Company controlled virtual computer over a network
A virtual computer application at a computing device may establish a secure communications channel between the computing device and a private network. The virtual computer application may determine one or more policies that specify one or more actions permitted to be performed by the computing device on documents in the private network based at least in part on context information associated with the computing device. The virtual computer application may determine whether to allow an action to be performed by the computing device on a document in the private network based at least in part on the one or more actions specified by the one or more policies. The virtual computer application may, in response to determining that the action to be performed on the document is not allowed, prevent the computing device from performing the action on the document.
1. A method comprising:
establishing, by a virtual computer application at a computing device, a secure communications channel between the computing device and a private network;
determining, by the virtual computer application, one or more policies that specify one or more actions permitted to be performed by the computing device on documents in the private network based at least in part on context information associated with the computing device;
determining, by the virtual computer application, whether the virtual computer application is able to control operating system-level functionalities of the computing device;
in response to determining that the virtual computer application is not able to control the operating system-level functionalities of the computing device, reducing, by the virtual computer application, a level of actions that can be performed by the computing device on documents in the private network;
determining, by the virtual computer application, whether to allow an action to be performed by the computing device on a document in the private network based at least in part on the one or more actions specified by the one or more policies; and
in response to determining that the action to be performed on the document is allowed, enabling, by the virtual computer application, the computing device to perform the action on the document.
2. The method of claim 1 , wherein determining the one or more policies applicable to the context information associated with the computing device, further comprises:
sending, by the virtual computer application to the private network, an indication of the context information associated with the computing device; and
in response to sending the indication of the context information associated with the computing device, receiving, by the virtual computer application from the private network, the one or more policies that are applicable to the context information associated with the computing device.
3. The method of claim 1 , wherein the context information associated with the computing device comprises one or more of: a location of the computing device, a time of day at the location of the computing device, a privilege level of a user of the computing device, or information associated with the location of the computing device provided by one or more third-party service providers.
4. The method of claim 1 , wherein determining the one or more policies that specify the one or more actions permitted to be performed by the computing device on the documents in the private network based at least in part on the context information associated with the computing device further comprises:
determining, by the virtual computer application, the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and contents of the document.
5. The method of claim 4 , wherein determining the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and the contents of the document further comprises:
determining, by the virtual computer application and based at least in part on the contents of the document, a classification of the document; and
determining, by the virtual computer application, the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and the classification of the document.
6. The method of claim 5 , wherein determining the classification of the document further comprises:
determining, by the virtual computer application and based at least in part on the contents of the document, the classification of the document using one or more machine learning techniques.
7. The method of claim 5 , wherein determining the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and the classification of the document is in response to the virtual computer application receiving a request from the computer device to open the document.
8. The method of claim 1 , wherein the action to be performed by the computing device comprises one of: opening the document at the computing device, saving the document to the computing device, saving the document to an external storage device connected to the computing device, or printing the document.
9. The method of claim 1 , further comprising:
determining, by the virtual computer application and based in part on at least one of: an amount of processing resources available at the computing device or network conditions of the secure communications channel between the computing device and the private network, whether to perform a processing task at the computing device or to offload performance of the processing task to computing resources in the private network.
10. A computing device comprising:
memory configured to store a virtual computer application;
one or more processors in communication with the memory and configured to execute the virtual computer application to:
establish a secure communications channel between the computing device and a private network;
determine one or more policies that specify one or more actions permitted to be performed by the computing device on documents in the private network based at least in part on context information associated with the computing device;
determine whether the virtual computer application is able to control operating system-level functionalities of the computing device;
in response to determining that the virtual computer application is not able to control the operating system-level functionalities of the computing device, reduce a level of actions that can be performed by the computing device on documents in the private network;
determine whether to allow an action to be performed by the computing device on a document in the private network based at least in part on the one or more actions specified by the one or more policies; and
in response to determining that the action to be performed on the document is allowed, enable the computing device to perform the action on the document.
11. The computing device of claim 10 , wherein to determine the one or more policies applicable to the context information associated with the computing device, the one or more processors are further configured to execute the virtual computer application to:
send, to the private network, an indication of the context information associated with the computing device; and
in response to sending the indication of the context information associated with the computing device, receive, from the private network, the one or more policies that are applicable to the context information associated with the computing device.
12. The computing device of claim 10 , wherein the context information associated with the computing device comprises one or more of: a location of the computing device, a time of day at the location of the computing device, a privilege level of a user of the computing device, or information associated with the location of the computing device provided by one or more third-party service providers.
13. The computing device of claim 10 , wherein to determine the one or more policies that specify the one or more actions permitted to be performed by the computing device on the documents in the private network based at least in part on the context information associated with the computing device, the one or more processors are further configured to execute the virtual computer application to:
determine the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and contents of the document.
14. The computing device of claim 13 , wherein to determine the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and the contents of the document, the one or more processors are further configured to execute the virtual computer application to:
determine, based at least in part on the contents of the document, a classification of the document; and
determine the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and the classification of the document.
15. The computing device of claim 14 , wherein to determine the classification of the document, the one or more processors are further configured to execute the virtual computer application to:
determine, based at least in part on the contents of the document, the classification of the document using one or more machine learning techniques.
16. The computing device of claim 14 , wherein the one or more processors are further configured to execute the virtual computer application to determine the one or more policies that specify the one or more actions permitted to be performed by the computing device on the document in the private network based at least in part on the context information associated with the computing device and the classification of the document is in response to the virtual computer application receiving a request from the computer device to open the document.
17. The computing device of claim 10 , wherein the action to be performed by the computing device comprises one of: opening the document at the computing device, saving the document to the computing device, saving the document to an external storage device connected to the computing device, or printing the document.
18. A non-transitory computer-readable storage medium storing instructions of a virtual computer application that, when executed, cause one or more processors of a computing device to:
establish a secure communications channel between the computing device and a private network;
determine one or more policies that specify one or more actions permitted to be performed by the computing device on documents in the private network based at least in part on context information associated with the computing device;
determine whether the virtual computer application is able to control operating system-level functionalities of the computing device;
in response to determining that the virtual computer application is not able to control the operating system-level functionalities of the computing device, reduce a level of actions that can be performed by the computing device on documents in the private network;
determine whether to allow an action to be performed by the computing device on a document in the private network based at least in part on the one or more actions specified by the one or more policies; and
in response to determining that the action to be performed on the document is allowed, enable the computing device to perform the action on the document.