zone being managed, a computing machine registry representing settings composed of a hardware device configuration, installed application settings, and operating system settings, the computing machine stores an emulated registry that emulates the computing machine registry of an application running within the zone being managed within the zone being managed, a first instance of a specified application accesses the computing machine registry, and a second instance of the specified application accesses the emulated registry.

[0278] In Example 57, the subject matter of Examples 49 through 56 is that the specified application is a file manager application, the first instance is for access to files from a plurality of additional computing resources, and the second instance is for access to files from a plurality of computing resources being managed and read-only access to a plurality of additional computing resources.

[0279] In Example 58, the subject matter of Examples 49 to 57 is to access a request to open a selected file via a file explorer of a computing machine, where the file explorer is executed externally to the zone to be managed, the file has a related application, and the file explorer provides access to both files external to the zone to be managed and files internal to the zone to be managed; determining whether the selected file is from among a plurality of managed computing resources; if it is determined that the selected file is from among a plurality of managed computing resources, opening the selected file using an instance of a related application running within the zone to be managed; and if it is determined that the selected file is not from among a plurality of managed computing resources, opening the selected file using an instance of a related application not running within the zone to be managed.

[0280] In Example 59, the subject matter of Examples 49 to 58 includes that the operating system of the computing machine cannot access a plurality of managed computing resources from outside the zone to be managed.

[0281] In Example 60, the subject matter of Examples 49 to 59 includes that a security program can access both the zone to be managed and the unmanaged zone, and the security program includes one or more of an antivirus program, a malware countermeasure program, or a security audit tool.

[0282] In Example 61, the subject matter of Examples 49 to 60 includes accessing unsecure computing resources using a restricted instance of a specified application that is running within a restricted zone; and blocking access by a restricted instance of the specified application to any of a plurality of managed computing resources and to any of a plurality of additional computing resources.

[0283] In Example 62, the subject matter of Example 61 includes that a security program is capable of accessing a managed zone, an unmanaged zone, and a restricted zone, and that the security program includes one or more of an antivirus program, a malware countermeasure program, or a security audit tool.

[0284] In Example 63, the subject matter of Examples 61 to 62 includes identifying unsecure computing resources based on unsecure computing resources that exist in a download memory area, a memory area associated with an attachment of an email application, or a memory area associated with a web browser.

[0285] In Example 64, the subject matter of Example 63 includes that the download memory area includes a download folder, the memory area associated with the web browser includes a download folder, and the memory area associated with an attachment of the email application includes an attachment folder.

[0286] Example 65 includes: storing computing resources including managed computing resources in the memory of a computing machine; receiving a request to display a computing resource from the computing resources stored in the memory; causing the computing resource to be displayed within the display area of a display device; determining, based on identification criteria, whether the computing resource is a managed computing resource from among the managed computing resources; when it is determined that the computing resource is a managed computing resource: causing an indicator to be displayed adjacent to an edge of the display area, the indicator indicating that the computing resource is a managed computing resource; or when it is determined that the computing resource is not a managed computing resource: foregoing causing the indicator to be displayed.

[0287] In Example 66, the subject matter of Example 65 includes that the identification criteria includes at least one of: a computing resource existing in a directory in a file system of a computing machine or a cloud storage unit, a file type of the computing resource, an application associated with the computing resource, a website associated with the computing resource, or a computing resource provided or installed on the computing machine by a specified entity.

[0288] In Example 67, the subject matter of Examples 65 - 66 includes that the identification criteria includes the presence of a computing resource within a pre - defined zone of the memory, and the pre - defined zone has at least one security policy applicable to computing resources within a pre - defined organizational zone and not applicable to computing resources external to the pre - defined organizational zone.

[0289] In Example 68, the subject matter of Examples 65 to 67 includes that the identification criterion includes the presence of computing resources within a pre-defined zone of the memory, the pre-defined zone is accessible to the computing resources within the pre-defined zone, and includes having at least one network interface that is not accessible to computing resources external to the pre-defined zone.

[0290] In Example 69, the subject matter of Examples 65 to 68 includes that the identification criterion includes computing resources that are accessed via a launcher managed in a computing machine or include data from additional managed computing resources.

[0291] In Example 70, the subject matter of Example 69 includes that the additional managed computing resources include at least one of: a file, an email, a software as a service (SaaS) application or website, or a network destination or subnet.

[0292] In Example 71, the subject matter of Examples 65 to 70 includes that the indicator includes a boundary line that occupies pixels outside the display area that are within n pixels or less from the display area, n is a positive integer, and the boundary line has a pre-defined color or design.

[0293] In Example 72, the subject matter of Examples 65 to 71 includes that the indicator includes a badge having a circular or oval shape that covers a portion of the edge of the display area.

[0294] In Example 73, the subject matter of Examples 65 to 72 includes that the memory of the computing machine stores managed computing resources and unmanaged computing resources, and the managed computing resources and unmanaged computing resources are mutually exclusive.

[0295] In Example 74, the subject matter of Examples 65 to 73 includes that the display area includes a part of the display space of the display device.

[0296] Example 75 is at least one machine-readable medium that, when executed by a processing circuit, causes the processing circuit to perform an operation of implementing any one of Examples 1 to 74.

[0297] Example 76 is an apparatus comprising means for implementing any one of Examples 1 to 74.

[0298] Example 77 is a system for implementing any one of Examples 1 to 74.

[0299] Example 78 is a method for implementing any one of Examples 1 to 74.

[0300] The embodiments have been described with reference to specific exemplary embodiments, but it will be apparent that various modifications and changes can be made to these embodiments without departing from the broader spirit and scope of the present disclosure. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a limiting sense. The accompanying drawings, which form a part of this specification, show, by way of example and not limitation, specific embodiments in which the subject matter can be implemented. The embodiments shown are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other embodiments can be utilized and derived therefrom without departing from the scope of the present disclosure so that structural and logical substitutions and changes can be made. Accordingly, the embodiments for carrying out the invention should not be construed in a limiting sense, and the scope of the various embodiments is defined only by the appended claims together with the full scope of equivalents to which such claims are entitled.

[0301] While specific embodiments have been illustrated and described in this specification, it should be understood that any configuration calculated to achieve the same purpose may be substituted for the specific embodiments shown. This disclosure is intended to cover any adaptations or variations of various embodiments. Combinations of the above embodiments, and other embodiments not specifically described herein, will be apparent to those skilled in the art upon reading the above description.

[0302] In this specification, the term "a" or "an" is used to include one or more, independent of other instances or usages of "at least one" or "one or more" as is common in patent documents. In this document, the term "or" is used to mean non-exclusive, unless otherwise specified, e.g., "A or B" means "A but not B", "B but not A", and "A and B". In this document, the terms "including" and "in which" are used as the plain English equivalents of the respective terms "comprising" and "wherein". Also, in the following claims, the terms "including" and "comprising" are open-ended, i.e., a system, user equipment (UE), article, composition, formation or process that includes elements in addition to those recited after such terms in a claim is still considered to be within the scope of that claim. Further, in the following claims, terms such as "first", "second", and "third" are used merely as labels and are not intended to impose numerical requirements on their objects.

[0303] The summary of the disclosure is provided in accordance with 37 C.F.R. § 1.72(b), which requires a summary that enables a reader to quickly ascertain the nature of the technical disclosure. The summary of the disclosure is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Additionally, in the detailed description of the invention, it will be apparent that various features are grouped in a single embodiment for the purpose of simplifying the disclosure. This method of disclosure is not to be construed as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as reflected in the following claims, the subject matter of the invention requires less than all of the features of a single disclosed embodiment. For this reason, the following claims are incorporated into the detailed description, and each claim stands on its own as a separate embodiment.

