Method and system for creating isolated workspaces through controlled interaction between a host and a virtual guest
By introducing guest data management applications into virtualized applications, remote office data security issues are solved, data protection in virtualized environments is achieved, unauthorized access and transmission is prevented, and the security of data transmission is enhanced.
Patent Information
- Application Number
- CN202180012471.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-02-07
- Filing Date
- 2021-02-03
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2041-02-03
AI Technical Summary
The data security of prior art in remote offices is insufficient, especially in virtualized environments running on employee-owned computing devices, and it is difficult to prevent unauthorized access and leakage of private data.
Introducing guest data management applications in virtualized applications, storing inaccessible encryption keys, and controlling and encrypting data transmission through the application, allowing only licensed processes and devices to access encrypted data, preventing unauthorized transmissions.
It effectively protects data in the virtualized environment, prevents unauthorized access and transmission, ensures data transmission in a secure network environment, and enhances data security in remote offices.
Smart Images

Figure CN115053222B_ABST
Abstract
Description
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims the benefit of U.S. Provisional Application No. 62 / 971,498, filed February 7, 2020, which is incorporated herein by reference in its entirety. Technical Field
[0003] Embodiments of the present invention generally relate to virtualization, and more particularly to apparatus, methods, and computer program products for providing a secure virtualization environment. Background Art
[0004] The following does not imply that anything discussed below is part of the prior art or part of the common general knowledge of a person skilled in the art.
[0005] Remote work arrangements are becoming commonplace for many office jobs. Enabling employees to work remotely offers many advantages for both employees and employers. For example, remote work arrangements can free up time that employees would otherwise spend commuting. This increases the time available for employees to be productive while balancing other commitments. This can also have the added benefit of reducing traffic congestion and strain on public transportation. Remote work can also enable employees to continue working during unforeseen events, such as adverse weather events (such as heavy snow or rain) or movement restrictions, such as those that may be implemented to limit the spread of infectious diseases (such as coronaviruses, such as Covid-19).
[0006] Remote work arrangements allow employees to work from a variety of locations, rather than from a specific physical location, such as an office building. This can save employers significant costs by reducing or eliminating the need for expensive office space. It also allows employees to remain productive even when they are away from their regular office location.
[0007] A remote office can be set up in an employee's home or in the office space of a shared work center, which provides office space for people from different companies. Employees working in a remote office can use a computer that can connect to a public computer network (such as the Internet) to collaborate with colleagues and access resources from servers on the organization's private network. This allows employees to continue working even in a new location, such as when traveling.
[0008] The network connection between the remote computer and the server in the private organization network is usually secured to prevent data leakage during data transmission between the remote office and the organization's server. Network technologies such as virtual private networks (VPNs) can be used to protect network connections. VPNs establish a secure and encrypted tunnel between a VPN client installed on the remote computer and a VPN server running in the organization's private network. This prevents the data transmission between the remote office and the server in the organization's private network from being eavesdropped on and causing private data to be leaked. The VPN client requires authentication (such as a username / password or a public / private key pair) to connect to the VPN server. This ensures that only authorized personnel can access the organization's private resources from the remote office and that data traffic between the remote office and the VPN server is encrypted.
[0009] Although VPNs create a secure channel between remote offices and servers within the organization's private network, they don't completely address data security issues in remote offices. For example, once private data is downloaded to a remote computer, preventing unauthorized third parties from accessing the data is challenging. Employees may accidentally or intentionally copy private data to USB drives or upload data to external servers that don't belong to the organization. Software installed on computers, such as malware or spyware, can also upload data to external servers that don't belong to the organization. These data security barriers significantly limit the usability of remote offices.
[0010] One approach to addressing data security issues in remote offices is to "harden" the computers used in a telework arrangement. Specifically, computers in the remote office can be configured to connect only to servers within the organization's private network. Hardening the computers ensures that all peripherals, except for basic input / output devices (such as the mouse, keyboard, and monitor), are disabled and cannot be used by these computers. However, this solution has several limitations. First, this approach often requires that the computers in the remote office be owned by the organization, as employees may be reluctant to harden their own computers. Furthermore, purchasing a computer for each employee working in the remote office not only places a financial burden on the organization, but also limits the choice of computers that employees can use in the remote office (which can negatively impact employee productivity).
[0011] Second, employees may be prevented from accessing public websites through hardened computers. This can significantly reduce employee productivity, as information and knowledge published in the public domain are often crucial for employees to effectively complete their tasks. To alleviate this problem, employees using hardened computers can also use other non-hardened computers to access public domain information and knowledge. Despite this, using public domain information and knowledge when performing tasks can still be difficult and inefficient because it is difficult to import data onto hardened computers (e.g., by copying and pasting).
[0012] Another technology often used to address data security issues in remote offices is virtualization. Virtualization is the practice of simulating an execution environment using software. However, virtualization may still not be sufficient to prevent the leakage of secure or private data, especially when the computing device hosting the virtualization is employee-owned. Because the host computing device is controlled by the employee, it is relatively simple for the employee to use virtualization tools to copy private organizational data from the virtualized environment. Therefore, further security measures are still required when using virtualization to protect private and sensitive organizational data. Summary of the Invention
[0013] The following introduction is provided to introduce the reader to a more detailed discussion. This introduction is not intended to limit or qualify any claimed or unclaimed invention. One or more inventions may exist in any combination or subcombination of the elements or process steps disclosed in any part of this document, including the claims and drawings.
[0014] The present disclosure relates to providing data security in a virtualized environment. In particular, the present disclosure provides a device, system, method, and computer program product configured to protect data accessed, generated, and transmitted within a guest execution environment emulated by a virtualized application. The present disclosure enables data in the guest execution environment to be protected even with respect to processes running on the same host as the virtualized application.
[0015] A host provides a host execution environment. A virtualization application runs in the host execution environment. The virtualization application simulates a guest execution environment. A guest operating system is installed in the guest execution environment. Multiple guest processes run in the guest operating system. A guest data management application is installed in the guest operating system and runs in the guest operating system. The guest data management application can be configured to protect data generated, accessed, and stored in the guest operating system.
[0016] The guest data management application can store at least one guest encryption key that is inaccessible to processes in the host execution environment and inaccessible to a user of the host device. The guest data management application can use the guest encryption key to encrypt data from the guest execution environment before the data is accessed by or transmitted to processes or devices outside the guest execution environment. This can prevent unauthorized access to the data from the guest execution environment, even by processes or peripheral devices on the same host computing device.
[0017] The guest data management application can communicate with an external relay server. The relay server and the guest data management application can collaborate to protect network data transmission between the guest execution environment and a permitted external computing device using network security procedures, such as a virtual private network. The relay server and the guest data management application can also exchange guest encryption keys to enable encryption of data while transmitting between the guest execution environment and a permitted external computing device (e.g., a computing device located on-site at an institution). This can further ensure that data can be securely transmitted between the guest execution environment and a permitted computing device located remotely from the computing device hosting the guest execution environment.
[0018] According to this broad aspect, a method for providing an isolated working environment on a host computing device is provided, the host computing device having a host processor and non-transitory host device memory, wherein the host processor defines a host execution environment of the host computing device and a plurality of host processes including a virtualization application running in the host execution environment, wherein the plurality of host processes include a plurality of non-kernel host processes, the virtualization application emulating a guest execution environment, wherein a guest operating system is installed in the guest execution environment and a plurality of guest application processes run in the guest operating system, the method comprising: running a guest data management application in the guest operating system, wherein the guest data management application is configured to: control the transfer of data from the plurality of guest application processes to any location outside the guest execution environment; storing, via the guest data management application, at least one guest encryption key, wherein the at least one guest encryption key is accessible via the guest data management application in the guest execution environment but is not accessible to: the host execution environment; and a user of the host computing device; identifying, via the guest data management application, a guest data management application from the plurality of guest application processes; The invention relates to a method for performing an attempted data transfer from a specific guest application process among multiple guest application processes to a specific location outside the guest execution environment, wherein the attempted data transfer includes: the specific guest application process attempting to transfer at least one data file to the specific location outside the guest execution environment; determining, by the guest data management application, that the at least one data file includes a security data file; encrypting, by the guest data management application, the security data file using a specific guest encryption key from the at least one guest encryption key; allowing, by the guest data management application, the attempted data transfer only after the security data file is encrypted, thereby transferring the security data file from the guest execution environment as an encrypted security data file; identifying, by the guest data management application, at least one permitted host process from the multiple host processes running in the host execution environment; and preventing unencrypted data transfer from any of the guest application processes to any non-kernel host process other than the multiple permitted host processes, while allowing unencrypted data transfer from the non-kernel host process to any of the guest application processes.
[0019] In some examples, the method may include: identifying, by the guest data management application, at least one secure guest application running in the guest operating system; and determining that the at least one data file includes a secure data file by: determining that the specific guest application process corresponds to a specific secure guest application in the at least one secure guest application; and in response to determining that the specific guest application process corresponds to the specific secure guest application, identifying all data files in the at least one data file as secure data files.
[0020] In some examples, the method may include: identifying, by the guest data management application, at least one permitted external computing device, wherein the guest execution environment is connected to each permitted external computing device via the host computing device and an external computer network; and preventing, by the guest data management application, file transfers between the guest execution environment and any external computing device other than the permitted external computing devices.
[0021] In some examples, the method may include: identifying, by the guest data management application, at least one permitted external relay server, wherein the guest execution environment is connected to each permitted external relay server via the host computing device and an external computer network; and preventing, by the guest data management application, file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the permitted external relay servers.
[0022] In some examples, the method may include: identifying, by the guest data management application, an attempted external file transfer from a given guest application process to a given external computing device, wherein the attempted external file transfer involves: the given guest application process attempting to transfer at least one given data file to the given external computing device through the host execution environment; determining, by the guest data management application, that the given external computing device is not associated with any permitted external relay server; and in response to determining that the given external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, the given guest application process from transferring the at least one given data file to any location outside the guest execution environment, thereby preventing the attempted external file transfer to the given external computing device.
[0023] In some examples, the method may include: identifying, by the guest data management application, an incoming file transfer from a specific external computing device, wherein the incoming file transfer includes: at least one specific data file transferred from the specific external computing device through the host execution environment; determining, by the guest data management application, that the specific external computing device is not associated with any permitted external relay server; and in response to determining that the specific external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, the at least one specific data file from being accessed by any of the guest application processes.
[0024] In some examples, the method may include securely exchanging, through the guest data management application, the at least one guest encryption key with a specific permitted external relay server, wherein the guest data management application is configured to exchange the at least one guest encryption key with the specific permitted external relay server through the host execution environment without exposing the at least one guest encryption key to the host execution environment outside the guest execution environment.
[0025] In some examples, the method may include: identifying, by the guest data management application, at least one permitted peripheral device associated with the host execution environment; and preventing, by the guest data management application, unencrypted data transmission between the guest execution environment and any peripheral device other than the permitted peripheral device.
[0026] In some examples, the method may include preventing, by the guest data management application, any data transfer between the guest execution environment and any peripheral device other than permitted peripheral devices.
[0027] In some examples, the at least one permitted host process running in the host execution environment may include a host process corresponding to the virtualized application.
[0028] According to a broad aspect, a computer program product is provided for providing an isolated working environment on a host computing device, the host computing device having a host processor, the host processor defining a host execution environment of the host computing device, and running a plurality of host processes including a virtualized application in the host execution environment, wherein the plurality of host processes include a plurality of unkernel host processes, the virtualized application emulating a guest execution environment, wherein a guest operating system is installed in the guest execution environment, and a plurality of guest application processes are running in the guest operating system, the computer program product including a computer-readable medium on which a plurality of host processes are stored. The host computing device stores computer-executable instructions for configuring the host processor of the host computing device to: run a guest data management application in the guest operating system, wherein the guest data management application is configured to: control data transfers from the plurality of guest application processes to any location outside the guest execution environment; store, via the guest data management application, at least one guest encryption key, wherein the at least one guest encryption key is accessible via the guest data management application in the guest execution environment and is inaccessible to: the host execution environment; and the host computing device. a user of the device; identifying, by the guest data management application, an attempted data transfer from a specific guest application process among the plurality of guest application processes to a specific location outside the guest execution environment, wherein the attempted data transfer comprises: the specific guest application process attempting to transfer at least one data file to the specific location outside the guest execution environment; determining, by the guest data management application, that the at least one data file comprises a secure data file; encrypting, by the guest data management application, the secure data file using a specific guest encryption key from the at least one guest encryption key; and encrypting, by the guest data management application, the secure data file. a guest data management application that allows attempted data transfer only after the security data file is encrypted, thereby transferring the security data file from the guest execution environment as an encrypted security data file; identifying, by the guest data management application, at least one permitted host process from the plurality of host processes running in the host execution environment; and preventing unencrypted data transfer from any of the guest application processes to any non-kernel host process other than the plurality of permitted host processes, while allowing unencrypted data transfer from the non-kernel host process to any of the guest application processes.
[0029] In some examples, the computer program product may also include instructions for configuring the host processor of the host computing device to: identify, through the guest data management application, at least one secure guest application running in the guest operating system; and determine that the at least one data file includes a secure data file by: determining that the specific guest application process corresponds to a specific secure guest application in the at least one secure guest application; and in response to determining that the specific guest application process corresponds to the specific secure guest application, identifying all data files in the at least one data file as secure data files.
[0030] In some examples, the computer program product may further include instructions for configuring the host processor of the host computing device to: identify, by the guest data management application, at least one permitted external computing device, wherein the guest execution environment is connected to each permitted external computing device via the host computing device and an external computer network; and prevent, by the guest data management application, file transfers between the guest execution environment and any external computing device other than the permitted external computing devices.
[0031] In some examples, the computer program product may further include instructions for configuring the host processor of the host computing device to: identify, by the guest data management application, at least one permitted external relay server, wherein the guest execution environment is connected to each permitted external relay server via the host computing device and an external computer network; and prevent, by the guest data management application, file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the permitted external relay servers.
[0032] In some examples, the computer program product may further include instructions for configuring the host processor of the host computing device to: identify, via the guest data management application, an attempted external file transfer from a given guest application process to a given external computing device, wherein the attempted external file transfer involves: the given guest application process attempting to transfer at least one given data file to the given external computing device through the host execution environment; determining, via the guest data management application, that the given external computing device is not associated with any permitted external relay server; and in response to determining that the given external computing device is not associated with any permitted external relay server, preventing, via the guest data management application, the given guest application process from transferring the at least one given data file to any location outside the guest execution environment, thereby preventing the attempted external file transfer to the given external computing device.
[0033] In some examples, the computer program product may further include instructions for configuring the host processor of the host computing device to: identify, by the guest data management application, an incoming file transfer from a specific external computing device, wherein the incoming file transfer includes: at least one specific data file transferred from the specific external computing device through the host execution environment; determine, by the guest data management application, that the specific external computing device is not associated with any permitted external relay server; and in response to determining that the specific external computing device is not associated with any permitted external relay server, prevent, by the guest data management application, the at least one specific data file from being accessed by any guest application among the guest applications.
[0034] In some examples, the computer program product may also include instructions for configuring the host processor of the host computing device to securely exchange, through the guest data management application, the at least one guest encryption key with a specific permitted external relay server, wherein the guest data management application is configured to exchange the at least one guest encryption key with the specific permitted external relay server through the host execution environment without exposing the at least one guest encryption key to the host execution environment outside the guest execution environment.
[0035] In some examples, the computer program product may also include instructions for configuring the host processor of the host computing device to: identify, via the guest data management application, at least one permitted peripheral device associated with the host execution environment; and prevent, via the guest data management application, the transmission of unencrypted data between the guest execution environment and any peripheral device other than the permitted peripheral device.
[0036] In some examples, the computer program product may further include instructions for configuring the host processor of the host computing device to prevent, through the guest data management application, any data transfer between the guest execution environment and any peripheral device other than permitted peripheral devices.
[0037] In some examples, the at least one licensed host process running in the host execution environment may include a host process corresponding to the virtualized application.
