IP Library Granted Patent US 10,986,137
Granted Patent B2
US 10,986,137 · App. 15/448,254 · Granted Apr 20, 2021

Clipboard hardening

Inventors: Rahul C. Kashyap (Foster City, CA); Rafal Wojtczuk (Warsaw, PL); Ian Pratt (Cambridge, GB)
Assignee: Hewlett-Packard Development Company, L.P.
H04L63/205G06F21/6209G06F21/6218H04L63/1491H04L63/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,986,137
App. No.
15/448,254
Granted
Apr 20, 2021
Kind
B2
Abstract

A software module executes in a first isolated execution environment. The module determines the first environment has caused data to the written to a first clipboard maintained by the first environment. The module consults policy data to determine whether the data should additionally be written to a second clipboard maintained by a second isolated execution environment. The policy data does not allow one or more types of clipboard objects to be written to the second clipboard even if they were written to the first clipboard at the initiation of or approved by a user to prevent the user from introducing a potentially hazardous type of object into the second clipboard. Upon the module determining that the policy data allows the data to be written to the second clipboard, the software module causes the data to written to the second clipboard.

Claims (44)

1. One or more non-transitory machine-readable storage mediums storing one or more sequences of instructions, which when executed by one or more processors, cause:

upon a software module, executing in a first isolated execution environment, determining that the first isolated execution environment has caused data to the written to a first clipboard maintained by the first isolated execution environment, the software module consulting policy data to determine whether the data should additionally be written to a second clipboard maintained by a second isolated execution environment,

wherein the policy data does not allow one or more types of clipboard objects to be written to the second clipboard even if a particular object of said one or more types of clipboard objects was written to the first clipboard at the initiation of or approval by a user to prevent said user from introducing a potentially hazardous type of object into said second clipboard;

upon the software module being instructed by said policy data that a portion of said data is said potentially hazardous type of object, the software module converting said portion to a simpler format of object which removes or renders insert any malicious code contained in said portion; and

upon the software module determining that the policy data allows the data to be written to the second clipboard, the software module causing the data to be written to the second clipboard, wherein the data written to the second clipboard includes said portion converted to said simpler format of object.

2. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein execution of the one or more sequences of instructions further cause:

the software module, in consultation with the policy data, verifying said data prior to permitting said data to be written to the second clipboard maintained by the second isolated execution environment.

3. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the policy data resides within the second isolated execution environment.

4. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein execution of the one or more sequences of instructions further causes:

upon determining that a particular policy defined by the policy data considers separate data transfers to the first clipboard as a single logical unit, the software module causing each of the separate data transfers to be written to the second clipboard as one logical unit after determining the policy data allows the separate data transfers to be written to the second clipboard.

5. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the software module consulting the policy data further comprises:

the software module determining whether the policy defined by the policy data permits an object type of data written to a first clipboard to be written to the second clipboard maintained by the second isolated execution environment.

6. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein a policy defined by the policy data is dependent upon, at least in part, a level of trust between the first isolated execution environment and the second isolated execution environment.

7. The one or more non-transitory machine-readable storage mediums of claim 1 , wherein the policy data permits an otherwise impermissible action if the first isolated execution environment is a host operating system.

8. An apparatus, comprising:

one or more processors; and

one or more non-transitory machine-readable storage mediums storing one or more sequences of instructions, which when executed, cause:

upon a software module, executing in a first isolated execution environment, determining that the first isolated execution environment has caused data to be written to a first clipboard maintained by the first isolated execution environment, the software module consulting policy data to determine whether the data should additionally be written to a second clipboard maintained by a second isolated execution environment,

wherein the policy data does not allow one or more types of clipboard objects to be written to the second clipboard even if a particular object of said one or more types of clipboard objects was written to the first clipboard at the initiation of or approval by a user to prevent said user from introducing a potentially hazardous type of object into said second clipboard;

upon the software module being instructed by said policy data that a portion of said data is said potentially hazardous type of object, the software module converting said portion to a simpler format of object which removes or renders insert any malicious code contained in said portion; and

upon the software module determining that the policy data allows the data to be written to the second clipboard, the software module causing the data to be written to the second clipboard, wherein the data written to the second clipboard includes said portion converted to said simpler format of object.

9. The apparatus of claim 8 , wherein execution of the one or more sequences of instructions further cause:

the software module, in consultation with the policy data, verifying said data prior to permitting said data to be written to the second clipboard maintained by the second isolated execution environment.

10. The apparatus of claim 8 , wherein the policy data resides within the second isolated execution environment.

11. The apparatus of claim 8 , wherein execution of the one or more sequences of instructions further causes:

upon determining that a particular policy defined by the policy data considers separate data transfers to the first clipboard as a single logical unit, the software module causing each of the separate data transfers to be written to the second clipboard as one logical unit after determining the policy data allows the separate data transfers to be written to the second clipboard.

12. The apparatus of claim 8 , wherein the software module consulting the policy data further comprises:

the software module determining whether the policy defined by the policy data permits an object type of data written to a first clipboard to be written to the second clipboard maintained by the second isolated execution environment.

13. The apparatus of claim 8 , wherein a policy defined by the policy data is dependent upon, at least in part, a level of trust between the first isolated execution environment and the second isolated execution environment.

14. The apparatus of claim 8 , wherein the policy data permits an otherwise impermissible action if the first isolated execution environment is a host operating system.

15. A method performed by one or more processors executing one or more sequences of instructions, comprising:

upon a software module, executing in a first isolated execution environment, determining that the first isolated execution environment has caused data to be written to a first clipboard maintained by the first isolated execution environment, the software module consulting policy data to determine whether the data should additionally be written to a second clipboard maintained by a second isolated execution environment,

wherein the policy data does not allow one or more types of clipboard objects to be written to the second clipboard even if a particular object of said one or more types of clipboard objects was written to the first clipboard at the initiation of or approval by a user to prevent said user from introducing a potentially hazardous type of object into said second clipboard;

upon the software module being instructed by said policy data that a portion of said data is said potentially hazardous type of object, the software module converting said portion to a simpler format of object which removes or renders insert any malicious code contained in said portion; and

upon the software module determining that the policy data allows the data to be written to the second clipboard, the software module causing the data to be written to the second clipboard, wherein the data written to the second clipboard includes said portion converted to said simpler format of object.

16. The method of claim 15 , wherein execution of the one or more sequences of instructions further cause:

the software module, in consultation with the policy data, verifying said data prior to permitting said data to be written to the second clipboard maintained by the second isolated execution environment.

17. The method of claim 15 , wherein the policy data resides within the second isolated execution environment.

18. The method of claim 15 , wherein execution of the one or more sequences of instructions further causes:

upon determining that a particular policy defined by the policy data considers separate data transfers to the first clipboard as a single logical unit, the software module causing each of the separate data transfers to be written to the second clipboard as one logical unit after determining the policy data allows the separate data transfers to be written to the second clipboard.

19. The method of claim 15 , wherein the software module consulting the policy data further comprises:

the software module determining whether the policy defined by the policy data permits an object type of data written to a first clipboard to be written to the second clipboard maintained by the second isolated execution environment.

20. The method of claim 15 , wherein a policy defined by the policy data is dependent upon, at least in part, a level of trust between the first isolated execution environment and the second isolated execution environment.

21. The method of claim 15 , wherein the policy data permits an otherwise impermissible action if the first isolated execution environment is a host operating system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2019
From: BROMIUM, INC.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 051305/0894 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2018
From: KASHYAP, RAHUL C; WOJTCZUK, RAFAL; PRATT, IAN
To: BROMIUM, INC.
Reel/Frame 045009/0895 →
Continuity (4)
Continuation In Part 15284305 · Oct 3, 2016
Continuation 13923212 · Jun 20, 2013
Provisional Application 61662288 · Jun 20, 2012
Related Publication 20170180427A1 · Jun 22, 2017