IP Library Granted Patent US 11,720,393
Granted Patent B2
US 11,720,393 · App. 17/383,528 · Granted Aug 8, 2023

Enforcing compliance rules using guest management components

Inventor: Adam Michael Hardy (Alpharetta, GA)
Assignee: AIRWATCH LLC
G06F9/45558G06F21/577G06F21/60G06F2009/45587G06F2009/45591G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,720,393
App. No.
17/383,528
Granted
Aug 8, 2023
Kind
B2
Abstract

A system can include a host device that includes a host management component and a virtual machine execution environment with a guest management component. The guest management component receives a data object generated by the host component. The data object specifies host parameters detected for the host device and hypervisor parameters detected for the hypervisor component. The hypervisor component relays the data object from the host management component to the guest management component, which identifies a violation of a compliance rule using this information. The guest management component performs an action based on the violation.

Claims (36)

1. A method, comprising:

receiving, by a guest management component executed within a guest virtual machine executed by a host device, at least one compliance rule from a management service;

receiving, by the guest management component from a hypervisor component, a host environment data object generated by a host management component executed in the host device, the host environment data object specifying host parameters detected for the host device and hypervisor parameters detected for the hypervisor component of the host device, wherein the hypervisor component relays the host environment data object from the host management component to the guest management component, wherein the host environment data object indicates an enrollment status of at least one of the hypervisor component or the host management component;

determining, by the guest management component, a violation of the at least one compliance rule identified based on at least one of the host parameters and the hypervisor parameters; and

performing, by the guest management component, an action based on the violation of the at least one compliance rule.

2. The method of claim 1 , wherein the action comprises transmitting an application programming interface (API) call from the guest management component to at least one of: the hypervisor component, the host component, and a host operating system of the host device.

3. The method of claim 1 , wherein the host environment data object further indicates at least one of: an operating system version, a list of stored files, a list of installed applications, a basic input output system (BIOS) type, and a unified extensible firmware interface (UEFI) version.

4. The method of claim 1 , wherein the action comprises initiating enrollment, with the management service, of at least one of the host management component and the hypervisor component with the management service.

5. The method of claim 1 , wherein the action performed by the guest management component comprises unenrollment, from the management service, of at least one of the host management component and the hypervisor component.

6. The method of claim 1 , further comprising:

transmitting, by the guest management component, a notification of the violation to at least one of: a user of the host device, and an administrator of an enterprise computing environment comprising the host device.

7. The method of claim 1 , wherein the action comprises instructing the hypervisor component to disable data sharing between the host device and the virtual machine.

8. A system, comprising:

a host device comprising at least one processor;

at least one hardware storage device storing instructions executable by the at least one processor, wherein the instructions, when executed by the at least one processor, cause the host device to at least cause the host device to at least:

receive, by a guest management component executed within a guest virtual machine executed by the host device, at least one compliance rule from a management service;

receive, by the guest management component from a hypervisor component, a host environment data object generated by a host management component executed in the host device, the host environment data object specifying host parameters detected for the host device and hypervisor parameters detected for the hypervisor component of the host device, wherein the hypervisor component relays the host environment data object from the host management component to the guest management component;

determine, by the guest management component, a violation of the at least one compliance rule identified based on at least one of the host parameters and the hypervisor parameters; and

perform, by the guest management component, an action based on the violation of the at least one compliance rule, wherein the action comprises causing enrollment, with the management service, of at least one of the host management component and the hypervisor component with the management service.

9. The system of claim 8 , wherein the action comprises transmitting an application programming interface (API) call from the guest management component to at least one of: the hypervisor component, the host component, and a host operating system of the host device.

10. The system of claim 8 , wherein the host environment data object indicates an enrollment status of at least one of the hypervisor component or the host management component.

11. The system of claim 8 , wherein the host environment data object indicates at least one of: an operating system version, a list of stored files, a list of installed applications, a basic input output system (BIOS) type, and a unified extensible firmware interface (UEFI) version.

12. The system of claim 8 , wherein the action performed by the guest management component further comprises unenrollment, from the management service, of the at least one of the host management component and the hypervisor component.

13. The system of claim 8 , wherein the instructions, when executed by the at least one processor, cause the host device to at least:

transmit, by the guest management component, a notification of the violation to at least one of: a user of the host device, and an administrator of an enterprise computing environment comprising the host device.

14. The system of claim 8 , wherein the action comprises instructing the hypervisor component to disable data sharing between the host device and the virtual machine.

15. A non-transitory computer-readable medium storing instructions, wherein the instructions, when executed by at least one processor, cause a host device to at least:

receive, by a guest management component executed within a guest virtual machine executed by the host device, at least one compliance rule from a management service;

receive, by the guest management component from a hypervisor component, a host environment data object generated by a host management component executed in the host device, the host environment data object specifying host parameters detected for the host device and hypervisor parameters detected for the hypervisor component of the host device, wherein the hypervisor component relays the host environment data object from the host management component to the guest management component;

determine, by the guest management component, a violation of the at least one compliance rule identified based on at least one of the host parameters and the hypervisor parameters; and

perform, by the guest management component, an action based on the violation of the at least one compliance rule, wherein the action performed by the guest management component comprises unenrollment, from the management service, of at least one of the host management component and the hypervisor component.

16. The non-transitory computer-readable medium of claim 15 , wherein the action performed by the guest management component comprises transmitting an application programming interface (API) call from the guest management component to at least one of: the hypervisor component, the host component, and a host operating system of the host device.

17. The non-transitory computer-readable medium of claim 15 , wherein the host environment data object indicates an enrollment status of at least one of the hypervisor component or the host management component.

18. The non-transitory computer-readable medium of claim 15 , wherein the action performed by the guest management component further comprises enrollment, with the management service, of the at least one of the host management component and the hypervisor component with the management service.

19. The non-transitory computer-readable medium of claim 15 , wherein the host environment data object indicates at least one of: an operating system version, a list of stored files, a list of installed applications, a basic input output system (BIOS) type, and a unified extensible firmware interface (UEFI) version.

20. The non-transitory computer-readable medium of claim 15 , wherein the action performed by the guest management component further comprises instructing the hypervisor component to disable data sharing between the host device and the virtual machine.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →