IP Library Granted Patent US 8,549,313
Granted Patent B2
US 8,549,313 · App. 13/459,129 · Granted Oct 1, 2013

Method and system for integrated securing and managing of virtual machines and virtual appliances

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,549,313
App. No.
13/459,129
Granted
Oct 1, 2013
Kind
B2
Abstract

Method and system for the integrated securing and managing of virtual machines and virtual appliances are presented. Sealing the virtual appliance at the computer of a sender, verifying authenticity of the sender at a recipient computer and managing the execution of the VA are performed in a seamless fashion.

Claims (51)

1. A secured virtual machine apparatus, comprising:

at least one hardware processor; and

at least one hardware memory device, having computer readable instructions stored thereon for execution by the at least one hardware processor, forming:

a virtual machine, comprising a virtual hard disk, containing an operating system and software applications running on the virtual hard disk; and

a security and management module, comprising:

a sealing module, sealing with the virtual machine, a signature of a sender, and policies governing ownership and execution of the virtual machine, to generate a secured virtual machine at a sender computer;

a security enforcement module, verifying authenticity of the sender upon receiving the secured virtual machine at a recipient computer; and

an execution management module, retrieving the virtual machine and the policies from the secured virtual machine, and managing the execution of the virtual machine on the recipient computer in accordance with the policies.

2. The secured virtual machine apparatus of claim 1 , the computer readable instructions further forming another module, recording changes made to the virtual machine on the sender computer before the virtual machine has been sealed.

3. The secured virtual machine apparatus of claim 2 , wherein the sealing module is further configured to seal the changes together with the virtual machine, the signature and the policies to generate the secured virtual machine.

4. The secured virtual machine apparatus of claim 1 , the computer readable instructions further forming yet another module, recording changes made to the virtual machine on the recipient computer.

5. The secured virtual machine apparatus of claim 1 , the computer readable instructions further forming a metadata module, comprising metadata related to resource requirement data and runtime data for the virtual machine.

6. The secured virtual machine apparatus of claim 1 , wherein the execution management module further comprises a rules engine, processing rules describing the policies.

7. The secured virtual machine apparatus of claim 1 , the computer readable instructions further forming an encryption module for encrypting the secured virtual machine at the sender computer, and a decryption module, decrypting the secured virtual machine at the recipient computer.

8. The secured virtual machine apparatus of claim 1 , wherein the sealing module further comprises:

a hash generation module, creating a hash of contents of a file containing the virtual machine; and

a signature generation module, encrypting the hash with a private key of the recipient.

9. The secured virtual machine apparatus of claim 8 , wherein the signature generation module further comprises an encryption module, encrypting the secured virtual machine with a key, and further encrypting the key with a public key of the recipient.

10. The secured virtual machine apparatus of claim 1 , wherein the security enforcement module further comprises:

a signature verification module, verifying the signature of the sender; and

a hash verification module, determining a hash of contents of the file containing the virtual machine at the recipient computer, and comparing it with a hash of contents of a file containing the virtual machine at the sender computer.

11. A computer system, comprising:

a hardware platform, comprising at least one central processing unit, and at least one memory device;

the at least one hardware memory device, having computer readable instructions stored thereon for execution by the at least one central processing unit, forming:

a hypervisor having a virtual machine manager, managing one or more virtual machines, each virtual machine, comprising a virtual hard disk, containing an operating system and software applications running on the virtual hard disk;

at least one of the virtual machines being configured as a secured virtual machine by causing the at least one central processing unit to:

to generate a secured virtual machine at a sender computer, including sealing with a virtual machine, a signature of a sender, and policies governing ownership and execution of the virtual machine;

verify authenticity of the sender upon receiving the secured virtual machine at a recipient computer; and

retrieve, from the secured virtual machine, the virtual machine and the policies, and manage the execution of the virtual machine on the recipient computer in accordance with the policies.

12. The computer system of claim 11 , wherein the computer readable instructions further cause the at least one central processing unit to record changes made to the virtual machine on the sender computer before the virtual machine has been sealed, and to seal the changes together with the virtual machine, the signature and the policies to generate the secured virtual machine.

13. The computer system of claim 11 , wherein the computer readable instructions further cause the at least one central processing unit to record changes made to the virtual machine on the recipient computer.

14. The computer system of claim 11 , wherein the computer readable instructions further cause the at least one central processing unit to encrypt the secured virtual machine at the sender computer, and to decrypt the encrypted secured virtual machine at the recipient computer.

15. The computer system of claim 11 , wherein the computer readable instructions further cause the at least one central processing unit to:

create a hash of contents of a file containing the virtual machine; and

encrypt the hash with a private key of the recipient.

16. The computer system of claim 15 , wherein the computer readable instructions further cause the at least one central processing unit to encrypt the secured virtual machine with a key, and further encrypt the key with a public key of the recipient.

17. The computer system of claim 11 , wherein the computer readable instructions further cause the at least one central processing unit to:

verify the signature of the sender; and

determine a hash of contents of the file containing the virtual machine at the recipient computer, and comparing it with a hash of contents of a file containing the virtual machine at the sender computer.

18. The computer system of claim 11 , wherein the computer readable instructions further cause the at least one central processing unit to form a rules engine, processing rules describing the policies.

19. The computer system of claim 11 , the computer readable instructions further forming a metadata module, comprising metadata related to resource requirement data and runtime data for the virtual machine.

20. A system for generating a secured virtual machine, the system comprising:

a sender computer, comprising:

a first processor; and

a first memory device, having computer readable instructions stored thereon for execution by the first processor, causing the first processor to generate the secured virtual machine, comprising sealing with a virtual machine, a signature of a sender, and policies governing ownership and execution of the virtual machine; and

a recipient computer, comprising:

a second processor; and

a second memory device, having computer readable instructions stored thereon

for execution by the second processor, causing the second processor to:

verify authenticity of the sender upon receiving the secured virtual machine at a recipient computer; and

retrieve the virtual machine and the policies from the secured virtual machine, and manage the execution of the virtual machine on the recipient computer in accordance with the policies.

Assignments (20)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS - REEL/FRAME 066615-0824 Recorded Aug 22, 2025
From: JEFFERIES FINANCE LLC
To: SNOW SOFTWARE, INC.
Reel/Frame 072527/0879 →
SECURITY INTEREST Recorded Aug 15, 2025
From: FLEXERA SOFTWARE LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL GENT
Reel/Frame 072460/0828 →
MERGER Recorded Nov 22, 2024
From: SNOW SOFTWARE US, INC.
To: FLEXERA SOFTWARE LLC
Reel/Frame 069373/0957 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Apr 18, 2024
From: JEFFERIES FINANCE LLC
To: SNOW SOFTWARE, INC.
Reel/Frame 067165/0214 →
PATENT SECURITY AGREEMENT (FIRST LIEN) Recorded Feb 16, 2024
From: SNOW SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 066615/0824 →
PATENT SECURITY AGREEMENT (SECOND LIEN) Recorded Feb 16, 2024
From: SNOW SOFTWARE, INC.
To: JEFFERIES FINANCE LLC, AS SECOND LIEN COLLATERAL AGENT
Reel/Frame 066619/0340 →
RELEASE OF SECURITY INTEREST Recorded Feb 15, 2024
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: SNOW SOFTWARE, INC.
Reel/Frame 066471/0027 →
RELEASE OF SECURITY INTEREST Recorded Jul 8, 2021
From: OBSIDIAN AGENCY SERVICES, INC.
To: EMBOTICS CORPORATION
Reel/Frame 056792/0547 →
PATENT SECURITY AGREEMENT Recorded Jul 7, 2021
From: SNOW SOFTWARE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 056784/0335 →
AMALGAMATION Recorded Jul 2, 2021
From: EMBOTICS CORPORATION; KEYSTRIKE CANADA INC.
To: EMBOTICS CORPORATION
Reel/Frame 056756/0440 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2021
From: EMBOTICS ULC
To: SNOW SOFTWARE, INC.
Reel/Frame 056746/0317 →
CHANGE OF NAME Recorded Jul 2, 2021
From: EMBOTICS CORPORATION
To: EMBOTICS ULC
Reel/Frame 056745/0413 →
SECURITY INTEREST Recorded Dec 12, 2019
From: EMBOTICS CORPORATION
To: OBSIDIAN AGENCY SERVICES, INC., AS COLLATERAL AGENT
Reel/Frame 051262/0731 →
RELEASE OF SECURITY INTEREST Recorded Dec 11, 2019
From: CANADIAN IMPERIAL BANK OF COMMERCE
To: EMBOTICS CORPORATION
Reel/Frame 051247/0045 →
MERGER AND CHANGE OF NAME Recorded Dec 11, 2019
From: EMBOTICS CORPORATION; 1229377 B.C. LTD.
To: 1229377 B.C. LTD
Reel/Frame 051256/0371 →
CHANGE OF NAME Recorded Dec 11, 2019
From: 1229377 B.C. LTD
To: EMBOTICS CORPORATION
Reel/Frame 051256/0529 →
SECURITY INTEREST Recorded Dec 12, 2018
From: EMBOTICS CORPORATION
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 047750/0272 →
CHANGE OF ADDRESS Recorded Jan 19, 2017
From: EMBOTICS CORPORATION
To: EMBOTICS CORPORATION
Reel/Frame 041420/0583 →
CHANGE OF COMPANY ADDRESS Recorded Apr 28, 2012
From: EMBOTICS CORPORATION
To: EMBOTICS CORPORATION
Reel/Frame 028123/0929 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2012
From: SEGUIN, JEAN-MARC L., MR.; LITKEY, JAY M., MR.; LYNCH, DAVID M., MR.; JAMENSKY, MARK, MR.
To: EMBOTICS CORPORATION
Reel/Frame 028124/0042 →