IP Library Granted Patent US 11,882,123
Granted Patent B2
US 11,882,123 · App. 17/747,251 · Granted Jan 23, 2024

Kernel level application data protection

Inventors: Akash Pati (Bangalore, IN); Shivam Srivastav (Bangalore, IN); Anirudh Singh Rathore (Karnataka, IN)
Assignee: VMware, Inc.
H04L63/101H04L63/168H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,882,123
App. No.
17/747,251
Granted
Jan 23, 2024
Kind
B2
Abstract

Disclosed are various examples for kernel level application data protection. In one example, a security label and a list of permitted applications are received. The security label is utilized to limit access to files that embed the security label. A security label map is written within a kernel layer of the client device. The security label map includes the security label and the list of permitted applications. A secured file is generated by embedding the security label within a file stored on the client device.

Claims (40)

1. A system comprising:

a client device comprising at least one processor; and

a data store comprising executable instructions, wherein the instructions, when executed by the at least one processor, cause the client device to at least:

receive, by a management agent executed by the client device, a security label and a list of permitted applications, wherein the security label is utilized to limit access to files that embed the security label;

invoke, by the management agent executed in user space of the client device, a security label map writing function exposed to the management agent in user space by a user driver executed in kernel space, wherein the user driver writes a security label map within a kernel layer of the client device, the security label map comprising: the security label and the list of permitted applications; and

generate a secured file by embedding the security label within a file stored on the client device.

2. The system of claim 1 , wherein the security label map comprises: an originating application, the security label, and the list of permitted applications permitted to access files originated by the originating application.

3. The system of claim 1 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

install a protected application on the client device, wherein the security label and the list of permitted applications are associated with the protected application within the security label map.

4. The system of claim 1 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

identify, by the management agent, that a protected application is installed on the client device.

5. The system of claim 1 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

identify, by the management agent, that the file is originated by a protected application.

6. The system of claim 5 , wherein the management agent generates the secured file in an instance in which the file is originated by the protected application.

7. The system of claim 6 , wherein the protected application originates the file by creating, downloading, or receiving the file.

8. A method performed by instructions executed by a client device, the method comprising:

receiving, by a management agent executed by the client device, a security label and a list of permitted applications, wherein the security label is utilized to limit access to files that embed the security label;

invoking, by the management agent executed in user space of the client device, a security label map writing function exposed to the management agent in user space by a user driver executed in kernel space, wherein the user driver writes a security label map within a kernel layer of the client device, the security label map comprising: the security label and the list of permitted applications; and

generating a secured file by embedding the security label within a file stored on the client device.

9. The method of claim 8 , wherein the security label map comprises: an originating application, the security label, and the list of permitted applications permitted to access files originated by the originating application.

10. The method of claim 8 , further comprising:

installing a protected application on the client device, wherein the security label and the list of permitted applications are associated with the protected application within the security label map.

11. The method of claim 8 , further comprising:

identifying, by the management agent, that a protected application is installed on the client device.

12. The method of claim 8 , further comprising:

identify, by the management agent, that the file is originated by a protected application.

13. The method of claim 12 , wherein the management agent generates the secured file in an instance in which the file is originated by the protected application.

14. The method of claim 13 , wherein the protected application originates the file by creating, downloading, or receiving the file.

15. A non-transitory computer-readable medium comprising executable instructions, wherein the instructions, when executed by at least one processor, cause a client device to at least:

receive, by a management agent executed by the client device, a security label and a list of permitted applications, wherein the security label is utilized to limit access to files that embed the security label;

invoke, by the management agent executed in user space of the client device, a security label map writing function exposed to the management agent in user space by a user driver executed in kernel space, wherein the user driver writes a security label map within a kernel layer of the client device, the security label map comprising: the security label and the list of permitted applications; and

generate a secured file by embedding the security label within a file stored on the client device.

16. The non-transitory computer-readable medium of claim 15 , wherein the security label map comprises: an originating application, the security label, and the list of permitted applications permitted to access files originated by the originating application.

17. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

install a protected application on the client device, wherein the security label and the list of permitted applications are associated with the protected application within the security label map.

18. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

identify, by the management agent, that a protected application is installed on the client device.

19. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the at least one processor, cause the client device to at least:

identify, by the management agent, that the file is originated by a protected application.

20. The non-transitory computer-readable medium of claim 19 , wherein the management agent generates the secured file in an instance in which the file is originated by the protected application.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →