IP Library Granted Patent US 10,216,961
Granted Patent B2
US 10,216,961 · App. 15/008,377 · Granted Feb 26, 2019

Enforcing restrictions related to a virtualized computer environment

Inventors: Matthew David Ginzton (San Francisco, CA); Matthew B. Eccleston (San Francisco, CA); Srinivas Krishnamurti (Palo Alto, CA); Gerald C. Chen (San Francisco, CA); Nick Michael Ryan (Sunnyvale, CA)
Assignee: VMware, Inc.
G06F21/6281G06F9/45558G06F12/1408H04L63/0236G06F2009/45587G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,216,961
App. No.
15/008,377
Granted
Feb 26, 2019
Kind
B2
Abstract

An administrator may set restrictions related to the operation of a virtual machine (VM), and virtualization software enforces such restrictions. There may be restrictions related to the general use of the VM, such as who may use the VM, when the VM may be used, and on what physical computers the VM may be used. There may be similar restrictions related to a general ability to modify a VM, such as who may modify the VM. There may also be restrictions related to what modifications may be made to a VM, such as whether the VM may be modified to enable access to various devices or other resources. There may also be restrictions related to how the VM may be used and what may be done with the VM. Information related to the VM and any restrictions placed on the operation of the VM may be encrypted to inhibit a user from circumventing the restrictions.

Claims (49)

1. A method, comprising:

distributing a complete installation package for a virtual computer system to each of multiple user physical computer systems, wherein the complete installation package is installable on each of the user physical computer systems to provide a virtual machine (VM) with restricted access to the VM, the complete installation package including the VM and enforcer software for enforcing one or more restrictions related to operation of the VM, wherein the enforcer software is configured to execute on the user physical system on which the VM runs but not within any VM on which the one or more restrictions are enforced and not within any virtualization software; and

on each of the multiple user physical computer systems:

installing the complete installation package including the VM and the enforcer software;

executing the VM, the VM giving a user access to guest software on the VM via virtualization software that emulates virtual system hardware for the VM, the VM being executed using the virtualization software and a virtual disk for storing data accessible to the guest software;

determining whether an action violates the one or more restrictions related to operation of the VM; and

in response to determining that the action violates the one or more restrictions, enforcing the one or more restrictions using the enforcer software by intercepting the action relating to operation of the VM that violates the one or more restrictions and restricting the action relating to the operation of the VM that violates the one or more restrictions.

2. The method of claim 1 , wherein the one or more restrictions are indicated in restriction information contained in a policy file, a copy of which file is distributed to and stored on a storage device in the corresponding physical computer system, and wherein the enforcer software uses the restriction information in the policy file to determine the one or more restrictions to be enforced.

3. The method of claim 2 , wherein the restriction information is encrypted before it is written to the storage device, and further wherein the enforcer software decrypts the encrypted restriction information upon reading the encrypted restriction information from the storage device.

4. The method of claim 1 , wherein distributing the VM further comprises:

generating a VM folder using a VM manager, the VM folder containing a VM configuration file, a virtual disk file, and a policy file indicating the one or more restrictions, wherein the one or more restrictions are specified by an administrator;

encrypting the VM folder using cryptographic software; and

distributing the encrypted VM folder from the VM manager to the corresponding physical computer system.

5. The method of claim 1 , wherein at least one of the one or more restrictions specifies at least one of when the VM may be used and a date after which the VM may not be used.

6. The method of claim 1 , wherein at least one of the one or more restrictions prevents transferring code or data into or out of the VM by restricting access to any removable or disconnectable device or by restricting network access.

7. The method of claim 1 , wherein at least one of the one or more restrictions is a restriction that specifies one or more physical computer systems on which the VM may be executed, wherein the VM is prevented from being executed on a non-specified physical computer system.

8. A physical computing system, comprising:

at least one physical processor; and

physical memory including instructions that, when executed by the at least one processor, cause the computing system to perform a method comprising:

distributing a complete installation package for a virtual computer system to each of multiple user physical computer systems, wherein the complete installation package is installable on each of the user physical computer systems to provide a virtual machine (VM) with restricted access to the VM, the complete installation package including the VM and enforcer software for enforcing one or more restrictions related to operation of the VM, wherein the enforcer software is configured to execute on the user physical system on which the VM runs but not within any VM on which the one or more restrictions are enforced and not within any virtualization software; and

on each of the multiple user physical computer systems:

installing the complete installation package including the VM and the enforcer software;

executing the VM, the VM giving a user access to guest software on the VM via virtualization software that emulates virtual system hardware for the VM, the VM being executed using the virtualization software and a virtual disk for storing data accessible to the guest software;

determining whether an action violates the one or more restrictions related to operation of the VM; and

in response to determining that the action violates the one or more restrictions, enforcing the one or more restrictions using the enforcer software by intercepting the action relating to operation of the VM that violates the one or more restrictions and restricting the action relating to the operation of the VM that violates the one or more restrictions.

