Code module use in endpoint devices
US-2024419773-A1 · Dec 19, 2024 · US
US2021240812A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2021240812-A1 |
| Application number | US-202016778534-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 31, 2020 |
| Priority date | Jan 31, 2020 |
| Publication date | Aug 5, 2021 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The present disclosure involves systems, software, and computer implemented methods for automatically controlling access and limiting functionality of a computer workstation based on which user is currently logged in. In some implementations, an overwatch application is installed on the workstations to be controlled and monitored. If an authorized, but limited, user logs in, the overwatch application can initiate a lockdown process on the workstation. In some instances, the lockdown process is managed by a dedicated lockdown application, which is initiated or notified from the overwatch application, and which can initiate a lockdown of particular applications, functionality, and allowed interactions on the workstation until the limited user has completed their task and a new user logs in.
Opening claim text (preview).
1 . A system for controlling access, the system comprising: a communications interface; at least one memory storing a repository of login credentials, a repository of authorization rules, and instructions; at least one hardware processor interoperably coupled with the at least one memory and the communications interface, wherein the instructions instruct the at least one hardware processor to: execute an overwatch application associated with a workstation, wherein the overwatch application monitors logins to the workstation; in response to detecting, by the overwatch application, an attempted login of a limited user, wherein the login is associated with a set of credentials corresponding to the limited user: initialize a lockdown application; identify, by the lockdown application and based on the authorization rules and the set of credentials, authorized processes, wherein an authorized process is a software process permitted to execute on the workstation during the login of the limited user; terminate, by the lockdown application, executing processes that are not authorized processes; identify, by the lockdown application, a set of authorized hardware inputs based on the authorization rules and the set of credentials; and monitor, by the lockdown application, inputs associated with the workstation for receipt of unauthorized hardware inputs to the workstation. 2 . The system of claim 1 , the instructions further instructing the at least one hardware processor to, in response to detecting, by the lockdown application, an unauthorized hardware input to the workstation: suppress, by the lockdown application, the unauthorized hardware input. 3 . The system of claim 1 , the instructions further instructing the at least one hardware processor to, in response to detecting, by the lockdown application, an attempt to initiate a process that is not an authorized process: transmit, via the communications interface, an alert to a central server; and execute a forced logout of the limited user. 4 . The system of claim 1 , wherein the overwatch application and lockdown application are remotely installed on the workstation by a server system. 5 . The system of claim 1 , wherein the attempted login of the limited user comprises: receiving the set of credentials at the workstation; transmitting, via the communications interface, the set of credentials to a server system, wherein the server system verifies the credentials as the credentials of an authorized, but limited user; and receiving, via the communications interface, a login authorization to the workstation, wherein the login authorization comprises information associated with the authorization rules, and wherein the authorization rules are associated with the set of credentials that match stored credentials in the stored repository of login credentials. 6 . The system of claim 1 , wherein the limited user includes a system user that is authorized to perform a particular set of tasks, wherein the particular set of tasks require only a subset of functionality associated with the workstation, and wherein the authorized processes correspond to the subset of functionality required by the particular set of tasks. 7 . The system of claim 6 , wherein the workstation is associated with a cash dispenser, and wherein the particular task includes refilling the cash dispenser. 8 . The system of claim 1 , wherein, in response to detecting, by the overwatch application, an attempted login by an authorized user, the instructions further instruct the at least one hardware processor to: allow full workstation functionality to the authorized user in response to an attempted login. 9 . The system of claim 8 , wherein the authorized user is a bank teller associated with the workstation. 10 . The system of claim 1 , wherein the hardware inputs to the workstation comprise inputs from at least one of: a keyboard; a mouse; a removable memory; a cash register; a touchscreen; or a microphone. 11 . A non-transitory, computer-readable medium storing computer-readable instructions executable by a computer and configured to: execute an overwatch application associated with a workstation, wherein the overwatch application monitors logins to the workstation; in response to detecting, by the overwatch application, an attempted login of a limited user, wherein the login is associated with a set of credentials corresponding to the limited user: initialize a lockdown application; identify, by the lockdown application and based on a set of authorization rules and the set of credentials, authorized processes, wherein an authorized process is a software process permitted to execute on the workstation during the login of the limited user; terminate, by the lockdown application, executing processes that are not authorized processes; identify, by the lockdown application, a set of authorized hardware inputs based on the authorization rules and the set of credentials; and monitor, by the lockdown application, inputs associated with the workstation for receipt of unauthorized hardware inputs to the workstation. 12 . The non-transitory, computer-readable medium of claim 11 , the instructions further instructing the at least one hardware processor to, in response to detecting, by the lockdown application, an unauthorized hardware input to the workstation: suppress, by the lockdown application, the unauthorized hardware input. 13 . The non-transitory, computer-readable medium of claim 11 , the instructions further instructing the at least one hardware processor to, in response to detecting, by the lockdown application, an attempt to initiate a process that is not an authorized process: transmit, via the communications interface, an alert to a central server; and execute a forced logout of the limited user. 14 . The non-transitory, computer-readable medium of claim 11 , wherein the overwatch application and lockdown application are remotely installed on the workstation by a server system. 15 . The non-transitory, computer-readable medium of claim 11 , wherein the attempted login of the limited user comprises: receiving the set of credentials at the workstation; transmitting, via the communications interface, the set of credentials to a server system, wherein the server system verifies the credentials as the credentials of an authorized, but limited user; and receiving, via the communications interface, a login authorization to the workstation, wherein the login authorization comprises information associated with the authorization rules, and wherein the authorization rules are associated with the set of credentials that match stored credentials in a stored repository of login credentials. 16 . The non-transitory, computer-readable medium of claim 11 , wherein the limited user includes a system user that is authorized to perform a particular set of tasks, wherein the particular set of tasks require only a subset of functionality associated with the workstation, and wherein the authorized processes correspond to the subset of functionality required by the particular set of tasks. 17 . A computerized method performed by one or more processors, the method comprising: executing an overwatch application associated with a workstation, wherein the overwatch application monitors logins to the workstation; in response to detecting, by the overwatch application, an attempted login of a limited user, wherein the login is associated with a set of credentials corresponding to the limited user: initializing a lockdown applic
to features or functions of an application · CPC title
to a system of files or objects, e.g. local or distributed file system or database · CPC title
Program or device authentication · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.