[0038] According to a broad aspect, a device for providing an isolated working environment is provided, the device comprising: a processor; and a non-volatile device memory having instructions stored on the non-volatile device memory, the instructions being used to configure the processor to: define a host execution environment; run a plurality of host processes including a virtualization application in the host execution environment, wherein the plurality of host processes include a plurality of non-kernel host processes, the virtualization application emulating a guest execution environment, wherein a guest operating system is installed in the guest execution environment and a plurality of guest application processes are run in the guest operating system; run a guest data management application in the guest operating system, wherein the guest data management application is configured to: control the transfer of data from the plurality of guest application processes to any location outside the guest execution environment; store at least one guest encryption key via the guest data management application, wherein the at least one guest encryption key is accessible via the guest data management application in the guest execution environment but is not accessible to: the host execution environment; and a user of the device; and identify, via the guest data management application, a guest encryption key from the plurality of guest application processes. an attempted data transfer from a specific guest application process in a program process to a specific location outside the guest execution environment, wherein the attempted data transfer includes the specific guest application process attempting to transfer at least one data file to the specific location outside the guest execution environment; determining, by the guest data management application, that the at least one data file includes a secure data file; encrypting, by the guest data management application, the secure data file using a specific guest encryption key from the at least one guest encryption key; and allowing, by the guest data management application, the attempted data transfer only after the secure data file is encrypted, thereby transferring the secure data file from the guest execution environment as an encrypted secure data file; identifying, by the guest data management application, at least one permitted host process from the plurality of host processes running in the host execution environment; and preventing unencrypted data transfer from any of the guest application processes to any non-kernel host process other than the plurality of permitted host processes, while allowing unencrypted data transfer from the non-kernel host process to any of the guest application processes.
[0039] In some examples, the instructions can be limited to configuring the processor to further: identify, through the guest data management application, at least one secure guest application running in the guest operating system; and determine that the at least one data file includes a secure data file by: determining that the specific guest application process corresponds to a specific secure guest application in the at least one secure guest application; and in response to determining that the specific guest application process corresponds to the specific secure guest application, identify all data files in the at least one data file as secure data files.
[0040] In some examples, the instructions can be limited to configuring the processor to further: identify, via the guest data management application, at least one permitted external computing device, wherein the guest execution environment is connected to each permitted external computing device via the host computing device and an external computer network; and prevent, via the guest data management application, file transfers between the guest execution environment and any external computing device other than the permitted external computing devices.
[0041] In some examples, the instructions can be limited to configuring the processor to further: identify, via the guest data management application, at least one permitted external relay server, wherein the guest execution environment is connected to each permitted external relay server via the host computing device and an external computer network; and prevent, via the guest data management application, file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the permitted external relay servers.
[0042] In some examples, the instructions may be limited to configuring the processor to further: identify, via the guest data management application, an attempted external file transfer from a given guest application process to a given external computing device, wherein the attempted external file transfer involves: the given guest application process attempting to pass at least one given data file to the given external computing device through the host execution environment; determining, via the guest data management application, that the given external computing device is not associated with any permitted external relay server; and in response to determining that the given external computing device is not associated with any permitted external relay server, preventing, via the guest data management application, the given guest application process from transferring the at least one given data file to any location outside the guest execution environment, thereby preventing the attempted external file transfer to the given external computing device.
[0043] In some examples, the instructions can be limited to configuring the processor to further: identify, via the guest data management application, an incoming file transfer from a specific external computing device, wherein the incoming file transfer includes: at least one specific data file transferred from the specific external computing device through the host execution environment; determine, via the guest data management application, that the specific external computing device is not associated with any permitted external relay server; and in response to determining that the specific external computing device is not associated with any permitted external relay server, prevent, via the guest data management application, the at least one specific data file from being accessed by any of the guest application processes.
[0044] In some examples, the instructions can be defined to further configure the processor to: securely exchange the at least one guest encryption key with a specific permitted external relay server through the guest data management application, wherein the guest data management application is configured to exchange the at least one guest encryption key with the specific permitted external relay server through the host execution environment without exposing the at least one guest encryption key to the host execution environment outside of the guest execution environment.
[0045] In some examples, the instructions can be limited to configuring the processor to further: identify, through the guest data management application, at least one permitted peripheral device associated with the host execution environment; and prevent, through the guest data management application, the transmission of unencrypted data between the guest execution environment and any peripheral device other than the permitted peripheral devices.
[0046] In some examples, the instructions may be defined to further configure the processor to: prevent, by the guest data management application, any data transfer between the guest execution environment and any peripheral device other than permitted peripheral devices.
[0047] In some examples, the at least one permitted host process running in the host execution environment includes a host process corresponding to the virtualized application.
[0048] Those skilled in the art will understand that the apparatus, method or computer program product disclosed herein may include any one or more of the features contained herein, and that these features may be used in any specific combination or subcombination.
[0049] These and other aspects and features of various embodiments are described in greater detail below. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] The accompanying drawings are intended to illustrate various examples of the systems, methods, and apparatus of the teachings of this specification and are not intended to limit the scope of the teachings in any way.
[0051] Figure 1 is a block diagram illustrating an example of a computer network system including a host computing device that provides virtualization according to an embodiment.
[0052] Figure 2 is a block diagram illustrating an example of a host computing device that provides virtualization using a guest data management application according to an embodiment.
[0053] Figure 3 is a block diagram illustrating an example of a computer network system including a tunnel server and a host computing device that provides virtualization using a guest data management application according to an embodiment.
[0054] Figure 4 is a block diagram illustrating an example of a computer network system including a gateway and a host computing device that provides virtualization using a guest data management application according to an embodiment.
[0055] Figure 5 is a block diagram illustrating another example of a host computing device that provides virtualization using a guest data management application according to an embodiment.
[0056] Figure 6 is a block diagram illustrating another example of a host computing device that provides virtualization using a guest data management application according to an embodiment.
[0057] Figure 7 is a flow chart illustrating an example of a method of providing an isolated work environment according to an embodiment. DETAILED DESCRIPTION
[0058] The drawings described below are provided to illustrate, but not to limit, aspects and features of various examples of the embodiments described herein. For simplicity and clarity of illustration, the elements in the drawings are not necessarily drawn to scale. For clarity, the dimensions of some elements may be exaggerated relative to other elements. It will be understood that, for simplicity and clarity of illustration, reference numerals may be repeated in the figures to indicate corresponding or similar elements or steps, where deemed appropriate.
[0059] In addition, numerous specific details are set forth to provide a thorough understanding of the embodiments described herein. However, one of ordinary skill in the art will appreciate that the embodiments described herein can be practiced without these specific details. In other instances, well-known methods, procedures, and components have not been described in detail to avoid obscuring the embodiments described herein. Likewise, the descriptions should not be construed as limiting the scope of the embodiments described herein.
[0060] Various systems or methods are described below to provide examples of implementations of the claimed subject matter. Any implementation described below does not limit any claimed subject matter, and any claimed subject matter may encompass methods or systems different from those described below. The claimed subject matter is not limited to systems or methods having all of the features of any one of the systems or methods described below, or having features common to multiple or all of the devices or methods described below. The systems or methods described below may not be implementations described in any of the claimed subject matter. Any subject matter disclosed in the systems or methods described below that is not claimed herein may be the subject of another protective instrument, such as a continuing patent application, and the applicants, inventors, or owners thereof do not intend to waive, disclaim, or dedicate any such subject matter to the public by disclosure herein.
[0061] The terms "embodiment," "example," "embodiments," "the embodiment," "the embodiments," "one or more embodiments," "some embodiments," and "one embodiment" refer to "one or more (but not all) embodiments of the invention," unless expressly stated otherwise.
[0062] It should be noted that terms of degree used herein, such as "substantially," "approximately," and "about," refer to reasonable deviations of the modified term so that the end result is not significantly changed. These terms of degree should also be construed to include deviations of the modified term if such deviations would not negate the meaning of the modified term.
[0063] Furthermore, numerical ranges recited herein by endpoints include all numbers and fractions within that range (e.g., 1 to 5 includes 1, 1.5, 2, 2.75, 3, 3.90, 4, and 5). It is also to be understood that all numbers and fractions are to be considered modified by the term "about," meaning that the recited number may be varied by up to that amount without significantly changing the end result.
[0064] The exemplary embodiments of the systems and methods described herein can be implemented as a combination of hardware or software. In some cases, the exemplary embodiments described herein can be implemented at least in part by using one or more computer programs that are executed on one or more programmable devices that include at least one processing element and a data storage element (including volatile memory, non-volatile memory, storage element, or any combination thereof). These devices can also have at least one input device (such as a button keyboard, mouse, touch screen, etc.) and at least one output device (such as a display screen, printer, wireless radio, etc.), depending on the nature of the device.
