IP Library Granted Patent US 11,016,797
Granted Patent B2
US 11,016,797 · App. 16/382,493 · Granted May 25, 2021

Device security across multiple operating system modalities

Inventors: John Hayes (Mountain View, CA); Volkmar Uhlig (Cupertino, CA)
Assignee: GHOST LOCOMOTION INC.
G06F9/45558G05D1/02G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,016,797
App. No.
16/382,493
Granted
May 25, 2021
Kind
B2
Abstract

Device security across multiple operating system modalities may include allocating, by a hypervisor, to a first virtual machine comprising a first operating system of a first modality, based on the first modality, a first one or more access privileges to one or more resources; and allocating, by the hypervisor, to a second virtual machine comprising a second operating system of a second modality, based on the second modality, a second one or more access privileges to the one or more resources.

Claims (30)

1. A method for device security across multiple operating system modalities comprising:

allocating, by a hypervisor of an autonomous vehicle, to a first virtual machine comprising executing a formally verified first operating system of a first modality, based on the first modality, a first one or more access privileges to one or more resources;

allocating, by the hypervisor, to a second virtual machine comprising executing an unverified second operating system of a second modality, based on the second modality, a second one or more access privileges to the one or more resources; and

modifying, by the hypervisor, the second one or more access privileges based on a change in a state of the autonomous vehicle, wherein the change in the state of the autonomous vehicle comprises the autonomous vehicle entering one or more of:

an autonomous driving mode, a potentially autonomous driving mode, or a stationary mode.

2. The method of claim 1 , wherein the one or more resources comprise one or more devices.

3. The method of claim 1 , further comprising modifying, by the hypervisor, the second one or more access privileges based on a state of the first virtual machine.

4. The method of claim 1 , further comprising passing, by the first virtual machine to the second virtual machine, one or more data values associated with the one or more resources.

5. The method of claim 1 , wherein the change in the state of the autonomous vehicle comprises receiving a command to disable or enable one or more functions of the autonomous vehicle.

6. An apparatus for device security across multiple operating system modalities, the apparatus configured to perform steps comprising:

a one or more processors allocating, by a hypervisor stored in the memory of an autonomous vehicle, to a first virtual machine comprising executing a formally verified first operating system of a first modality, based on the first modality, a first one or more access privileges to one or more resources;

the one or more processors allocating, by the hypervisor stored in the memory of the autonomous vehicle, to a second virtual machine comprising executing an unverified a second operating system of a second modality, based on the second modality, a second one or more access privileges to the one or more resources; and

modifying, by the hypervisor, the second one or more access privileges based on a change in a state of the autonomous vehicle, wherein the change in the state of the autonomous vehicle comprises the autonomous vehicle entering one or more of;

an autonomous driving mode, a potentially autonomous driving mode, or a stationary mode.

7. The apparatus of claim 6 , wherein the one or more resources comprise one or more devices.

8. The apparatus of claim 6 , wherein the steps further comprise modifying, by the hypervisor, the second one or more access privileges based on a state of the first virtual machine.

9. The apparatus of claim 6 , wherein the steps further comprise passing, by the first virtual machine to the second virtual machine, one or more data values associated with the one or more resources.

10. The apparatus of claim 6 , wherein the change in the state of the autonomous vehicle comprises receiving a command to disable or enable one or more functions of the autonomous vehicle.

11. An autonomous vehicle configured device security across multiple operating system modalities, the autonomous vehicle comprising an apparatus configured to perform steps comprising:

a one or more processors allocating, by a hypervisor stored in the memory of the autonomous vehicle, to a first virtual machine comprising executing a formally verified first operating system of a first modality, based on the first modality, a first one or more access privileges to one or more resources;

the one or more processors allocating, by the hypervisor stored in the memory of the autonomous vehicle, to a second virtual machine comprising a second operating system of a second modality, based on the second modality, a second one or more access privileges to the one or more resources; and

modifying, by the hypervisor, the second one or more access privileges based on a change in a state of the autonomous vehicle, wherein the change in the state of the autonomous vehicle comprises the autonomous vehicle entering one or more of:

an autonomous driving mode, a potentially autonomous driving mode, or a stationary mode.

12. The autonomous vehicle of claim 11 , wherein the one or more resources comprise one or more devices.

13. The autonomous vehicle of claim 11 , wherein the steps further comprise modifying, by the hypervisor, the second one or more access privileges based on a state of the first virtual machine.

14. A computer program product disposed upon a non-transitory computer readable medium, the computer program product comprising computer program instructions for device security across multiple operating system modalities that, when executed, cause a computer system to carry out the steps of:

allocating, by a hypervisor of an autonomous vehicle, to a first virtual machine comprising executing a formally verified first operating system of a first modality, based on the first modality, a first one or more access privileges to one or more resources;

allocating, by the hypervisor, to a second virtual machine comprising executing an unverified second operating system of a second modality, based on the second modality, a second one or more access privileges to the one or more resources; and

modifying, by the hypervisor, the second one or more access privileges based on a change in a state of the autonomous vehicle, wherein the change in the state of the autonomous vehicle comprises the autonomous vehicle entering one or more of:

an autonomous driving mode, a potentially autonomous driving mode, or a stationary mode.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2024
From: GHOST AUTONOMY, INC.
To: APPLIED INTUITION, INC.
Reel/Frame 068982/0647 →
CHANGE OF NAME Recorded Aug 8, 2022
From: GHOST LOCOMOTION INC.
To: GHOST AUTONOMY INC.
Reel/Frame 061118/0665 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2019
From: HAYES, JOHN; UHLIG, VOLKMAR
To: GHOST LOCOMOTION INC.
Reel/Frame 048869/0225 →
Continuity (1)
Related Publication 20200326968A1 · Oct 15, 2020
Cited By (1)
US 12,425,412