9. The computing system of claim 8 , wherein the one or more restrictions are indicated in restriction information contained in a policy file, a copy of which file is distributed to and stored on a storage device in the corresponding physical computer system, and wherein the enforcer software uses the restriction information in the policy file to determine the one or more restrictions to be enforced.

10. The computing system of claim 9 , wherein the restriction information is encrypted before it is written to the storage device, and further wherein the enforcer software decrypts the encrypted restriction information upon reading the encrypted restriction information from the storage device.

11. The computing system of claim 8 , wherein distributing the VM further comprises:

generating a VM folder using a VM manager, the VM folder containing a VM configuration file, a virtual disk file, and a policy file indicating the one or more restrictions, wherein the one or more restrictions are specified by an administrator;

encrypting the VM folder using cryptographic software; and

distributing the encrypted VM folder from the VM manager to the corresponding physical computer system.

12. The computing system of claim 8 , wherein at least one of the one or more restrictions specifies at least one of when the VM may be used and a date after which the VM may not be used.

13. The computing system of claim 8 , wherein at least one of the one or more restrictions prevents transferring code or data into or out of the VM by restricting access to any removable or disconnectable device or by restricting network access.

14. The computing system of claim 8 , wherein at least one of the one or more restrictions is a restriction that specifies one or more physical computer systems on which the VM may be executed, wherein the VM is prevented from being executed on a non-specified physical computer system.

15. A non-transitory computer readable storage medium comprising one or more sequences of instructions, the instructions, when executed by one or more processors of a computing system, causing the computing system to execute the operations of:

distributing a complete installation package for a virtual computer system to each of multiple user physical computer systems, wherein the complete installation package is installable on each of the user physical computer systems to provide a virtual machine (VM) with restricted access to the VM, the complete installation package including the VM and enforcer software for enforcing one or more restrictions related to operation of the VM, wherein the enforcer software is configured to execute on the user physical system on which the VM runs but not within any VM on which the one or more restrictions are enforced and not within any virtualization software; and

on each of the multiple user physical computer systems:

installing the complete installation package including the VM and the enforcer software;

executing the VM, the VM giving a user access to guest software on the VM via virtualization software that emulates virtual system hardware for the VM, the VM being executed using the virtualization software and a virtual disk for storing data accessible to the guest software;

determining whether an action violates the one or more restrictions related to operation of the VM; and

in response to determining that the action violates the one or more restrictions, enforcing the one or more restrictions using the enforcer software by intercepting the action relating to operation of the VM that violates the one or more restrictions and restricting the action relating to the operation of the VM that violates the one or more restrictions.

16. The non-transitory computer readable storage medium of claim 15 , wherein the one or more restrictions are indicated in restriction information contained in a policy file, a copy of which file is distributed to and stored on a storage device in the corresponding physical computer system, and wherein the enforcer software uses the restriction information in the policy file to determine the one or more restrictions to be enforced.

17. The non-transitory computer readable storage medium of claim 16 , wherein the restriction information is encrypted before it is written to the storage device, and further wherein the enforcer software decrypts the encrypted restriction information upon reading the encrypted restriction information from the storage device.

18. The non-transitory computer readable storage medium of claim 15 , wherein distributing the VM further comprises:

generating a VM folder using a VM manager, the VM folder containing a VM configuration file, a virtual disk file, and a policy file indicating the one or more restrictions, wherein the one or more restrictions are specified by an administrator;

encrypting the VM folder using cryptographic software; and

distributing the encrypted VM folder from the VM manager to the corresponding physical computer system.

19. The non-transitory computer readable storage medium of claim 15 , wherein at least one of the one or more restrictions specifies at least one of when the VM may be used and a date after which the VM may not be used.

20. The non-transitory computer readable storage medium of claim 15 , wherein at least one of the one or more restrictions prevents transferring code or data into or out of the VM by restricting access to any removable or disconnectable device or by restricting network access.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
Continuity (5)
Continuation 14340506 · Jul 24, 2014
Continuation 13853766 · Mar 29, 2013
Division 11522172 · Sep 14, 2006
Provisional Application 60718656 · Sep 19, 2005
Related Publication 20160154949A1 · Jun 2, 2016
Cited By (1)
US 12,301,561