[0065] It should also be noted that some of the elements for implementing at least a portion of an embodiment described herein may be implemented by software, which is written in a high-level computer programming language such as object-oriented programming. Thus, the program code can be written in C, C++, or any other suitable programming language and may include modules or classes, which are well known to those skilled in object-oriented programming. Alternatively, or in addition, some of the elements implemented by software may be written in assembly language, machine language, or firmware as needed. In either case, the language may be a compiled or interpreted language.
[0066] At least some of these software programs may be stored on a storage medium (e.g., a computer-readable medium, such as, but not limited to, a ROM, a magnetic disk, an optical disk) or a device readable by a general or special purpose programmable device. The software program code, when read by the programmable device, configures the programmable device to operate in a new, specific, and predetermined manner to perform at least one method described herein.
[0067] Furthermore, at least some of the procedures associated with the systems and methods of the embodiments described herein may be distributed in a computer program product comprising a computer-readable medium carrying computer-usable instructions for one or more processors. The medium may be provided in a variety of forms, including non-transitory forms such as, but not limited to, one or more floppy disks, optical disks, magnetic tapes, chips, and magnetic and electronic storage.
[0068] A computer program is a set of instructions that can be executed by a computer (i.e., by a processor). A process is an instance of a program, i.e., a copy of the program in a computer's memory that can be executed by the computer's central processing unit (CPU). In the following discussion, reference is made to a computer system's processor and operations performed by that computer system's processor. It should be understood that this reference encompasses one or more processing elements and the use of one or more processing elements to perform operations, such as one or more processing cores in one or more CPUs.
[0069] An operating system (OS) is a set of software (consisting of several programs and libraries) that controls the use of a computer's available hardware and software resources. The core component of the OS, called the kernel, is a program that manages all computer hardware devices, including the CPU, memory, and input / output (IO) devices such as disks and network adapters, through a hardware-software interface. The kernel provides hardware access interfaces for software running within the operating system. At runtime, kernel processes instantiated from the kernel also manage processes instantiated from programs outside the kernel (non-kernel processes) and provide non-kernel processes with a unified kernel interface (called system calls) to access hardware devices.
[0070] An execution environment is a set of hardware and, optionally, an operating system (OS) on which software (i.e., programs) can be executed. Virtualization is the act of simulating an execution environment using software. Virtualization software is a program that executes (i.e., runs) in one execution environment and simulates other execution environments. The execution environment in which virtualization software runs is a host. The term host, as used herein, refers to a set of hardware with or without an OS. The host provides a host execution environment. The host execution environment provided by the host may or may not include an operating system. When a host includes an operating system, the operating system is referred to as a host operating system or host OS.
[0071] The execution environment provided / emulated by virtualization software is a virtual guest. As used herein, the term "virtual guest" refers to a set of hardware along with an operating system. The operating system (OS) installed in the virtual guest (i.e., the operating system running in the execution environment provided by the virtualization software) is the guest operating system (OS). Software running in the virtual guest (i.e., guest processes) interacts with the host only through the virtual guest.
[0072] Virtualization can be provided at the hardware level or the OS level. The embodiments described herein can be implemented with virtualization applications at the hardware level or the OS level. That is, the embodiments described herein can be configured to run with virtual guests in the form of virtual machines with guest operating systems installed and / or virtual guests in the form of user space instances (containers or jails).
[0073] In hardware-level virtualization, the virtualization software is also called a hypervisor. Various types of hypervisors can be used for different virtualization systems. When a Type I hypervisor is used as a virtualization application, the host is bare metal hardware. In other words, the host omits the operating system. When a Type II hypervisor is used as a virtualization application, the host includes hardware and an operating system called the host OS. In other words, the host includes the operating system. Regardless of the type of hypervisor, the virtual guest in hardware-level virtualization is always a virtual machine (VM). A virtual machine provides simulated hardware with an OS (called a guest OS) installed. In some implementations, if any host OS is used, the guest OS can be different from the host OS. Alternatively, the guest OS and the host OS can be the same operating system.
[0074] In OS-level virtualization, the host computer consists of a set of hardware and an operating system (the host OS). Virtualized applications are implemented as part of the host OS kernel. Virtual guests are userspace instances (also called containers or jails in some implementations) consisting of emulated hardware and an OS (the guest OS) that shares the same kernel with the host OS.
[0075] Virtualizations can be nested. That is, the host for a given virtualization can itself be a virtual guest hosted on another host. The embodiments described herein can be implemented regardless of whether virtualizations are nested. That is, in the embodiments described herein, a host can itself be a virtual guest of another host. Similarly, in the embodiments described herein, virtual guests can be used to host other virtual guests.
[0076] By using virtualization applications, organizations can deploy hosted virtual guests on employee computers in remote offices. This allows employees to use their own computers while maintaining a degree of isolation between the execution environment they use to work for the organization (i.e., the virtual guest) and the execution environment of their personal computers (the host). However, the isolation between the host and the virtual guest may still be insufficient to prevent the leakage of private organizational data, especially when the host is owned by the employee.
[0077] Because the host computing device is controlled by an employee, it is relatively easy for the employee to break the isolation between the host and the virtual guest and copy data from the virtual guest to the host. For example, when a piece of software on the virtual guest (i.e., a guest application running a guest process in the guest execution environment) writes data to the virtual guest's disk, the data is ultimately saved as one or more files on the virtual guest's host disk. Therefore, an employee can use virtualization tools to extract data on the virtual guest's disk from files created by the virtual guest on the host. Users can also create a virtual network between the virtual guest and the host and send data from the virtual guest to the host via the virtual network.
[0078] The embodiments described herein can alleviate many data security issues by controlling the interaction between the host and the virtual guests. An isolated workspace can be created by carefully controlling the interaction between the host and the virtual guests.
[0079] The host provides an interface that can transmit data between the virtual guest and an external device or network. Therefore, the communication between the virtual guest and any external device or network needs to transmit data through the host. The embodiments described herein can connect the virtual guest to one or more networks (such as, for example, a secure network of an internal organization's intranet), which may be inaccessible to the host. For the virtual guest running on a host connected to a public network (such as the Internet), the embodiments described herein can connect the host and the virtual guest to separate independent networks. The embodiments described herein can make one or more private networks (intranets) accessible to the virtual guest, but not to the host. For example, the virtual guest can be limited to being able to access certain servers on the public network (i.e., the virtual guest can be limited to only communicating with permitted external servers), thereby promoting the virtual guest to be connected to those private networks.
[0080] The embodiments described herein can also ensure that data generated in a virtual guest is always encrypted before being sent to or through the host. Data generated in a virtual guest can be encrypted regardless of whether the data is saved to the virtual guest's disk or sent to a server on a private network.
[0081] Implementing the embodiments described herein on a computer (host) in a remote office hosting a virtual guest can allow a user to access public websites through the host while allowing the user to access and use secure or private data (such as private organizational data) within the isolated workspace formed by the virtual guest. The embodiments described herein can prevent data within the isolated workspace from leaking through the virtual guest or the host, thereby preventing the leakage of secure or private data (such as private organizational data).
[0082] For clarity and ease of illustration, the embodiments described herein are described in the context of a telework arrangement. However, it should be understood that the embodiments described herein are not limited to telecommuting / teleworking arrangements. The embodiments described herein can be implemented to positive effect in many scenarios where preventing data leakage is important. For example, the embodiments described herein can be implemented with a computer (host) in a regular office hosting a virtual guest. This can allow employees to access public knowledge and information through the host. At the same time, employees can access and use private organizational data within an isolated workspace while preventing private organizational data from leaking into the public domain through the host or virtual guest.
[0083] In the embodiments described herein, one or more guest data management applications may be installed in a guest operating system of a virtual guest. The one or more guest data management applications may be configured to provide an isolated workspace for the virtual guest. The guest data management applications may be configured to perform various operations to provide data security and prevent data leakage from the isolated workspace.
[0084] The guest data management application can be configured to encrypt data generated by a guest process (i.e., a process running in the guest execution environment provided by the virtual guest) using an encryption key that is not available to the host. For example, when a guest process attempts to write data to a virtual guest disk or certain areas of a virtual guest disk, the guest data management application can encrypt the data. The guest data management application can also decrypt data that a guest process reads from a virtual guest disk or certain areas of a virtual guest disk using an encryption key that is not available to the host.
[0085] In the embodiments described herein, a guest data management application can be configured to identify secure guest applications running in a guest operating system. For example, the guest data management application can maintain a list of secure guest applications. The guest data management application can be configured to encrypt data written to a virtual guest disk or certain areas of a virtual guest disk by a guest process on a virtual guest whenever a guest process is spawned from one of the secure guest applications (i.e., when the guest process is an instance of a secure guest application in the list).
[0086] In embodiments described herein, a guest data management application is configured to exchange encryption keys with a relay server external to the host. The guest data management application and the relay server can be configured to exchange encryption keys through the host without the host being able to use the encryption keys. For example, a network management application can be installed on the relay server to facilitate the exchange of encryption keys. The guest data management application can be configured to manage encryption keys within the guest operating system to ensure that the host is unable to use the encryption keys.
[0087] In the embodiments described herein, the guest data management application can be configured to use an encryption key exchanged with a relay server to encrypt data sent by the guest process to an external computing device via the relay server. The guest data management application can be configured to use the exchanged encryption key to decrypt data sent by the external computing device to the guest process via the relay server.
[0088] The network management application on the relay server can be configured to encrypt data sent from the external computing device to the guest process via the relay server using the encryption key exchanged between the guest OS and the relay server. The network management application can be configured to decrypt data sent from the guest process of the virtual guest via the relay server using the exchanged encryption key.
[0089] In embodiments described herein, a guest data management application may be configured to identify one or more permitted external computing devices (which may include one or more permitted relay servers). The guest data management application may be configured to prevent data transmission between a virtual guest and any external computing device other than the permitted external computing devices. The guest data management application may be configured to maintain a list of permitted external computing devices that includes relay servers (and any other permitted computing devices). The guest data management application may be configured to block data transmissions that a guest process attempts to send to any computing device not on the list. The guest data management application may also be configured to block data transmissions that any computing device not on the list sends to a guest process.
[0090] In embodiments described herein, a guest data management application may be configured to identify one or more permitted peripheral devices. In some examples, the guest data management application may be configured to encrypt data transmitted by a guest process to any peripheral device other than permitted peripheral devices using an encryption key that is unavailable to the host. The guest data management application may also be configured to decrypt data received by a guest process on a virtual guest from peripheral devices other than permitted peripheral devices using the encryption key. The guest data management application may be configured to prevent unencrypted data transmission between a guest execution environment and any peripheral device other than permitted peripheral devices. In some examples, the guest data management application may be configured to prevent any data transmission between a guest execution environment and any peripheral device other than permitted peripheral devices.
[0091] For example, the guest data management application can maintain a list of approved peripheral devices. In some examples, the guest data management application encrypts data sent by the guest process to a peripheral device not on the list and decrypts data received by the guest process from a peripheral device not on the list using an encryption key not available to the host. Additionally, the guest data management application can block data sent to and received from the peripheral device by the guest process when the peripheral device is not on the list.
[0092] In the embodiments described herein, the guest data management application can be configured to allow processes running on the host (i.e., host processes) to send data to guest processes running on the virtualized guest via the virtualization application, and to prohibit guest processes from sending data to the host process via the virtualization application. That is, in some examples, the guest data management application can prevent guest processes from transmitting data to host processes. In some cases, the guest data management application can allow guest processes to transfer data only to those host processes that have been determined to be permitted host processes.
[0093] The embodiments described herein can be implemented in various types of computer networks. A (computer) network is a group of interconnected devices (e.g., computers, phones, routers, and switches). Devices can be connected via various communication interfaces, such as physical cable media and / or using wireless communication protocols. A computer is considered connected to a network if it can exchange data with other devices over the network. Each device connected to the network can have an associated device address. The embodiments herein are described in the context of an Internet Protocol (IP) network, i.e., a network that uses IP addresses. In an IP address, the address of a device connected to the network typically consists of an IP address and a port pair. When a first device (source) sends data to a second device (destination) over the network, the first device assembles the data into a packet with the data as the payload, the address of the first device as the source address, and the address of the second device as the destination address. The first device then sends the packet through a sequence of devices (number of hops) on the network, with the second device (destination) being the last in the sequence. The source address contained in the packet is used by the destination device to send a reply to the source device.
[0094] A subnet or subnetwork is a logical division of an IP network. Specifically, a subnet is a range of IP addresses. A device is considered to be on a subnet when its IP address falls within the range specified by the subnet.
[0095] Data can be transferred between different subnets using various methods. Gateways and tunnels are two different methods that allow data to be exchanged between more than one subnet. A gateway is a device located on multiple subnets. The gateway has a gateway service installed on it. The gateway service is configured to forward packets between different subnets.
[0096] A tunnel includes a tunnel server and a tunnel endpoint. A tunnel server is a computer in one or more subnets that has a tunnel service program installed. A tunnel endpoint is a computer in at least one subnet that also has a tunnel server installed. A tunnel client program is installed on the tunnel endpoint. The tunnel endpoint exchanges data with the tunnel computer through the tunnel server by encapsulating packets exchanged between the tunnel endpoint and the tunnel computer into packets exchanged between the tunnel endpoint and the tunnel server. Before the tunnel endpoint exchanges data with the tunnel computer through the tunnel server, the tunnel client on the tunnel endpoint can authenticate and exchange encryption keys (for encrypting the encapsulated packets) with the tunnel service on the tunnel server.
[0097] Now refer to Figure 1 ,exist Figure 1 Shown in FIG. 1 is an example computer network system 100. Computer network system 100 is an example of a computer network system in which embodiments described herein may be implemented.
[0098] like Figure 1 As shown, the computer network system 100 may include a plurality of subnets 106A and 106B for connecting, for example, the host computing device 120 and the relay server 104 computing device.
[0099] like Figure 1 As shown, a host computing device 120 is coupled to the first subnet 106A. The host computing device 120 can be a desktop computer, a laptop computer, a smartphone, or a tablet computer that can be connected to the first subnet 106A via a wireless connection or a wired Ethernet connection. The host computing device 120 can generally include a processor (i.e., a host processor) and device memory (host device memory), including volatile memory and non-transitory memory. The host computing device can also include at least one network interface; and peripheral devices, such as input devices (e.g., a keyboard and / or a touch screen), output devices (e.g., a display, a speaker, a printer), and the host computing device can also include other peripheral devices.
[0100] The host processor defines a host execution environment for the host computing device 120. Multiple host processes, including virtualized applications 122, can run in the host execution environment. Optionally, an operating system (host operating system) can be installed in the host execution environment. When the host operating system runs in the host execution environment, the multiple host processes can include multiple host kernel processes running in the host execution environment. The multiple host processes can also include multiple non-kernel processes running in the host execution environment. The non-kernel processes typically include processes instantiated by programs outside the kernel in the host execution environment.
[0101] The virtualization application 122 can be configured to simulate a guest execution environment. The guest execution environment can be referred to as a virtual guest 124. A guest operating system can be installed in the guest execution environment. When a host operating system runs in the host execution environment, the guest operating system can be the same type of operating system as the host operating system, or a different type of operating system than the host operating system.
[0102] Multiple guest application processes can run in the guest operating system. The multiple guest application processes running in the virtual guest can interact with the host execution environment 120 only through the guest execution environment 124 and the virtualization application 122.
[0103] Data received by a guest application process from or through the host execution environment must first pass through the virtualization application 122 and the guest kernel process of the guest execution environment before reaching the guest application process. For example, data generated by a host process must first pass through the virtualization application 122 and the guest kernel process of the guest execution environment 124 before reaching the guest application process. Similarly, when data is transferred from a remote computing device (e.g., from relay server 104) to a guest application process, the transferred data must first pass through the host 120, then through the virtualization application 122 and the guest kernel process of the guest execution environment 124 before reaching the guest application process. Common examples of data that must first pass through the virtualization application 122 and the guest kernel process of the guest execution environment 124 before being transferred to the guest application process include input from peripheral devices on the host 120 (e.g., a keyboard or mouse); data transmitted from the host 120 or a remote computer to the virtual guest 124; and data read by a guest process from non-transitory device memory (i.e., data read from disk).
