IP Library Granted Patent US 11,343,252
Granted Patent B2
US 11,343,252 · App. 16/679,711 · Granted May 24, 2022

Kernel level application data protection

Inventors: Akash Pati (Bangalore, IN); Shivam Srivastav (Bangalore, IN); Anirudh Singh Rathore (Karnataka, IN)
Assignee: VMWARE, INC.
H04L63/101H04L63/168H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,343,252
App. No.
16/679,711
Granted
May 24, 2022
Kind
B2
Abstract

Disclosed are various examples for kernel level application data protection. In one example, a security label map is written to a kernel layer. The security label map includes a security label and a list of permitted applications for files originated by a protected application. A file access system call is intercepted by kernel-level management instructions. An application identity is identified for an application requesting to access a secure file. Access to the secured file is permitted or denied based on a comparison of the application identity with the list of permitted applications.

Claims (46)

1. A system for web application security through containerization, the system comprising:

a client device comprising at least one processor; and

a data store comprising executable instructions, wherein the instructions, when executed by the at least one processor, cause the client device to at least:

transmit, by a container application to a management service accessed over a network, an identifier of a protected application that is loaded in a container of the container application;

receive, by the container application, in response to transmitting the identifier of the protected application to the management service, a security label for the protected application, and a list of permitted applications that are allowed to access files originated by the protected application, wherein the container application uses the security label to identify and protect the files originated by the protected application;

write a security label map within a kernel layer of the client device, the security label map comprising: the security label, and the list of permitted applications;

generate, by the container application, a secured file by embedding the security label within a file originated by the protected application;

intercept, by kernel-level management instructions, a file access system call to access the secured file;

determine, by the kernel-level management instructions, an application identity for an application that invokes the file access system call; and

permit or deny, by the kernel-level management instructions, access to the secured file based on a comparison of the application identity with the list of permitted applications within the security label map.

2. The system of claim 1 , wherein the container application calls a function that writes the security label map, wherein the function is exposed by a user driver within the kernel layer.

3. The system of claim 1 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

install the protected application on the client device, wherein the security label and the list of permitted applications are received based on the protected application being installed on the client device.

4. The system of claim 1 , wherein the security label is uniquely associated with the protected application.

5. The system of claim 1 , wherein the security label is embedded within an inode table.

6. The system of claim 1 , wherein the kernel-level management instructions permit access to the secured file by passing the file access system call to an inter-process communication mechanism.

7. The system of claim 1 , wherein the kernel-level management instructions deny access to the secured file by preventing the file access system call from being passed to an inter-process communication mechanism.

8. A method performed by instructions executed by a client device, the method comprising:

transmitting, by a container application to a management service accessed over a network, an identifier of a protected application that is loaded in a container of the container application;

receiving, by the container application, in response to transmitting the identifier of the protected application to the management service, a security label for the protected application, and a list of permitted applications that are allowed to access files originated by the protected application, wherein the container application uses the security label to identify and protect the files originated by the protected application;

writing a security label map within a kernel layer of the client device, the security label map comprising: the security label, and the list of permitted applications;

generating, by the container application, a secured file by embedding the security label within a file originated by the protected application;

intercepting, by kernel-level management instructions, a file access system call to access the secured file;

determining, by the kernel-level management instructions, an application identity for an application that invokes the file access system call; and

permitting or denying, by the kernel-level management instructions, access to the secured file based on a comparison of the application identity with the list of permitted applications within the security label map.

9. The method of claim 8 , wherein the container application calls a function that writes the security label map, wherein the function is exposed by a user driver within the kernel layer.

10. The method of claim 8 , further comprising:

installing the protected application on the client device, wherein the security label and the list of permitted applications are received based on the protected application being installed on the client device.

11. The method of claim 8 , wherein the security label is uniquely associated with the protected application.

12. The method of claim 8 , wherein the security label is embedded within an inode table.

13. The method of claim 8 , wherein the kernel-level management instructions permit access to the secured file by passing the file access system call to an inter-process communication mechanism.

14. The method of claim 8 , wherein the kernel-level management instructions deny access to the secured file by preventing the file access system call from being passed to an inter-process communication mechanism.

15. A non-transitory computer-readable medium comprising executable instructions, wherein the instructions, when executed by at least one processor, cause a client device to at least:

transmit, by a container application to a management service accessed over a network, an identifier of a protected application that is loaded in a container of the container application;

receive, by the container application, in response to transmitting the identifier of the protected application to the management service, a security label for the protected application, and a list of permitted applications that are allowed to access files originated by the protected application, wherein the container application uses the security label to identify and protect the files originated by the protected application;

generate, by the container application, a secured file by embedding the security label within a file originated by the protected application;

write a security label map within a kernel layer of the client device, the security label map comprising: the security label, and the list of permitted applications;

intercept, by kernel-level management instructions, a file access system call to access the secured file;

determine, by the kernel-level management instructions, an application identity for an application that invokes the file access system call; and

permit or deny, by the kernel-level management instructions, access to the secured file based on a comparison of the application identity with the list of permitted applications within the security label map.

16. The non-transitory computer-readable medium of claim 15 , wherein the container application calls a function that writes the security label map, wherein the function is exposed by a user driver within the kernel layer.

17. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

install the protected application on the client device, wherein the security label and the list of permitted applications are received based on the protected application being installed on the client device.

18. The non-transitory computer-readable medium of claim 15 , wherein the security label is uniquely associated with the protected application.

19. The non-transitory computer-readable medium of claim 15 , wherein the security label is embedded within an inode table.

20. The non-transitory computer-readable medium of claim 15 , wherein the kernel-level management instructions permit access to the secured file by passing the file access system call to an inter-process communication mechanism.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2021
From: PATI, AKASH; SRIVASTAV, SHIVAM; RATHORE, ANIRUDH SINGH
To: VMWARE, INC.
Reel/Frame 056168/0583 →