IP Library Granted Patent US 12,111,915
Granted Patent B2
US 12,111,915 · App. 18/300,088 · Granted Oct 8, 2024

Security-enhanced file open and download

Inventors: Sisimon Soman (Sunnyvale, CA); Arun Padoor Chandramohan (Singapore, SG)
Assignee: Omnissa, LLC
G06F21/53G06F9/45558G06F16/954G06F21/566G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,111,915
App. No.
18/300,088
Granted
Oct 8, 2024
Kind
B2
Abstract

A method of downloading or opening a file in response to a user input made through an application running in the computer system, includes the steps of detecting by the application that the user input is to download or open a file, issuing a request by the application to a file sanitation server to sanitize the file to remove embedded codes in the file and return the sanitized file, and upon receiving the sanitized file by the application, saving the sanitized file in a folder where the sanitized file can be opened.

Claims (42)

1. A method of downloading a file in response to a user input made through a remote desktop application running on a client device, comprising:

transmitting the user input made through the remote desktop application from the client device to a virtual computing instance that is executing in a physical machine connected to the client device over a network and hosting a remote desktop service for the client device;

detecting, by an application running inside the virtual computing instance, that the user input is to download a file through the application;

issuing, by an extension of the application running inside the virtual computing instance, a request to download the file from a specified location corresponding to the user input, sanitize the downloaded file to remove embedded codes in the downloaded file, and return the sanitized file;

sending, by a sanitation agent running inside the virtual computing instance, the request to a file sanitation server;

receiving, by the sanitation agent, the sanitized file from the file sanitation server; and

upon receiving the sanitized file by the sanitation agent, saving the sanitized file in a folder managed by the virtual computing instance.

2. The method of claim 1 , wherein the application is a browser.

3. The method of claim 2 , wherein the browser is running in an isolated execution space.

4. The method of claim 1 , wherein the application is an e-mail application.

5. The method of claim 4 , wherein the e-mail application is running in an isolated execution space.

6. The method of claim 1 , wherein the virtual computing instance is one of a plurality of virtual machines that are isolated from each other and executing in the physical machine.

7. The method of claim 1 , wherein the application is running inside an application execution space that is provisioned in the virtual computing instance.

8. The method of claim 1 , further comprising:

synchronizing the folder managed by the virtual computing instance with a local folder in the client device, such that the sanitized file is saved in the local folder.

9. A non-transitory computer readable medium comprising instructions executable in a computer system to cause the computer system to carry out a method of downloading a file in response to a user input made through a remote desktop application running in a client device connectable to the computer system over a network, the method comprising:

transmitting the user input made through the remote desktop application from the client device to a virtual computing instance that is executing in a physical machine connected to the client device over the network and hosting a remote desktop service for the client device;

detecting by an application running inside the virtual computing instance, that the user input is to download a file through the application;

issuing, by an extension of the application running inside the virtual computing instance, a request to download the file from a specified location corresponding to the user input, sanitize the downloaded file to remove embedded codes in the downloaded file, and return the sanitized file;

sending, by a sanitation agent running inside the virtual computing instance, the request to a file sanitation server;

receiving, by the sanitation agent, the sanitized file from the file sanitation server; and

upon receiving the sanitized file by the sanitation agent, saving the sanitized file in a folder managed by the virtual computing instance.

10. The non-transitory computer readable medium of claim 9 , wherein the application is a browser.

11. The non-transitory computer readable medium of claim 10 , wherein the browser is running in an isolated execution space.

12. The non-transitory computer readable medium of claim 9 , wherein the application is an e-mail application.

13. The non-transitory computer readable medium of claim 12 , wherein the e-mail application is running in an isolated execution space.

14. The non-transitory computer readable medium of claim 9 , wherein the computer system is a virtual machine.

15. The non-transitory computer readable medium of claim 9 , wherein the method further comprises:

synchronizing the folder managed by the virtual computing instance with a local folder in the client device, such that the sanitized file is saved in the local folder.

16. A computer system comprising:

a memory configured to store a program; and

a processor configured to execute the program stored in the memory to perform an operation for downloading a file in response to a user input made through a remote desktop application running on a client device, the operation comprising:

transmitting the user input made through the remote desktop application from the client device to a virtual computing instance that is executing in the computer system, which is connectable to the client device over a network and configured to host a remote desktop service for the client device;

detecting, by an application running inside the virtual computing instance, that the user input is to download a file through the application;

issuing, by an extension of the application running inside the virtual computing instance, a request to download the file from a specified location corresponding to the user input, sanitize the downloaded file to remove embedded codes in the downloaded file, and return the sanitized file;

sending, by a sanitation agent running inside the virtual computing instance, the request to a file sanitation server;

receiving, by the sanitation agent, the sanitized file from the file sanitation server; and

upon receiving the sanitized file by the sanitation agent, saving the sanitized file in a folder managed by the virtual computing instance.

17. The computer system of claim 16 , wherein the application is a browser.

18. The computer system of claim 17 , wherein the browser is running in an isolated execution space.

19. The computer system of claim 16 , wherein the application is an e-mail application.

20. The computer system of claim 19 , wherein the e-mail application is running in an isolated execution space.

Assignments (3)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →