IP Library Granted Patent US 9,934,407
Granted Patent B2
US 9,934,407 · App. 14/885,412 · Granted Apr 3, 2018

Apparatus for and method of preventing unsecured data access

Inventor: Neil Sikka (Bethesda, MD)
G06F21/6245G06F21/602G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,934,407
App. No.
14/885,412
Granted
Apr 3, 2018
Kind
B2
Abstract

Shown and depicted is preventing sensitive information from being exfiltrated from an organization using hypervisors. A Data Loss Prevention system is composed using virtual machines or domains to segment memory between domains which are assumed to be untrusted and domains which are known to be trusted. Sensitive information is cypher text when observed by software in Untrusted Domains, and clear text when observed by software in Trusted Domains. Sensitive information is unencrypted when it is in the address space of a protected process running inside a trusted domain.

Claims (36)

1. Computer comprising a processor configured to: execute a trusted virtual machine and a process in the trusted virtual machine that is executed in response to a request from an untrusted virtual machine that is without an authentication protocol;

prevent output of unsecured content from the virtual machine other than to hardware generating user sensory stimulation or a display virtual machine as necessary for user sensory stimulation;

secure content from the virtual machine so as to be unsecurable only with a File Key and a hardware security device;

the File Key further secured with a Public DLP Key of a designated recipient of the File Key, which is storable in a server;

access a medium accessible by either or both of the trusted virtual machine and untrusted virtual machine, configured to contain data secured before being written from the trusted virtual machine and/or unsecured after being read into the trusted virtual machine;

unsecure content from data that is unsecurable only with a File Key and a specific hardware security device, without communication with a securer of the content; and

wherein the content can be user modified.

2. Computer of claim 1 , wherein said processor is configured to route without an untrusted virtual machine: input, output, device assignment and combinations thereof.

3. Computer of claim 1 , wherein said processor is configured to permit content to be input into the virtual machine.

4. Computer of claim 1 , wherein said processor is configured to execute a host and/or one or more designated virtual machines and to forward sensory output to any one or combination thereof.

5. Computer of claim 1 , wherein said processor is configured to transmit data and/or receive data.

6. Computer of claim 1 , wherein the File Key is generated with an environmental factor and/or a key associated with a recipient or combination of keys associated with a plurality of recipients.

7. Computer of claim 1 , wherein the File Key is inaccessible to a user securing the content and/or a user unsecuring the data.

8. Computer of claim 1 , wherein the request comprises selecting data from a medium.

9. Computer of claim 8 , wherein said processor is configured to execute a process appropriate for a content type associated with the data in the virtual machine.

10. Computer of claim 8 , wherein said processor is configured to secure content to and/or unsecure data from a file.

11. Method of securing content comprising:

executing a trusted virtual machine;

executing a process in the virtual machine responsive to a request from an untrusted virtual machine without an authentication protocol;

preventing output of unsecured content from the virtual machine other than to hardware generating user sensory stimulation or a display virtual machine as necessary for user sensory stimulation;

securing content from the virtual machine so as to be unsecurable only with a File Key and a hardware security device;

wherein the File Key further secured with a Public DLP Key of a designated recipient of the File Key, which is storable in a server;

accessing a medium that is accessible by either or both of the trusted virtual machine and untrusted virtual machine, configured to contain data secured before being written from the trusted virtual machine and/or unsecured after being read into the trusted virtual machine;

unsecuring content from data that is unsecurable only with a File Key and a specific hardware security device without communication with a securer of the content; and

wherein the content can be user modified.

12. Method of claim 11 , further comprising routing without an untrusted virtual machine: input, output, device assignment and combinations thereof.

13. Method of claim 11 , further comprising permitting content to be input into the virtual machine.

14. Method of claim 11 , further comprising:

executing a host and/or one or more designated virtual machines; and

forwarding sensory output to any one or combination thereof.

15. Method of claim 11 , further comprising transmitting data and/or receiving data.

16. Method of claim 11 , wherein the File Key is generated with an environmental factor and/or a key associated with a recipient or combination of keys associated with a plurality of recipients.

17. Method of claim 11 , wherein the File Key is inaccessible to a user securing the content and/or a user unsecuring the data.

18. Method of claim 11 , wherein the request comprises selecting data from a medium.

19. Method of claim 18 , further comprising executing a process appropriate for a content type associated with the data in the virtual machine.

20. Method of claim 18 , further comprising securing content to and/or unsecuring data from a file.

Continuity (3)
Continuation PCTUS2015036123 · Jun 17, 2015
Provisional Application 62024630 · Jul 15, 2014
Related Publication 20160034702A1 · Feb 4, 2016