IP Library › Granted Patent US 10,536,559
Granted Patent B2
US 10,536,559 · App. 15/073,472 · Granted Jan 14, 2020

Blocking an interface of a redirected USB composite device

Inventor: Gokul Thiruchengode Vajravel (Bangalore, IN)
Assignee: Dell Products L.P.
H04L67/42H04L67/025H04L67/142
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,536,559
App. No.
15/073,472
Filed
Mar 17, 2016
Granted
Jan 14, 2020
Kind
B2
Examiner
KIM, EUI H
Art Unit
2453
USPC
709/203
Abstract

Session level restrictions can be implemented to limit access to a redirected interface of a composite device. These session level restrictions can be defined within a policy of a directory service, such as Active Directory, to facilitate the dynamic application of the restrictions to the appropriate remote sessions. In this way, access restrictions can be applied to individual interfaces of a redirected composite device so that a particular interface will only be accessible from specified remote sessions.

Claims (46)

1. A method for blocking redirection of an individual interface of a USB composite device when the USB composite device is connected to a client terminal that has established a remote session with a server and multiple interfaces of the USB composite device are redirected to the server over the remote session, the method comprising:

in response to a first device stack being created on the server for a first interface of the USB composite device that is redirected to the server over the remote session established between the client terminal and the server;

determining, by a first filter driver on the first device stack, that the first interface is redirected to the server;

accessing, by the first filter driver, a first policy applicable to the remote session to determine that the first interface is prohibited from redirection to the server;

identifying, by the first filter driver, one or more symbolic links in a global object manager namespace that have a device target matching the first interface; and

moving, by the first filter driver, the one or more symbolic links to an object manager namespace that is not associated with any user session on the server to thereby prevent the first interface from being accessed from any user session;

in response to a second device stack being created on the server for a second interface of the USB composite device that is redirected to the server over the remote session established between the client terminal and the server;

determining, by the second filter driver, that the second interface is redirected to the server;

accessing, by the second filter driver, a second policy to determine that the second interface is not prohibited from redirection to the server; and

allowing, by the second filter driver, the second interface to be redirected to the server via the second device stack thereby making the second interface accessible to the client terminal within the remote session.

2. The method of claim 1 , wherein determining that the first and second interfaces are redirected to the server comprises enumerating drivers in the first and second device stack respectively to identify the presence of a virtual bus driver.

3. The method of claim 1 , wherein one or both of the first and second policy comprises an Active Directory group policy object.

4. The method of claim 1 , wherein the one or more symbolic links comprise multiple symbolic links.

5. The method of claim 1 , wherein identifying the one or more symbolic links in the global object manager namespace that have a device target matching the first interface comprises enumerating one or more device objects in the first device stack to identify any symbolic links associated with the one or more device objects.

6. The method of claim 1 , further comprising: identifying one or more symbolic links in one or more local object manager namespaces have a device target matching the first interface; and

moving the one or more symbolic links in the one or more local object manager namespaces to an object manager namespace that is not associated with any user session on the server.

7. The method of claim 1 , wherein moving the one or more symbolic links to the object manager namespace that is not associated with any user session on the server comprises deleting the one or more symbolic links from the global object manager namespace and adding the one or more symbolic links to the object manager namespace that is not associated with any user session on the server.

8. The method of claim 1 , further comprising: prior to identifying the one or more symbolic links in the global object manager namespace that have a device target matching the first interface, determining that an operating system of the server does not allow the first interface to be associated with a property that defines from which sessions the first interface may be accessed.

9. The method of claim 1 , wherein the first policy and the second policy are the same policy.

10. The method of claim 1 , wherein determining that the first interface is prohibited from redirection to the server comprises determining that the first policy prohibits redirection of a class of devices and that the first interface matches the class.

11. A method for blocking redirection of an individual interface of a USB composite device when the USB composite device is connected to a client terminal that has established a remote session with a server and multiple interfaces of the USB composite device are redirected to the server over the remote session, the method comprising:

in response to a first device stack being created on the server for a first interface of the USB composite device that is redirected to the server over the remote session established between the client terminal and the server, determining, by a first filter driver on the first device stack, that the first interface is redirected to the server;

in response to a second device stack being created on the server for a second interface of the USB composite device that is redirected to the server over the remote session established between the client terminal and the server, determining, by a second filter driver on the second device stack, that the second interface is redirected to the server;

accessing, by both the first and second filter drivers, a policy applicable to the remote session over which the first and second interfaces are redirected;

determining, by the first filter driver, that the policy does not prohibit redirection of the first interface, and in response, allowing the first interface to be redirected to the server via the first device stack thereby making the first interface accessible to the client terminal within the remote session; and

determining, by the second filter driver, that the policy prohibits redirection of the second interface;

determining whether an operating system of the server allows device objects to include a session ID property to define from which sessions corresponding devices can be accessed;

when it is determined that the operating system of the server allows device objects to include a session ID property to define from which sessions the corresponding devices can be accessed, assigning an invalid session ID that is not associated with any user session on the server to a session ID property of a device object representing the second interface to thereby prevent the second interface from being accessed from any user session; and

when it is determined that the operating system of the server does not allow device objects to include a session ID property to define from which sessions the corresponding devices can be accessed, moving any symbolic link that has a device target matching the second interface to an object manager namespace that is not associated with any user session on the server to thereby prevent the second interface from being accessed from any user session.

12. The method of claim 11 , wherein the session ID property is the DEVPKEY_Device_SessionId property in the Windows operating system such that the invalid session ID is assigned to the DEVPKEY_DEVICE_SesssionId property.

13. The method of claim 12 , wherein the DEVPKEY_Device_SessionId property is assigned a value of 0xFFFFFFFF.

14. The method of claim 11 , wherein determining that the first and second interfaces are redirected to the server comprises enumerating drivers in the first and second device stack respectively to identify the presence of a virtual bus driver.

15. The method of claim 11 , wherein the policy comprises an Active Directory group policy object.

16. The method of claim 11 , wherein moving any symbolic link that has a device target matching the second interface comprises enumerating one or more device objects in the second device stack to identify any symbolic links associated with the one or more device objects.

17. The method of claim 11 , wherein determining that the first and second interfaces are redirected to the server comprises enumerating drivers in the first and second device stack respectively to identify the presence of a virtual bus driver.

18. The method of claim 11 , wherein determining that the second interface is prohibited from redirection comprises determining that the policy prohibits redirection of a class of devices and that the second interface matches the class.

19. One or more non-transitory computer storage media storing computer executable instructions which when executed on a server implement a method for blocking redirection of an individual interface of a USB composite device when the USB composite device is connected to a client terminal that has established a remote session with a server and multiple interfaces of the USB composite device are redirected to the server over the remote session, the method comprising:

in response to a first device stack being created on the server for a first interface of the USB composite device that is redirected to the server over the remote session established between the client terminal and the server, determining, by a first filter driver on the first device stack, that the first interface is redirected to the server;

in response to a second device stack being created on the server for a second interface of the USB composite device that is redirected to the server over the remote session established between the client terminal and the server, determining, by a second filter driver on the second device stack, that the second interface is redirected to the server;

accessing, by both the first and second filter drivers, a policy applicable to the remote session over which the first and second interfaces are redirected;

determining, by the first filter driver, that the policy does not prohibit redirection of the first interface, and in response, allowing the first interface to be redirected to the server via the first device stack thereby making the first interface accessible to the client terminal within the remote session; and

determining, by the second filter driver, that the policy prohibits redirection of the second interface,

determining whether an operating system of the server allows device objects to include a session ID property to define from which sessions corresponding devices can be accessed;

when it is determined that the operating system of the server allows device objects to include a session ID property to define from which sessions the corresponding devices can be accessed, assigning an invalid session ID that is not associated with any user session on the server to a session ID property of a device object representing the second interface to thereby prevent the second interface from being accessed from any user session; and

when it is determined that the operating system of the server does not allow device objects to include a session ID property to define from which sessions the corresponding devices can be accessed, moving any symbolic link that has a device target matching the second interface to an object manager namespace that is not associated with any user session on the server to thereby prevent the second interface from being accessed from any user session.

20. The non-transitory computer storage media of claim 19 , wherein determining that the first and second interfaces are redirected to the server comprises enumerating drivers in the first and second device stack respectively to identify the presence of a virtual bus driver.

Assignments (15)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2016
From: VAJRAVEL, GOKUL THIRUCHENGODE
To: DELL PRODUCTS L.P.
Reel/Frame 038146/0392 →
Continuity (1)
Related Publication 20170272546A1 · Sep 21, 2017
Cited By (1)
US 12,432,310