IP Library Patent Application 17368355
Patent Application
App. No. 17/368,355

MANAGED ISOLATED WORKSPACE ON A USER DEVICE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/368,355
Abstract

A method and system for method for providing a managed and isolated workspace on a user device are provided. The method creating a secured workspace in the user device, wherein the secured workspace is separated from a host operating system and includes a guest operating system; monitoring activity performed in the secured workspace and host operating system; determining, based on a security policy, if the monitored activity is risky; and causing execution of any determined risky activity in the secured workspace, thereby defending the host operating system from the determined risky activity, wherein the host operating system executes sensitive applications to an organization.

Claims (41)

1 . A method for providing a managed and isolated workspace on a user device, comprising:

creating a secured workspace in the user device, wherein the secured workspace is separated from a host operating system and includes a guest operating system;

monitoring activity performed in the secured workspace and host operating system;

determining, based on a security policy, if the monitored activity is risky; and

causing execution of any determined risky activity in the secured workspace, thereby defending the host operating system from the determined risky activity, wherein the host operating system executes sensitive applications to an organization.

2 . The method of claim 1 , further comprising:

establishing a VPN tunnel between the secured workspace and an unsecured network, wherein the unsecured network is separated from a network of the organization.

3 . The method of claim 1 , further comprising:

rendering the secured workspace as a separate desktop on the user device; and

rendering the secured workspace to appear differently than the host operating system.

4 . The method of claim 1 , wherein the monitored activity includes any one of: launching an application, a user interface command, a filesystem command, a network access, a network connectivity, a peripheral device access, and a peripheral device connectivity.

5 . The method of claim 1 , wherein the security policy includes any one of: a catalog of trusted applications, a network policy, a user interface policy, a browsing policy, and a connectivity policy.

6 . The method of claim 4 , wherein causing execution of any determined risky activity in the secured workspace further comprises:

launching an application file determined to be risky in the secured workspace.

7 . The method of claim 4 , wherein causing execution of any determined risky activity in the secured workspace further comprises:

opening a file determined to be risky in the secured workspace.

8 . The method of claim 4 , wherein causing execution of any determined risky activity in the secured workspace further comprises:

allowing any peripheral device connectivity through the workspace only.

9 . The method of claim 4 , wherein causing execution of any determined risky activity in the secured workspace further comprises:

tunneling all traffic from the secured workspace via an established VPN tunnel.

10 . The method of claim 4 , causing execution of any determined risky activity in the secured workspace further comprises:

controlling user interface commands by performing at least one of: limiting clipboard operations and limiting keystroke injection.

11 . The method of claim 1 , further comprising:

watermarking any object displayed on the secured workspace.

12 . The method of claim 1 , wherein the creation of the secured workspace is performed using any one of: existing operating system file binaries, a clean operating system version, and a pre-defined custom operating system version with pre-installed applications.

13 . The method of claim 1 , wherein the secured workspace is non-persistent.

14 . The method of claim 1 , wherein the user device is any one of: a user device managed by the organization and a user device unmanaged by the organization.

15 . The method of claim 1 , wherein the secured workspace and host operating system are controlled by a hypervisor.

16 . The method of claim 15 , wherein the host operating system is executed by a hardware layer of the user device.

17 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to perform a process providing a managed and isolated workspace on a user device, the process comprising:

creating a secured workspace in the user device, wherein the secured workspace is separated from a host operating system and includes a guest operating system;

monitoring activity performed in the secured workspace and host operating system;

determining, based on a security policy, if the monitored activity is risky; and

causing execution of any determined risky activity in the secured workspace, thereby defending the host operating system from the determined risky activity, wherein the host operating system executes sensitive applications to an organization.

18 . A system for providing a managed and isolated workspace on a user device, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

create a secured workspace in the user device, wherein the secured workspace is separated from a host operating system and includes a guest operating system;

monitor activity performed in the secured workspace and host operating system;

determine, based on a security policy, if the monitored activity is risky; and

cause execution of any determined risky activity in the secured workspace, thereby defending the host operating system from the determined risky activity, wherein the host operating system executes sensitive applications to an organization.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2025
From: PERCEPTION POINT LTD.
To: FORTINET, INC.
Reel/Frame 070935/0242 →
SECURITY INTEREST Recorded Mar 26, 2023
From: PERCEPTION POINT LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 063103/0450 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2022
From: HYSOLATE LTD.
To: PERCEPTION POINT LTD.
Reel/Frame 060958/0747 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2021
From: TRABELSI, TOMER; ADLER, NIR; FIGOVSKY, BORIS; ZLOTNIK, OLEG; ZAMIR, TAL
To: HYSOLATE LTD.
Reel/Frame 056765/0278 →