IP Library Granted Patent US 10,846,396
Granted Patent B1
US 10,846,396 · App. 14/328,189 · Granted Nov 24, 2020

Downloading data in a dedicated virtual machine

Inventors: Gaurav Banga (Cupertino, CA); Ian Pratt (Cambridge, GB); Vikram Kapoor (Cupertino, CA); Kiran Bondalapati (Los Altos, CA)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/53G06F9/455G06F9/468G06F21/62G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,846,396
App. No.
14/328,189
Granted
Nov 24, 2020
Kind
B1
Abstract

Embodiments of the invention enable any request to download data to a computer system to be performed such that the requested data is stored in a dedicated virtual machine. A request to transfer data from an external location to the computer system is received. The request may originate from a process in a virtual machine or a host operating system. A connection with the external location using parameters identified in the request. The request is performed by transferring the data from the external location to a dedicated virtual machine which does not have access to the file system and cannot persistently store data on the computer system. One or more dedicated virtual machines may be instantiated as needed. A single dedicated virtual machine may accommodate multiple downloads concurrently.

Claims (30)

1. A non-transitory computer-readable storage medium that stores one or more sequences of instructions for safely receiving information from an apparatus, which when executed by one or more processors, causes:

upon intercepting, at a network stack level on a computer system, from a process executing within a first virtual machine or a host operating system running on the computer system, a request to transfer data from an external location to the computer system, initiating a connection with the external location using parameters identified in the request; and

performing the request by transferring the data from the external location to a second virtual machine, running on the computer system, which is prohibited from interpreting or executing the data transferred from the external location.

2. The non-transitory computer-readable storage medium of claim 1 , wherein the second virtual machine is instantiated in response to determining that the process is requesting to transfer data from an external location.

3. The non-transitory computer-readable storage medium of claim 1 , wherein the second virtual machine is receiving data concurrently from a plurality of external locations.

4. The non-transitory computer-readable storage medium of claim 1 , wherein initiating the connection is performed by the second virtual machine.

5. The non-transitory computer-readable storage medium of claim 1 , wherein initiating the connection is performed by a host module that executes external to the first virtual machine or the second virtual machine.

6. The non-transitory computer-readable storage medium of claim 1 , wherein the parameters identified in the request includes at least one cookie associated with the external location.

7. The non-transitory computer-readable storage medium of claim 1 , wherein the second virtual machine does not have access to the file system of the computer system and cannot persistently store data on the computer system.

8. The non-transitory computer-readable storage medium of claim 1 , wherein intercepting, at the network stack level, a request to transfer data from said external location to the computer system is performed using a network stack of the host operating system.

9. An apparatus configured to safely receive information from another apparatus, comprising:

one or more processors; and

one or more non-transitory computer-readable storage mediums storing one or more sequences of instructions, which when executed by the one or more processors, causes:

upon intercepting, at a network stack level on a computer system, from a process executing within a first virtual machine or a host operating system running on the computer system, a request to transfer data from an external location to the computer system, initiating a connection with the external location using parameters identified in the request; and

performing the request by transferring the data from the external location to a second virtual machine, running on the computer system, which is prohibited from interpreting or executing the data transferred from the external location.

10. The apparatus of claim 9 , wherein the second virtual machine is instantiated in response to determining that the process is requesting to transfer data from an external location.

11. The apparatus of claim 9 , wherein the second virtual machine is receiving data concurrently from a plurality of external locations.

12. The apparatus of claim 9 , wherein initiating the connection is performed by the second virtual machine.

13. The apparatus of claim 9 , wherein initiating the connection is performed by a host module that executes external to the first virtual machine or the second virtual machine.

14. The apparatus of claim 9 , wherein the parameters identified in the request includes at least one cookie associated with the external location.

15. The apparatus of claim 9 , wherein the second virtual machine does not have access to the file system of the computer system and cannot persistently store data on the computer system.

16. A method for safely receiving information from another apparatus, comprising:

upon intercepting, at a network stack level on a computer system, from a process executing within a first virtual machine or a host operating system running on the computer system, a request to transfer data from an external location to the computer system, initiating a connection with the external location using parameters identified in the request; and

performing the request by transferring the data from the external location to a second virtual machine, running on the computer system, which is prohibited from interpreting or executing the data transferred from the external location.

17. The method of claim 16 , wherein the second virtual machine is instantiated in response to determining that the process is requesting to transfer data from an external location.

18. The method of claim 16 , wherein the second virtual machine is receiving data concurrently from a plurality of external locations.

19. The method of claim 16 , wherein initiating the connection is performed by the second virtual machine.

20. The method of claim 16 , wherein initiating the connection is performed by a host module that executes external to the first virtual machine or the second virtual machine.

21. The method of claim 16 , wherein the parameters identified in the request includes at least one cookie associated with the external location.

22. The method of claim 16 , wherein the second virtual machine does not have access to the file system of the computer system and cannot persistently store data on the computer system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2019
From: BROMIUM, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 051305/0894 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2014
From: BANGA, GAURAV; PRATT, IAN; KAPOOR, VIKRAM; BONDALAPATI, KIRAN
To: BROMIUM, INC.
Reel/Frame 033288/0730 →
Continuity (3)
Continuation In Part 13526354 · Jun 18, 2012
Continuation In Part 13419345 · Mar 13, 2012
Continuation In Part 13115354 · May 25, 2011
Cited By (1)
US 12,625,959