IP Library Granted Patent US 11,875,177
Granted Patent B1
US 11,875,177 · App. 17/985,388 · Granted Jan 16, 2024

Variable access privileges for secure resources in an autonomous vehicle

Inventors: John Hayes (Mountain View, CA); Volkmar Uhlig (Cupertino, CA)
Assignee: GHOST AUTONOMY INC.
G06F9/45558G05D1/02G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,875,177
App. No.
17/985,388
Granted
Jan 16, 2024
Kind
B1
Abstract

Variable access privileges for secure resources in an autonomous vehicle, including: allocating, by a hypervisor, to a first virtual machine comprising a first operating system, a first one or more access privileges to one or more resources; allocating, by the hypervisor, to a second virtual machine comprising a second operating system different than the first operating system, a second one or more access privileges to the one or more resources; and modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine; wherein the hypervisor, the first virtual machine, and the second virtual machine are implemented by an autonomous vehicle.

Claims (37)

1. A method comprising:

configuring, by a hypervisor, a first virtual machine to have a first one or more access privileges to one or more resources, wherein the first virtual machine comprises a first operating system having a first combination of non-exclusive modalities, wherein the hypervisor determines the first one or more access privileges by accessing a data structure that associates particular combinations of non-exclusive modalities with corresponding access privileges;

configuring, by the hypervisor, a second virtual machine to have a second one or more access privileges to the one or more resources, wherein the second virtual machine comprises a second operating system different from the first operating system and having a second combination of non-exclusive modalities, wherein the hypervisor determines the second one or more access privileges by accessing the data structure; and

modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine;

wherein the hypervisor, the first virtual machine, and the second virtual machine are implemented by an autonomous vehicle.

2. The method of claim 1 , wherein the change in the execution state of the first virtual machine comprises one or more of: a suspension of the first virtual machine, a termination of the first virtual machine, or a resuming execution of the first virtual machine.

3. The method of claim 1 , wherein the one or more resources comprise one or more devices.

4. The method of claim 1 , wherein the first operating system comprises a formally verified operating system and the second operating system comprises an unverified operating system.

5. The method of claim 1 , further comprising passing, by the first virtual machine to the second virtual machine, one or more data values associated with the one or more resources.

6. An apparatus comprising:

one or more processors and memory, wherein the one or more processors are configured to perform steps comprising:

configuring, by a hypervisor, a first virtual machine to have a first one or more access privileges to one or more resources, wherein the first virtual machine comprises a first operating system having a first combination of non-exclusive modalities, wherein the hypervisor determines the first one or more access privileges by accessing a data structure that associates particular combinations of non-exclusive modalities with corresponding access privileges;

configuring, by the hypervisor, a second virtual machine to have a second one or more access privileges to the one or more resources, wherein the second virtual machine comprises a second operating system different from the first operating system and having a second combination of non-exclusive modalities, wherein the hypervisor determines the second one or more access privileges by accessing the data structure; and

modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine;

wherein the hypervisor, the first virtual machine, and the second virtual machine are implemented by an autonomous vehicle.

7. The apparatus of claim 6 , wherein the change in the execution state of the first virtual machine comprises one or more of: a suspension of the first virtual machine, a termination of the first virtual machine, or a resuming execution of the first virtual machine.

8. The apparatus of claim 6 , wherein the one or more resources comprise one or more devices.

9. The apparatus of claim 6 , wherein the first operating system comprises a formally verified operating system and the second operating system comprises an unverified operating system.

10. The apparatus of claim 6 , wherein the steps further comprise passing, by the first virtual machine to the second virtual machine, one or more data values associated with the one or more resources.

11. An autonomous vehicle comprising:

an apparatus comprising one or more processors and memory, wherein the one or more processors are configured to perform steps comprising:

configuring, by a hypervisor, a first virtual machine to have a first one or more access privileges to one or more resources, wherein the first virtual machine comprises a first operating system having a first combination of non-exclusive modalities, wherein the hypervisor determines the first one or more access privileges by accessing a data structure that associates particular combinations of non-exclusive modalities with corresponding access privileges;

configuring, by the hypervisor, a second virtual machine to have a second one or more access privileges to the one or more resources, wherein the second virtual machine comprises a second operating system different from the first operating system and having a second combination of non-exclusive modalities, wherein the hypervisor determines the second one or more access privileges by accessing the data structure; and

modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine.

12. The autonomous vehicle of claim 11 , wherein the change in the execution state of the first virtual machine comprises one or more of: a suspension of the first virtual machine, a termination of the first virtual machine, or a resuming execution of the first virtual machine.

13. The autonomous vehicle of claim 11 , wherein the one or more resources comprise one or more devices.

14. The autonomous vehicle of claim 11 , wherein the first operating system comprises a formally verified operating system and the second operating system comprises an unverified operating system.

15. The autonomous vehicle of claim 11 , wherein the steps further comprise passing, by the first virtual machine to the second virtual machine, one or more data values associated with the one or more resources.

16. A computer program product disposed upon a non-transitory computer readable storage medium, the computer program product comprising computer program instructions that, when executed, cause a computer system to carry out steps comprising:

configuring, by a hypervisor, a first virtual machine to have a first one or more access privileges to one or more resources, wherein the first virtual machine comprises a first operating system having a first combination of non-exclusive modalities, wherein the hypervisor determines the first one or more access privileges by accessing a data structure that associates particular combinations of non-exclusive modalities with corresponding access privileges;

configuring, by the hypervisor, a second virtual machine to have a second one or more access privileges to the one or more resources, wherein the second virtual machine comprises a second operating system different from the first operating system and having a second combination of non-exclusive modalities, wherein the hypervisor determines the second one or more access privileges by accessing the data structure; and

modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine;

wherein the hypervisor, the first virtual machine, and the second virtual machine are implemented by an autonomous vehicle.

17. The computer program product of claim 16 , wherein the change in the execution state of the first virtual machine comprises one or more of: a suspension of the first virtual machine, a termination of the first virtual machine, or a resuming execution of the first virtual machine.

18. The computer program product of claim 16 , wherein the one or more resources comprise one or more devices.

19. The computer program product of claim 16 , wherein the first operating system comprises a formally verified operating system and the second operating system comprises an unverified operating system.

20. The computer program product of claim 16 , wherein the steps further comprise passing, by the first virtual machine to the second virtual machine, one or more data values associated with the one or more resources.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2024
From: GHOST AUTONOMY, INC.
To: APPLIED INTUITION, INC.
Reel/Frame 068982/0647 →
CHANGE OF NAME Recorded Sep 5, 2023
From: GHOST LOCOMOTION INC.
To: GHOST AUTONOMY INC.
Reel/Frame 064808/0661 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2022
From: HAYES, JOHN; UHLIG, VOLKMAR
To: GHOST LOCOMOTION INC.
Reel/Frame 061736/0983 →
Continuity (2)
Continuation 17328616 · May 24, 2021
Continuation 16382493 · Apr 12, 2019
Cited By (1)
US 12,248,852