IP Library Granted Patent US 8,312,478
Granted Patent B1
US 8,312,478 · App. 13/460,908 · Granted Nov 13, 2012

System and method for using virtual machine for driver installation sandbox

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,312,478
App. No.
13/460,908
Granted
Nov 13, 2012
Kind
B1
Abstract

A method, system and computer program product for providing driver functionality in computing system includes installing an operating system on the computing system; forming a plurality of isolated sandboxes running on the computing system under control of the operating system; during an attempt to install a driver, installing driver stub in the operating system; installing the driver in one of the isolated sandboxes, wherein the driver directly uses at least part of system resources; using a gateway between the driver stub and the installed driver to provide an interface for transmitting requests from the driver stub to driver.

Claims (37)

1. A method of providing driver functionality, the method comprising:

forming at least one isolated sandbox having a limited-functionality operating system on a computing system;

during an attempt to install a host driver in a host operating system (OS), installing a driver stub in the host OS instead of the host driver, wherein the stub is accessible from the isolated sandbox,

wherein the stub supports Application Programming Interface (API) function calls supported by the host driver, including API interfaces and API call parameters;

installing a sandbox driver in the isolated sandbox;

using a gateway to redirect API requests from the driver stub to the sandbox driver for execution of the requests in the sandbox instead of in the host OS, and to transmit responses back from the sandbox driver to the host OS, wherein the stub provides access to functionality of the sandbox driver via the gateway and invokes the sandbox driver through the gateway and using the redirecting; and

wherein the sandbox driver uses the gateway to interface to host API.

2. The method of claim 1 , wherein the stub is installed in low-level kernel space.

3. The method of claim 1 , wherein the gateway includes a network communication means.

4. The method of claim 1 , wherein the sandbox is a Virtual Machine.

5. The method of claim 1 , wherein the Virtual Machine can directly invoke the host API.

6. The method of claim 1 , wherein the sandbox is a paravirtualized Virtual Machine.

7. The method of claim 1 , wherein the limited functionality operating system is integrated with the host OS.

8. The method of claim 1 , wherein the limited functionality operating system shares kernel services with the host OS.

9. The method of claim 1 , wherein the limited functionality operating system shares kernel memory with the host OS.

10. The method of claim 1 , wherein the sandbox driver directly uses at least some system resources.

11. The method of claim 1 , further comprising a controlled memory area shared for common access of the host operating system by at least some of the sandboxes, wherein the controlled memory area is used for processing requests.

12. The method of claim 1 , further comprising a controlled memory area being shared for common access of the host operating system by at least some of the sandboxes, wherein the controlled memory area is used for direct access of the sandbox driver to the host operating system resources.

13. The method of claim 1 , wherein the sandbox driver allocates resources on the host OS kernel level, and wherein allocated resources are associated in the OS kernel with the stub.

14. The method of claim 1 , wherein the sandbox is loaded based on a preconfigured snapshot of a virtual machine.

15. The method of claim 1 , wherein the sandbox is installed after starting the virtual machine from a snapshot and the sandbox is configured based on the snapshot.

16. A method of providing driver functionality, the method comprising:

starting a paravirtualized Virtual Machine (VM) having a limited-functionality operating system on a computing system;

during an attempt to install a host driver in a host operating system (OS), installing a driver stub in the host OS instead of the host driver, wherein the stub is accessible from the VM,

wherein the stub supports Application Programming Interface (API) function calls supported by the host driver, including API interfaces and API call parameters;

installing a VM driver in the VM; and

using a gateway to redirect API requests from the driver stub to the VM driver for execution of the requests in the VM instead of in the host OS, and to transmit responses back from the VM driver to the host OS, wherein the stub provides access to functionality of the VM driver via the gateway and invokes the VM driver through the gateway and using the redirecting,

wherein the VM driver uses the gateway to interface to host API, and

wherein the Virtual Machine directly invokes the host API.

17. A system for managing driver installation comprising:

at least one isolated sandbox on a computing system that has a processor and a memory, the sandbox having a limited functionality operating system (OS);

a driver stub installed in a host OS during an attempt to install a host driver in the host OS to replace the host driver, wherein the stub is accessible from the at least one isolated sandbox,

wherein the stub supports Application Programming Interface (API) function calls supported by the host driver, including API interfaces and API call parameters;

a sandbox driver in the isolated sandbox;

a gateway, which includes a network communication means, that redirects API requests from the driver stub to the sandbox driver for execution of the requests in the sandbox instead of in the host OS, and transmits responses back from the sandbox driver to the host OS,

wherein the stub provides access to functionality of the sandbox driver in the sandbox via the gateway and invokes the sandbox driver through the gateway and using the redirecting; and

wherein the sandbox driver uses the stub through the gateway to interface to host OS API.

Assignments (3)
SECURITY INTEREST IN TRADEMARK, PATENT, AND COPYRIGHT RIGHTS Recorded Dec 22, 2022
From: VIRTUOZZO INTERNATIONAL GMBH; ONAPP LIMITED
To: WILMINGTON TRUST (LONDON) LIMITED
Reel/Frame 062206/0557 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2018
From: PARALLELS IP HOLDINGS GMBH
To: VIRTUOZZO INTERNATIONAL GMBH
Reel/Frame 045179/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2012
From: TORMASOV, ALEXANDER G.; PROTASSOV, STANISLAV S.; BELOUSSOV, SERGUEI M.
To: PARALLELS IP HOLDINGS GMBH
Reel/Frame 029261/0040 →