[0104] Data generated by guest processes running in guest execution environment 124 must likewise pass through virtual guest 124 and virtualization software 122 before reaching host 120. Common examples of data that must first pass through the guest kernel process and virtualization application 122 of guest execution environment 124 and be transferred by a guest application process include: graphics display data transferred to peripheral devices on host 120, such as a monitor; outbound data transfers from a guest process to host 120 or to a remote computer; and data written by a guest process to non-transitory device memory (i.e., data written to disk).
[0105] As described above, the computer network system 100 also includes a relay server 104. As shown, the relay server 104 is coupled to both the first subnet 106A and the second subnet 106B. The relay server 104 can be configured to enable data exchange between the first subnet 106A and the second subnet 106B. That is, network traffic sent by a computing device on the first subnet 106A can pass through the relay server 104 to reach the second subnet 106B and any computing devices connected thereto. Similarly, network traffic sent by a computing device on the second subnet 106B can pass through the relay server 104 to reach the first subnet 106A and any computing devices connected thereto (e.g., the host 120). In the computer network system 100, the host computing device 120 is connected to the relay server 104 via the first subnet 106A, thereby enabling data to be exchanged between the virtual guest 124 and the computing device connected to the second subnet 106B.
[0106] The relay server 104 may be implemented as a gateway server (see Figure 4 ) and / or tunnel servers (see e.g. Figure 3 ). As with all devices shown in computer network system 100, although not all are shown, there can be multiple relay servers 104. In various examples of computer network system 100, multiple gateways and / or tunnel servers can be provided to connect multiple networks and subnets 106. In some cases, multiple relay servers can also exist between host 120 and gateway / tunnel servers 104 and / or between host 120 and virtual guest 124.
[0107] In the embodiments described herein, the guest data management application 125 can run in the guest execution environment 124. The guest data management application 125 can include a guest kernel process and / or a guest non-kernel process running in the guest execution environment 124. As used herein, the term "software application" or "application" refers to computer-executable instructions, particularly computer-executable instructions stored in a non-transitory medium such as a non-volatile memory and executed by a computer processor. When executing the instructions, the computer processor can receive input and transmit output to any of a variety of input or output devices connected to it.
[0108] The software application may be associated with an application identifier that uniquely identifies the software application. In some cases, the application identifier may also identify the version and build of the software application. A software application may be identified by name by those who use it, as well as those who provide or maintain it. A mobile application, or "app," generally refers to a software application that is installed and used on mobile devices such as smartphones, tablets, or other "smart" devices.
[0109] The guest data management application 125 is presented primarily for ease of explanation, and it should be understood that the features and operations associated with the guest data management application 125 may be implemented using a variety of software applications.
[0110] The guest data management application 125 can be configured to control the transfer of data between multiple guest application processes running in the guest execution environment of the virtual guest 124 and any location outside the guest execution environment, including the host execution environment. In particular, the guest data management application can be configured to monitor, intercept, and control any data transfer from a guest application process to any location outside the guest execution environment. This can help prevent data from leaking from the virtual execution environment 124, and even prevent data from leaking to the host 120. For example, the guest data management application 125 can be configured to ensure that secure or private data (and in some cases all data) generated in the virtual execution environment 124 is encrypted before being transmitted to or through the host 120. Various examples of functionality that can be provided by the guest data management application 125 are described in further detail below, such functionality being, for example, Figure 2 The disk filter 228 is shown in FIG; Figures 3 and 4 Network filter 336 and network filter 436 shown in; Figure 5 The clipboard manager 550 shown in FIG; and Figure 6 Device filter 656 is shown in FIG.
[0111] Now refer to Figure 7 ,exist Figure 7 , is a flow chart of an example process 700 for providing an isolated working environment on a host computing device. Process 700 is an example process that can be implemented using a guest data management application installed and / or running in a guest execution environment, such as virtual guest 124, as shown in computer network system 100. Generally speaking, process 700 can be implemented by at least one processor, such as host computing device 120, on which virtualization application 122 is running and provides a guest execution environment having a guest operating system in which guest data management application 125 is installed and running.
[0112] At 710, the guest data management application 125 can be configured to store at least one guest encryption key. The at least one guest encryption key can be stored in a manner that is accessible to the guest data management application 125 in the guest execution environment. The guest data management application 125 can store each guest encryption key but make the guest encryption key inaccessible to the host execution environment and the user of the host computing device 120.
[0113] The at least one guest encryption key can be stored by guest data management application 125 in an encrypted manner, such that the at least one guest encryption key is known only to guest data management application 125. The encrypted at least one guest encryption key can be further protected by guest data management application 125 such that no other process other than processes spawned by guest data management application 125 can access the encrypted at least one guest encryption key. In other words, only processes spawned from guest data management application 125 are permitted to access the encrypted at least one guest encryption key. Processes spawned from guest data management application 125 can include both kernel processes and non-kernel processes running in the guest execution environment. Therefore, without guest data management application 125, the at least one guest encryption key is unavailable to the host. In other words, access to the at least one guest encryption key can only be obtained through (and provided by) guest data management application 125. This also ensures that a user of the host computing device cannot access the encrypted at least one guest encryption key, let alone the unencrypted at least one guest encryption key.
[0114] At 720, the guest data management application 125 may identify an attempted data transfer (attempted data transfer) from the guest execution environment. The attempted data transfer may be identified as a transfer from a guest application process to a location external to the guest execution environment (e.g., a host process, a host disk, a peripheral device, a remote computer, etc.). The guest application process may be a specific guest application process among a plurality of guest application processes running in the guest execution environment. The attempted data transfer may involve the specific guest application process attempting to transfer at least one data file to a specific location external to the guest execution environment.
[0115] At 730, the guest data management application 125 can determine that at least one data file in the attempted data transfer identified at 720 comprises a secure data file. The guest data management application 125 can identify the secure data file in the at least one data file based on file identification data, such as metadata or an associated tag, that identifies the data file as a secure data file.
[0116] In some cases, the guest data management application can identify a secure data file from at least one data file based on the guest application process that generated the data file. For example, the guest data management application can identify multiple secure guest application processes from among multiple guest application processes running in the guest execution environment. The guest data management application can then identify any and all files generated by the secure guest application processes as secure data files. The multiple secure guest application processes can be identified based on the corresponding programs that generated the processes.
[0117] Alternatively, guest data management application 125 may be configured to determine that all data files associated with any and all attempted data transfers from the guest execution environment are to be considered safe data files.
[0118] At 740, the guest data management application 125 may encrypt the secure data file identified at 730 using a specific guest encryption key. The specific guest encryption key may be one of the guest encryption keys stored by the guest data management application 125 at 710. The specific guest encryption key may be an encryption key accessible to the guest data management application 125 but not to the host 120 and / or a user of the host.
[0119] At 750, the guest data management application 125 may allow the attempted data transfer only after the secure data file has been encrypted at 740. The guest data management application 125 may ensure that the secure data file is transferred from the guest execution environment as an encrypted secure data file. This can help prevent unauthorized third parties from accessing the information contained in the secure data file.
[0120] In some examples, the guest data management application 125 can encrypt all data files in the attempted data transfer, regardless of whether some of the files are secure data files. For example, the guest data management application 125 can encrypt all data files in the attempted data transfer based on the destination of the attempted data transfer. In some cases, if the guest data management application 125 determines that the destination of the attempted data transfer is an external computing device, the guest data management application 125 can encrypt all data files in the attempted data transfer to ensure that the information in the data files cannot be intercepted by an unauthorized third party (which may include the host 120).
[0121] In some cases, the guest data management application 125 can be configured to encrypt all data files that are attempted to be transferred out of the guest execution environment. This can provide enhanced security to prevent the leakage of data generated in the guest execution environment.
[0122] In some cases, the guest data management application 125 can identify secure destinations where some data does not need to be encrypted. For example, the guest data management application can identify one or more approved peripheral devices to which data can be transferred unencrypted. This can facilitate the use of the host computing device 120 while the user is working in the guest execution environment.
[0123] In some cases, the guest data management application 125 can identify at least one permitted host process from among multiple host processes running in the host execution environment. For example, the host process corresponding to the virtualization application 122 can be identified as a permitted host process by the guest data management application 125. This can facilitate the operation of the guest execution environment and the guest processes in the guest execution environment.
