IP Library › Granted Patent US 9,507,615
Granted Patent B2
US 9,507,615 · App. 14/101,010 · Granted Nov 29, 2016

Methods and systems for allocating a USB device to a trusted virtual machine or a non-trusted virtual machine

Inventors: James McKenzie (Cambridge, GB); Jean Guyader (Cambridge, GB)
Assignee: Citrix Systems, Inc.
G06F9/45533G06F21/31G06F21/53G06F21/554G06F21/556G06F21/57G06F21/629G06F21/79G06F21/83G06F21/84G06F21/85H04L63/20G06F9/45558G06F2009/45575G06F2009/45579G06F2009/45587G06F2221/2101G06F2221/2107G06F2221/2115G06F2221/2143G06F2221/2147G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,507,615
App. No.
14/101,010
Granted
Nov 29, 2016
Kind
B2
Abstract

The methods and systems described herein provide for allocating a universal serial bus (USB) device to one of a trusted virtual machine and a non-trusted virtual machine. A control program receives data indicating a USB port on the computing machine received a USB device and identifies at least one attribute of the USB device. The control program selects, based on application of a policy to the identified at least one device attribute, one of a trusted virtual machine and a non-trusted virtual machine executing. The control program grants, to the virtual machine selected by the control program, access to the USB device.

Claims (52)

1. A method for allocating at least one universal serial bus (USB) device to one of a trusted virtual machine and a non-trusted virtual machine, in a computing device executing a hypervisor hosting the trusted virtual machine and the non-trusted virtual machine, the method comprising:

establishing, by a control program executed by a processor of the computing device, a trust level of a virtual machine responsive to a user providing authentication credentials;

receiving, by the control program, data indicating a USB port on the computing device received a first USB device;

identifying, by the control program, at least one attribute of the first USB device;

selecting, by the control program, a first security policy based on the at least one attribute of the first USB device;

applying, by the control program, the first security policy to the at least one attribute of the first USB device to determine a security level of the first USB device;

granting, by the control program to the trusted virtual machine, access to the first USB device based on the security level of the first USB device;

preventing, by the control program to the non-trusted virtual machine, access to the first USB device based on the security level of the first USB device; and

selecting, by the control program, based on (i) the at least one attribute of the first USB device and (ii) the security level of the first USB device, the trusted virtual machine among a plurality of virtual machines executing on the computing device.

2. The method of claim 1 , wherein identifying at least one attribute of the first USB device comprises identifying a device type of the first USB device.

3. The method of claim 1 , wherein identifying at least one attribute of the first USB device further comprises requesting, by the control program from a USB manager executing on the computing device, the at least one attribute of the first USB device.

4. The method of claim 1 , further comprising:

identifying, by the control program, at least one attribute of a second USB device of a same type as the first USB device; and

applying, by the control program, a second security policy to the at least one attribute of the second USB device to determine a security level of the second USB device, wherein the security level of the second USB device is a different security level than the security level of the first USB device.

5. The method of claim 1 , further comprising:

determining, by the control program, the security level of the first USB device, the security level of the first USB device indicating the first USB device cannot be accessed by trusted virtual machines;

selecting, by the control program based on the security level of the first USB device, a non-trusted virtual machine executing on the computing device; and

granting, by the control program to the selected non-trusted virtual machine, access to the first USB device.

6. The method of claim 1 , further comprising identifying, by the control program based on application of the first security policy to the at least one attribute of the first USB device, a group of permitted transactions.

7. The method of claim 1 , further comprising:

intercepting, by the control program, a request to access the first USB device by the trusted virtual machine;

determining, by the control program, whether the trusted virtual machine is permitted to access the first USB device;

granting, by the control program to the trusted virtual machine access to the first USB device; and

forwarding, by the control program, the request to the first USB device.

8. The method of claim 1 , wherein selecting one of the trusted virtual machine executing on the computing device and the non-trusted virtual machine executing on the computing device is performed further responsive to a window generated by an application executed by the selected virtual machine having focus.

9. The method of claim 1 , further comprising updating, by the control program, a virtualized view of physical resources available to the trusted virtual machine to include the first USB device.

10. In a computing device executing a hypervisor hosting a trusted virtual machine and a non-trusted virtual machine, a system for allocating at least one universal serial bus (USB) device to one of the trusted virtual machine and the non-trusted virtual machine, comprising:

the computing device comprising a USB port and a processor executing a control program and the hypervisor hosting the trusted virtual machine and the non-trusted virtual machine; and

wherein the control program is configured to:

establish a trust level of a virtual machine responsive to a user providing authentication credentials, receive data indicating the USB port on the computing device received a first USB device;

identify at least one attribute of the first USB device;

select a first security policy based on the at least one attribute of the first USB device;

apply the first security policy to the at least one attribute of the first USB device to determine a security level of the first USB device, grant the trusted virtual machine access to the first USB device based on the security level of the first USB device; and

prevent the non-trusted virtual machine access to the first USB device based on the security level of the first USB device; and

select based on (i) the at least one attribute of the first USB device and (ii) the security level of the first USB device, the trusted virtual machine among a plurality of virtual machines executing on the computing device.

11. The system of claim 10 , wherein the control program is configured to identify a device type of the first USB device.

12. The system of claim 10 , wherein the control program is configured to request from a USB manager executing on the computing device, the at least one attribute of the first USB device.

13. The system of claim 10 , wherein the control program is configured to:

identify at least one attribute of a second USB device of a same type as the first USB device; and

apply a second security policy to the at least one attribute of the second USB device to determine a security level of the second USB device, wherein the security level of the second USB device is a different security level than the security level of the first USB device.

14. The system of claim 10 , wherein the control program is configured to:

determine the security level of the first USB device, the security level of the first USB device indicating the first USB device cannot be accessed by trusted virtual machines;

select, based on the determination of the security level of the first USB device, a non-trusted virtual machine executing on the computing device; and

grant access to the first USB device.

15. The system of claim 10 , wherein the control program is configured to identify, based on application of the first security policy to the at least one attribute of the first USB device, a group of permitted transactions.

16. The system of claim 10 , wherein the control program is configured to:

intercept a request to access the first USB device by the trusted virtual machine;

determine whether the trusted virtual machine is permitted to access the first USB device;

grant the trusted virtual machine access to the first USB device; and

forward the request to the first USB device.

17. The system of claim 10 , wherein the control program is configured to select one of the trusted virtual machine executing on the computing device and the non-trusted virtual machine executing on the computing device, responsive to a window generated by an application executed by the selected virtual machine having focus.

18. The system of claim 10 , wherein the control program is configured to update a virtualized view of physical resources available to the trusted virtual machine to include the first USB device.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 10, 2013
From: MCKENZIE, JAMES; GUYADER, JEAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 031752/0430 →
Continuity (9)
Continuation 12967358 · Dec 14, 2010
Provisional Application 61286216 · Dec 14, 2009
Provisional Application 61286218 · Dec 14, 2009
Provisional Application 61286215 · Dec 14, 2009
Provisional Application 61286266 · Dec 14, 2009
Provisional Application 61286263 · Dec 14, 2009
Provisional Application 61286619 · Dec 15, 2009
Provisional Application 61286636 · Dec 15, 2009
Related Publication 20140101754A1 · Apr 10, 2014