Remotely restricting client devices

US11079893B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11079893-B2
Application numberUS-201514687564-A
CountryUS
Kind codeB2
Filing dateApr 15, 2015
Priority dateApr 15, 2015
Publication dateAug 3, 2021
Grant dateAug 3, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Disclosed are various examples for remotely restricting client devices. A client device can be placed into a restricted mode in which application switching capabilities of the client device are disabled. Additionally, the client device can transmit screen capture data to a management service, which can provide the ability for an administrator user to monitor data shown on a display associated with the client device. The client device can also be removed from the restricted mode in response to a command sent from the management service to the client device.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method comprising: obtaining, by at least one computing device executing a management service, a request to register a client device, the request received from a client application; generating in a user interface within a management console, by the at least one computing device, an entry associated with the client device; obtaining, from the user interface associated with the management console, a request to place the client device in a restricted mode that disables an application switching capability of the client device; generating, by the at least one computing device, a command to place the client device in the restricted mode, wherein the command causes the client device to edit a system registry associated with an operating system of the client device to disable the application switching capability of the client device, wherein to edit the system registry associated with the operating system of the client device to disable the application switching capability of the client device comprises an instance in which a feature of the operating system is disabled that allows at least one application that is executing in a foreground on the client device to be changed; and transmitting, from the at least one computing device, the command to the client device to place the client device in the restricted mode, the command identifying at least one permitted application executable by the client device while the client device is in the restricted mode in the instance in which the feature is disabled. 2. The method of claim 1 , wherein the restricted mode that disables the application switching capability further comprises disabling a file explorer or a task manager associated with the operating system of the client device. 3. The method of claim 1 , further comprising: obtaining, from the client device, a screen capture associated with a display of the client device; and generating, by the at least one computing device, a representation of the screen capture in the user interface. 4. The method of claim 1 , further comprising: obtaining, through the user interface in the management console, a request to remove the client device from the restricted mode; generating, by the at least one computing device, a removal command to remove the client device from the restricted mode; and transmitting, from the at least one computing device, the removal command to the client device, wherein the client device is configured to enable an application switching capability of the client device in response to receiving the removal command. 5. The method of claim 1 , further comprising: generating, by the at least one computing device, an administrator password associated with the client device, wherein the administrator password facilitates removal of the client device from the restricted mode; and transmitting, by the at least one computing device, the administrator password to an administrator device. 6. The method of claim 5 , wherein the administrator device comprises a removable storage device in communication with the at least one computing device. 7. The method of claim 1 , wherein the at least one permitted application comprises a browser application. 8. The method of claim 7 , wherein the command identifies a whitelist comprising at least one network address-accessible by the browser application. 9. A non-transitory computer-readable medium embodying a program, when executed by a client device, the program causes the client device to at least: generate a request to register the client device in a restricted mode, wherein the request comprises an identifier associated with the client device; transmit the request to a management service accessible over a network; obtain a command to place the client device in the restricted mode from the management service, the command identifying a permitted application that is allowed to be executed while the client device is in the restricted mode; disable an application switching capability by editing a system registry associated with an operating system of the client device, wherein to disable the application switching capability by editing the system registry comprises an instance in which a feature of the operating system is disabled that allows at least one application that is executing in a foreground on the client device to be changed; enter the restricted mode in the instance in which the feature is disabled; and execute the permitted application identified by the command to place the client device in the restricted mode. 10. The non-transitory computer-readable medium of claim 9 , wherein the program is further configured to cause the client device to disable a task manager executed by the operating system of the client device in response to receiving the command to place the client device in the restricted mode. 11. The non-transitory computer-readable medium of claim 9 , wherein the program is further configured to cause the client device to disable a file explorer executed by the operating system of the client device. 12. The non-transitory computer-readable medium of claim 9 , wherein the program is further configured to cause the client device to execute the permitted application in a full screen mode on the client device. 13. The non-transitory computer-readable medium of claim 9 , wherein the program is further configured to cause the client device to: detect an administrator device in proximity to the client device; determine whether the administrator device is authorized to cause removal of the client device from the restricted mode; and remove the client device from the restricted mode in response to determining that the administrator device is authorized. 14. The non-transitory computer-readable medium of claim 13 , wherein the program causes the client device to detect an administrator device in proximity to the client device by detecting coupling of a removable storage device with the client device. 15. A system comprising: a client device executing a client application; and a computing environment executing a management service, the computing environment in communication with the client device over a network, wherein the client device is configured to: generate a request to register the client device in a restricted mode, wherein the request originates from the client application; transmit the request to the management service; obtain a command to place the client device in the restricted mode, the command being received from the management service and the command specifying a permitted application that is allowed to be executed while the client device is in the restricted mode; disable an application switching capability by editing a system registry associated with an operating system of the client device, wherein to disable the application switching capability by editing the system registry comprises an instance in which a feature of the operating system is disabled that allows at least one application that is executing in a foreground on the client device to be changed; enter the restricted mode in the instance in which the feature is disabled; and execute the permitted application identified by the command while the client device is in the restricted mode. 16. The system of claim 15 , wherein the client device is configured to execute the client application upon startup of the client device. 17. The system of claim 15 , wherein the client device is further configured to execute the client application in an administrator mode, wherein the administrator mode is associate

Assignees

Inventors

Classifications

  • Protocols · CPC title

  • Managing security policies for mobile devices or for controlling mobile applications · CPC title

  • Access security · CPC title

  • G06F3/0481Primary

    based on specific properties of the displayed interaction object or a metaphor-based environment, e.g. interaction with desktop elements like windows or icons, or assisted by a cursor's changing behaviour or appearance · CPC title

  • Multiple levels of security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11079893B2 cover?
Disclosed are various examples for remotely restricting client devices. A client device can be placed into a restricted mode in which application switching capabilities of the client device are disabled. Additionally, the client device can transmit screen capture data to a management service, which can provide the ability for an administrator user to monitor data shown on a display associated w…
Who is the assignee on this patent?
Airwatch Llc
What technology area does this patent fall under?
Primary CPC classification G06F3/0481. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 03 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).