[0124] Permitted host processes may include kernel host processes and non-kernel host processes. For example, some processes generated from virtualization application 122 may be non-kernel host processes. These non-kernel host processes may be included in the permitted host process list so that, for example, unencrypted graphics information may be sent from the guest execution environment to these permitted non-kernel host processes so that the graphics information can be viewed by a user of the host computing device.
[0125] The guest data management application 125 can be configured to prevent any and all unencrypted data from being transmitted from any guest application process to any non-kernel host process other than a non-kernel host process included in the plurality of permitted host processes. At the same time, the guest data management application 125 can be configured to allow unencrypted data to be transmitted from a non-kernel host process to any guest application process.
[0126] In some cases, the guest data management application 125 can be configured to prohibit / prevent any data from being transferred from one or more non-kernel host processes to any guest application process. For example, if shared folders are prohibited in both directions, the guest data management application 125 can be configured to prevent processes spawned from the Windows Explorer program from transferring any data to any guest application process running in the guest execution environment.
[0127] Now refer to Figure 2 ,exist Figure 2 2 is an example of a host computing system 200 according to an embodiment. Figure 2As shown, host computing system 200 includes host 220. Host 220 provides a host execution environment. Host 220 includes host disk 232. Host disk 232 generally represents storage available to host 220 (and, through host 220, to virtual guests 224) from underlying hardware accessible by host 220.
[0128] A virtualization application 222 runs in the host execution environment. The virtualization application 222 provides a virtual guest 224 that defines a guest execution environment. One or more guest application processes 226 run in the guest execution environment of the virtual guest 224. The virtual guest 224 also includes a guest disk 230. The guest disk 230 generally represents a virtualized representation of a disk storage device that can be provided by the virtualization application 222. The virtualization application 222 can provide or emulate a file storage device interface that can be used to store and retrieve data in the guest execution environment. When data is written to the guest disk 230, the virtualization application 222 can in turn write the data to the host disk 232 for storage. Similarly, when retrieving data from the guest disk 230 in the guest execution environment, the virtualization application 222 can read data from the host disk 232.
[0129] In the example of computer network system 200, a guest data management application including disk filter 228 is running in the guest execution environment 224. Disk filter 228 can be configured to manage disk access for guest application process 226 running in guest execution environment 224.
[0130] In operation, the guest process 226 may attempt to write data to the guest disk 230 (an attempted data transfer, which may be referred to as an attempted write operation). The disk filter 228 may be configured to intercept data (e.g., one or more data files) during the attempted write operation. The disk filter 228 may then encrypt the one or more data files before storing them on the guest disk 230. Only after encryption can the one or more encrypted files be stored on the guest disk 230. The virtualization application 222 may then write the encrypted files to the host disk 232. This ensures that plaintext files (also referred to as original text or decrypted files) from the virtual guest 224 are not stored on the host disk 232. Instead, data generated by the virtual guest 224 can only be stored on the host disk 232 in an encrypted form, which is also referred to as ciphertext.
[0131] As described above, disk filter 228 can encrypt data files using an encryption key that is not available to host 220. This ensures that information stored in files in guest execution environment 224 on host disk 232 cannot be accessed by host 220 or users of host 220.
[0132] During operation, the guest process 226 may also attempt to read data from the guest disk 230. When this occurs, the virtualization application 222 may read data from the host disk 232 to the guest disk 230. In some cases, the read data may include encrypted data files previously stored from the guest execution environment. The disk filter 228 may determine that one or more data files in the read data are encrypted data files. The disk filter 228 may decrypt the encrypted data files in the data on the guest disk 230 (using the encryption key described above) to generate a decrypted or plaintext data file. The decrypted data file may then be passed to the guest process 226.
[0133] In some cases, disk filter 228 can be configured to intercept and encrypt all data files that guest process 226 attempts to write to guest disk 230. Additionally, disk filter 230 can encrypt only data files that have been identified as safe data files.
[0134] In some cases, a secure data file can be identified using file identification data associated with the data file, such as metadata contained in the file. Alternatively or additionally, disk filter 228 can identify one or more secure guest applications running in the guest operating system. Disk filter 228 can then determine whether the data file is a secure data file based on the guest application process that generated the data file or is attempting to store the data file. Disk filter 228 can determine that a specific guest application process associated with an attempted data transfer, such as an attempted write operation, corresponds to one of the secure guest applications. Then, in response to determining that the specific guest application process is from a secure guest application, disk filter 228 can identify all data files in the attempted data transfer as secure data files.
[0135] Disk filter 228 can maintain a list of safe guest applications (i.e., a whitelist of guest programs). When guest process 226 attempts to write a data file to guest disk 230, disk filter 228 can intercept the data file. Disk filter 228 can then check whether process 226 is spawned (i.e., an instance) from a safe guest program identified in the whitelist.
[0136] If disk filter 228 determines that process 226 corresponds to a secure guest, disk filter 228 can encrypt the data file using an encryption key not available to the host, as described above. Disk filter 228 can also include file identification data with the encrypted data file. The file identification data can identify the file as an encrypted data file (i.e., disk filter 228 can mark the data as encrypted). Disk filter 228 can then pass the encrypted data file (including the file identification data) to guest disk 230. Virtualization software 222 can then write the encrypted data file from guest disk 230 to host disk 232.
[0137] If disk filter 228 determines that process 226 does not correspond to a secure guest program, disk filter 228 can include file identification data with the data file, the file identification data identifying the file as a plain (unencrypted) data file (i.e., disk filter 228 can mark the data file as plain). Disk filter 228 can then pass the plain data file to guest disk 230. Virtualization software 222 can then write the plain data file from guest disk 230 to host disk 232.
[0138] When guest process 226 attempts to read data from guest disk 230, virtualization software 222 may read the data from host disk 232 into guest disk 230. This data is then intercepted by disk filter 228. Disk filter 228 can determine whether the data is an encrypted data file by examining the file identification data. For example, if the data is marked as encrypted, disk filter 228 can determine that the data file is encrypted; if the data is marked as plain text, disk filter 228 can determine that the data file is plain text. If disk filter 228 determines that the data file is plain text, it can pass the data file directly to requesting process 226. If disk filter 228 determines that the data file is encrypted, disk filter 228 decrypts the data using an encryption key not available to the host to generate a decrypted data file. Disk filter 228 can then pass the decrypted data file to requesting process 226.
[0139] Now refer to Figure 3 ,exist Figure 3, an example of a computer network system 300 is shown. Computer network system 300 includes a host computing device 320, a virtualized application 322, and a virtual guest 324. For ease of illustration, the features of the host computing device, virtualized application, and virtual guest described above with respect to computer network system 100 and computer network system 200 are not repeated here. However, it should be understood that these features can be used in conjunction with the features specifically described with respect to host computing device 320, virtualized application 322, and virtual guest 324.
[0140] Figure 3 An example of a virtual guest 324 is shown in which a guest data management application running thereon includes a network filter 336 installed in the guest execution environment. The network filter 336 can be configured to enable the virtual guest 324 and the guest processes 326 running in the guest execution environment of the virtual guest 324 to securely communicate with external computing devices and external servers.
[0141] In the example of computer network system 300, virtual guest 324 and guest process 326 can be configured to communicate with a permitted external computing device (e.g., external computing device 302T) through a permitted relay server (in this example, tunnel server 308). Tunnel server 308 can include a network adapter 342 operable to facilitate communications with first subnet 306A and second subnet 306B, and vice versa.
[0142] Tunnel client 334 can be installed in virtual guest 324. Tunnel client 324 can be operable to enable communication with tunnel server 308. Tunnel client 324 and the tunnel service running on tunnel server 308 can be configured to provide virtual guest 324 with private subnet access to permitted external computing devices, such as computing device 302T.
[0143] The network filter 336 can be configured to manage communications between the virtual guest 324 and external servers and external computing devices. The network filter 336 can be configured to prevent data from being transmitted to any external computer other than external computing devices that have been identified as safe or approved.
[0144] As shown in computer network system 300, the guest execution environment of virtual guest 324 can be coupled to external computing device 302T and external computing device 302B via host computing device 320 and external computer networks, such as first subnet 306A and second subnet 306B (via tunnel server 308). Network filter 336 can be configured to identify at least one permitted external computing device. For example, the permitted external computing device can be identified based on address data (e.g., a range of permitted destination addresses associated with an organization).