Claims

A method executed by a computing machine, comprising: storing, in the computing machine, a plurality of managed computing resources and a plurality of additional computing resources, wherein the plurality of managed computing resources are associated with a security policy; simultaneously displaying, on a display unit coupled to the computing machine via the native computing environment of the computing machine, all or a portion of the visual representation of the specified managed computing resources and all or a portion of the visual representation of the specified additional computing resources, wherein the visual representation of the specified managed computing resources includes data generated during the execution of software associated with the specified managed computing resources, and the visual representation of the specified additional computing resources includes data generated during the execution of software associated with the specified additional computing resources; applying a security rule from the security policy to the specified managed computing resources, wherein applying the security rule includes promoting, by a management service, tracking of the activities of the computing machine with respect to the specified managed computing resources; facilitating, by a management service, tracking of the activities of the computing machine with respect to the specified additional computing resources and with respect to activities on the computing machine that are not associated with one or more of the plurality of managed computing resources. Displaying a visual indicator indicating that tracking is in progress, in association with a visual representation of a specified managed computing resource, where the visual indicator includes a boundary line for the visual representation of the specified managed computing resource, and the boundary line is within a distance of n or fewer pixels from the visual representation of the specified managed computing resource, and the points outside the visual representation of the specified managed computing resource are occupied by these pixels, provided that these pixels are not occupied by the visual representation of other computing resources that are more dominant than the specified managed computing resource within the computing resource stack, where n is a positive integer, and A method comprising the above. **Claim 2** The method according to claim 1, wherein the additional computing resources include personal computing resources, the managed computing resources include business computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites. **Claim 3** Further comprising aligning the application of a security rule from a security policy to a specified additional computing resource. The method according to claim 1. **Claim 4** The method according to claim 1, wherein applying the security rule includes blocking the copying of data from a specified managed computing resource to a specified additional computing resource by communicating with a hardware driver of a computing machine. **Claim 5** The method according to claim 1, wherein the visual indicator includes a badge adjacent to the area of the display unit occupied by the visual representation of the specified managed computing resource. **Claim 6** The method according to claim 1, wherein the activities of the computing machine related to the specified managed computing resource and the activities of the computing machine related to the specified additional computing resource include network traffic. **Claim 7** The method according to claim 1, wherein the activities of the computing machine regarding the specified managed computing resources and the activities of the computing machine regarding the specified additional computing resources include Internet browsing.

8. The method according to claim 1, wherein the activities of the computing machine regarding the specified managed computing resources and the activities of the computing machine regarding the specified additional computing resources include camera or microphone input activities.

9. Storing information transmitted from the computing machine to the management service; Providing a visual representation of the information transmitted from the computing machine to the management service in response to a user request; The method according to claim 1, further comprising:

10. The method according to claim 1, wherein the management service includes at least one of a cloud-based management service, one or more servers, or an administrator computing device associated with a security policy.

11. The security rule includes one or more rules that block a set of operations from the specified managed computing resources to the specified additional computing resources, and the set of operations includes at least one of a drag-and-drop operation, a copy-and-paste operation, a cut-and-paste operation, a keylogging operation, a file download operation, a file upload operation, a file attachment operation, a printing operation, an operation to open a specific website, an operation to open a category of websites, an application launch operation, or a screenshot operation. The method according to claim 1.

12. Applying the security rule includes blocking copying data from the specified managed computing resources to the specified additional computing resources by communicating with the controller of the computing machine. The method according to claim 1.

13. Ending the display of the visual representation of the specified additional computing resources on the display unit in response to a user input; Continuing to display on the display unit a visual representation of the specified managed computing resources and a visual indicator indicating that tracking is in progress The method according to claim 1, further comprising:

14. A non-transitory machine-readable medium storing instructions that, when executed by a processing circuit of a computing machine, cause the processing circuit to In a computing machine, storing a plurality of managed computing resources and a plurality of additional computing resources, wherein the plurality of managed computing resources are associated with a security policy; Simultaneously displaying, via the native computing environment of the computing machine, all or a portion of the visual representation of the specified managed computing resources and all or a portion of the visual representation of the specified additional computing resources on a display unit coupled to the computing machine, wherein the visual representation of the specified managed computing resources includes data generated during execution of software associated with the specified managed computing resources, and the visual representation of the specified additional computing resources includes data generated during execution of software associated with the specified additional computing resources; Applying a security rule from the security policy to the specified managed computing resources, wherein applying the security rule includes promoting tracking, by a management service, of the activities of the computing machine with respect to the specified managed computing resources; Balancing promoting tracking, by a management service, of the activities of the computing machine with respect to the specified additional computing resources and activities on the computing machine that are not associated with one or more of the plurality of managed computing resources Displaying a visual indicator that indicates that tracking is in progress, in association with a visual representation of a specified managed computing resource, wherein the visual indicator includes a boundary line for the visual representation of the specified managed computing resource, and the boundary line is within a distance of n or fewer pixels from the visual representation of the specified managed computing resource, and occupies points outside the visual representation of the specified managed computing resource, provided that these pixels are not occupied by the visual representation of another computing resource that is more dominant than the specified managed computing resource within the computing resource stack, where n is a positive integer, and A machine-readable medium that causes an operation to be performed that includes this. Claim 15 The machine-readable medium according to claim 14, wherein the additional computing resources include personal computing resources, the managed computing resources include business computing resources, and the plurality of managed computing resources and the plurality of additional computing resources include files, cloud file storage access, applications, or websites. Claim 16 The machine-readable medium according to claim 14, wherein the operation further includes matching the application of a security rule from a security policy to the specified additional computing resource. Claim 17 The machine-readable medium according to claim 14, wherein the visual indicator includes a badge adjacent to the area of the display unit occupied by the visual representation of the specified managed computing resource. Claim 18 The machine-readable medium according to claim 14, wherein the activities of the computing machine regarding the specified managed computing resource and the activities of the computing machine regarding the specified additional computing machine include network traffic. Claim 19 A machine-readable medium according to claim 14, wherein activities of a computing machine with respect to a specified managed computing resource and activities of the computing machine with respect to a specified additional computing resource include Internet browsing.

20. A machine-readable medium according to claim 14, wherein activities of a computing machine with respect to a specified managed computing resource and activities of the computing machine with respect to a specified additional computing resource include camera or microphone input activities.

21. A system comprising a processing circuit, and a memory storing instructions, wherein when the instructions are executed by the processing circuit of the computing machine, the instructions cause the processing circuit to store, in the computing machine, a plurality of managed computing resources and a plurality of additional computing resources, wherein the plurality of managed computing resources are associated with a security policy, simultaneously display, on a display unit coupled to the computing machine via the native computing environment of the computing machine, all or a portion of a visual representation of a specified managed computing resource and all or a portion of a visual representation of a specified additional computing resource, wherein the visual representation of the specified managed computing resource includes data generated during execution of software associated with the specified managed computing resource, and the visual representation of the specified additional computing resource includes data generated during execution of software associated with the specified additional computing resource, apply a security rule from the security policy to the specified managed computing resource, wherein applying the security rule includes at least facilitating tracking, by a management service, of activities of the computing machine with respect to the specified managed computing resource. To cause a management service to track activities on a computing machine related to a specified additional computing resource and activities on a computing machine not associated with one or more of a plurality of managed computing resources To display a visual indicator indicating that tracking is in progress, in association with a visual representation of a specified managed computing resource, the visual indicator including a boundary line for the visual representation of the specified managed computing resource, the boundary line occupying outer points within a distance of n or fewer pixels from the visual representation of the specified managed computing resource, the pixels not being occupied by visual representations of other computing resources that are more dominant than the specified managed computing resource within the computing resource stack, where n is a positive integer A system that performs operations including

Citation Information

Patent Citations

  • Endoscope apparatus

    JP1997192095A

  • Secret information protection system for existing application

    JP2006139475A

  • Methods and systems for facilitating the isolation of application workspaces

    JP2015526951A

  • Wrapping applications in field programmable business logic

    JP2018510426A

  • Server-based architecture for securely providing multi-domain applications

    US9021559B1