IP Library Granted Patent US 8,239,608
Granted Patent B1
US 8,239,608 · App. 11/544,999 · Granted Aug 7, 2012

Secure computing environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,239,608
App. No.
11/544,999
Granted
Aug 7, 2012
Kind
B1
Abstract

Detailed herein are approaches to enabling a secure computing environment. In one approach, a computer system runs an operating system and a virtual machine management console. An input device is used to provide input to the operating system. The operating system is configured such that input received from the input device is directed to the virtual machine management console. The virtual machine management console, in turn, is configured to pass some or all of the input to a virtual machine.

Claims (42)

1. A method comprising:

logging in, by a computer system, a user account of a host operating system (OS) running on the computer system, wherein the user account is associated with a secure computing environment; and

upon logging in the user account, providing, by the computer system, the secure computing environment by:

preventing, based on a configuration of the user account, execution of one or more selected programs by the host OS that are unrelated to virtualization software running on the computer system;

disabling, based on the configuration of the user account, one or more selected user interface features of the host OS that allow access to files or programs resident on the computer system;

automatically launching a first virtual machine via the virtualization software; and

redirecting input received from a user of the user account to the virtualization software, wherein the virtualization software is configured to pass a portion of the input to the first virtual machine, and wherein the redirecting causes the input to be directed solely to the virtualization software, such that the input is not acted upon by programs of the host OS or the host OS itself for any purpose other than performing the redirecting.

2. The method of claim 1 , wherein said redirecting comprises:

receiving said input via an interface driver;

passing said input from said interface driver to said virtualization software.

3. The method of claim 2 , further comprising:

passing said input from said virtualization software to said first virtual machine.

4. The method of claim 2 , further comprising:

monitoring said input for an instruction code, said instruction code for instructing said virtualization software to change from a first mode of operation to a second mode of operation.

5. The method of claim 4 , wherein said virtualization software is operable in said second mode to run a second virtual machine.

6. The method of claim 5 , wherein said instruction code is received from an authenticated user.

7. The method of claim 1 , wherein said input comprises keyboard input.

8. The method of claim 1 , wherein said input comprises network input.

9. The method of claim 1 wherein the one or programs include a native shell program for the host OS.

10. The method of claim 1 wherein the one or more user interface features include open/save dialogs, keystroke combinations, or menu items of the host OS that allow access to files or programs resident on the computer system.

11. The method of claim 1 wherein the user account is associated with access restrictions that prevent the user from reading, writing, or executing files accessible on the computer system through the host OS.

12. The method of claim 1 wherein the first virtual machine is configured to disallow the user from exiting from the first virtual machine.

13. A computer system comprising:

a processor configured to:

log in a user account of a host operating system (OS) running on the computer system, the user account being associated with a secure computing environment; and

upon logging in the user account, provide the secure computing environment by:

preventing, based on a configuration of the user account, execution of one or more selected programs by the host OS that are unrelated to virtualization software running on the computer system;

disabling, based on the configuration of the user account, one or more selected user interface features of the host OS that allow access to files or programs resident on the computer system;

automatically launching a first virtual machine via the virtualization software; and

redirecting input received from a user of the user account to the virtualization software, wherein the virtualization software is configured to pass a portion of the input to the first virtual machine, and wherein the redirecting causes the input to be directed solely to the virtualization software, such that the input is not acted upon by programs of the host OS or the host OS itself for any purpose other than performing the redirecting.

14. The computing system of claim 13 , wherein the host OS comprises a driver, said driver for enabling an input device.

15. The computing system of claim 14 , wherein said driver is configured to pass a command, received from an input device, to said virtualization software.

16. The computing system of claim 13 , wherein said virtualization software is configured to detect an instruction code contained in said input, and, in response to said instruction code, change from a first mode of operation to a second mode of operation.

17. The secure computing system of claim 13 , wherein the processor is further configured to create and manage a second virtual machine via the virtualization software, and wherein the virtualization software is further configured to pass a second portion of said input to said second virtual machine.

18. A non-transitory computer readable medium having stored thereon computer-readable program code executable by a computer system, the program code comprising:

code that causes the computer system to log in a user account of a host operating system (OS) running on the computer system, the user account being associated with a secure computing environment; and

code that causes the computer system to provide the secure computing environment upon logging in the user account, the code that causes the computer system to provide the secure computing environment comprising:

code that causes the computer system to prevent, based on a configuration of the user account, execution of one or more selected programs by the host OS that are unrelated to virtualization software running on the computer system;

code that causes the computer system to disable, based on the configuration of the user account, one or more selected user interface features of the host OS that allow access to files or programs resident on the computer system;

code that causes the computer system to automatically launch a first virtual machine via the virtualization software; and

code that causes the computer system to redirect input received from a user of the user account to the virtualization software, wherein the virtualization software is configured to pass a portion of the input to the first virtual machine, and wherein the redirecting causes the input to be directed solely to the virtualization software, such that the input is not acted upon by programs of the host OS or the host OS itself for any purpose other than performing the redirecting.

19. The non-transitory computer readable medium of claim 18 , wherein an administrative user account is provided, said administrative account being configured for administering operation of said computer system, said host OS, and said virtualization software.

Assignments (4)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: VMWARE LLC
To: OMNISSA, LLC
Reel/Frame 068327/0365 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2006
From: GINZTON, MATT
To: VMWARE, INC.
Reel/Frame 018397/0603 →