[0145] For example, computing device 302T may be identified as a permitted external computing device. Network filter 336 may be configured to prevent file transfers between the guest execution environment and any external computing device (e.g., computing device 302B) other than the permitted external computing device (e.g., computing device 302T).
[0146] In some cases, network filter 336 can be configured to control communications between virtual guest 324 and process 326 based on the external relay servers involved in the communications. For example, network filter 336 can be configured to limit data transmission to communications between virtual guest 324 and approved external servers. Network filter 336 can only allow data transmission between virtual guest 324 and external servers associated with the organization to prevent data leakage.
[0147] Network filter 336 can be configured to identify at least one approved external relay server (e.g., tunnel server 308). The approved external relay server can be identified based on address data (e.g., a range of approved server addresses associated with the organization). Network filter 336 can be configured to prevent file transfers between the guest execution environment and any relay server other than the approved external relay servers. Thus, network filter 336 can be configured to prevent file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the approved external relay servers (i.e., such transfers to the external computing device are allowed only if the transfer is routed through the approved relay server).
[0148] For example, network filter 336 can be configured to allow only outgoing packets (i.e., packets sent from virtual guest 324) with a destination address belonging to an approved tunnel server 308 on first subnet 306A to pass to network adapter 338 (and thereby to network adapter 340 and first subnet 306A). In some cases, network filter 336 can be configured to allow only incoming packets (i.e., packets sent to virtual guest 324) with a source address belonging to an approved tunnel server 308 on first subnet 306A to pass from network adapter 338 to guest process 326.
[0149] The guest data management application may also include a tunnel client 334. The tunnel client 334 may be configured to cooperate with the tunnel service 310 to define a secure communication channel between the virtual guest 324 and the tunnel server 308. The tunnel client 334 may be configured to exchange at least one guest encryption key with an external relay server (i.e., a permitted external relay server 308) via the host computing device 320, without making the encryption key available to the host 320. The tunnel client 334 may be configured to exchange the at least one guest encryption key with the tunnel server 308 through the host execution environment of the host 320, without exposing the at least one guest encryption key to the host execution environment outside of the guest execution environment of the virtual guest 324. For example, when the virtual guest 324 is launched, the tunnel client 334 may verify the encryption key and exchange the encryption key with the tunnel service 310 on the tunnel server 308 using standard key exchange techniques that prevent man-in-the-middle attacks through the host 320 and the first subnet 306A.
[0150] Network filter 336 can be configured to identify attempted data transfers in the form of attempted external file transfers from a given guest application process 326 to a given external computing device (e.g., computing device 302B or computing device 302T). The attempted external file transfer can involve the given guest application process 326 attempting to transfer at least one given data file to the given external computing device (e.g., computing device 302B or computing device 302T) via the host execution environment of host 320. Network filter 336 can be configured to allow or prevent the attempted external file transfer based on the destination address of the attempted external file transfer.
[0151] For example, when guest process 326 attempts to send data to computing device 302T on second subnet 306B (i.e., an attempted external file transfer to computing device 302T), tunnel client 334 may assemble a data transfer packet. The data transfer packet may include an inner packet that includes the data as a payload; the address of virtual guest 324 on second subnet 306B as a source address; and the address of computing device 302T on second subnet 306B as a destination address. Tunnel client 334 may encrypt the inner packet using an encryption key exchanged with tunnel service 310. Tunnel client 334 may further assemble an outer packet that includes the encrypted inner packet as a payload; the address of virtual guest 324 on first subnet 306A as a source address; and the address of tunnel server 308 on first subnet 306A as a destination address. Network filter 336 may inspect the outer packet to determine whether to allow the attempted data transfer. Because the destination address of the external packet belongs to the approved tunnel server 308 on the first subnet 306A, the network filter 336 can allow the attempted data transmission. The external packet can then be sent to the network adapter 338 of the virtual guest 324. The virtualization software 322 can then forward the external packet to the network adapter 340 of the host 320, which can then send the external packet to the tunnel server 308 via the first subnet 306A. After receiving the external packet, the tunnel service 310 on the tunnel server 308 can decompose the external packet into an encrypted inner packet, decrypt the inner packet using the encryption key exchanged with the tunnel client 334, and then forward the decrypted inner packet to the computing device 302T on the second subnet 306B.
[0152] In some cases, network filter 336 may determine that a given external computing device is not associated with a permitted external relay server. Then, in response to determining that the intended target computing device is not associated with a permitted external relay server, network filter 336 may prevent guest process 326 from transferring at least one given data file to any location outside the guest execution environment. This may prevent attempted external file transfers to a given external computing device that has not been identified as permitted. This may prevent data leakage that may occur through transfers to unauthorized computing devices.
[0153] For example, when guest process 326 attempts to send data to computing device 302B on first subnet 306A (i.e., an attempted external file transfer to computing device 302B), tunnel client 334 may assemble a data transfer packet. The data transfer packet may include the data as a payload, the address of virtual guest 324 on first subnet 306A as a source address, and the address of computing device 302B on first subnet 306A as a destination address. Tunnel client 334 may then forward the data transfer packet to network filter 336 for inspection. Network filter 336 may inspect the data transfer packet to determine whether the attempted data transfer is allowed. Because the destination address of the data transfer packet does not belong to an approved external device (i.e., an approved relay server 308 on first subnet 306A), network filter 336 may block the packet, thereby preventing the attempted external file transfer.
[0154] The network filter 336 can also be configured to manage incoming file transfers to the virtual guest 324. The network filter 336 can identify incoming file transfers from a specific external computing device (e.g., external computing device 302T or external computing device 302B). The incoming file transfer can include at least one specific data file transferred from the specific external computing device through the host execution environment of the host 320 (e.g., through the network adapter 340). The network filter 336 can determine whether to allow the incoming file transfer to be passed to the guest process 326 based on the source address of the incoming file transfer.
[0155] For example, computing device 302T may transmit an incoming file transfer to guest process 326. Computing device 302T may assemble a data transfer packet that includes an inner packet containing: data as a payload; the address of computing device 302T on second subnet 306B as a source address; and the address of virtual guest 324 on second subnet 306B as a destination address. Computing device 302T may then send the inner packet to tunnel server 308 via second subnet 306B. Upon receiving the inner packet, tunnel service 310 on tunnel server 308 may encrypt the inner packet using the encryption key exchanged with tunnel client 334 and assemble an outer packet with the encrypted inner packet as a payload, the address of tunnel server 308 on first subnet 306A as a source address, and the address of virtual guest 324 on first subnet 306A as a destination address. Tunnel service 310 may then send the outer packet to host 320 via first subnet 306A. After receiving the external packet, the host 320 may forward the external packet to the network adapter 338 of the virtual guest 324 through the virtualization software 322. The external packet may then be provided to the network filter 336.
[0156] Upon receiving the external packet, network filter 336 can inspect the packet. Network filter 336 can determine that the incoming file transfer is from a specific external computing device associated with an approved external relay server because the source address of the packet belongs to tunnel server 308 on first subnet 306A. Network filter 336 can then pass the external packet to tunnel client 334.
[0157] The tunnel client 334 can then decompose the outer packet into the encrypted inner packet (the encrypted incoming data transmission) and decrypt the inner packet. The tunnel client 334 can identify at least one transport-specific encryption key corresponding to the encrypted inner packet (e.g., based on key identification data included with the encrypted inner packet). The at least one transport-specific encryption key can be one of the encryption keys exchanged with the tunnel service 310 on the tunnel server 308. The tunnel client 334 can then decrypt the encrypted incoming data transmission using the at least one transport-specific encryption key to extract the decrypted inner packet. The tunnel client 334 can then pass the decrypted inner packet to the guest process 326.
[0158] In some cases, network filter 336 may determine that a particular external computing device associated with an incoming file transfer is not associated with an approved external relay server. In response, network filter 336 may prevent at least one particular data file in the incoming file transfer from being accessed by any guest application process 326. This may prevent malicious data or code from infiltrating the isolated workspace provided by virtual guest 324.
[0159] For example, computing device 302B on first subnet 206A may attempt to transfer data to guest process 326. However, network filter 336 may prevent the incoming file transfer from being accessed by any guest process 326.
[0160] When computing device 302B on first subnet 306A sends data to guest process 326, computing device 302B can assemble a data transfer packet that includes the data as a payload, the address of computing device 302B on first subnet 306A as a source address, and the address of virtual guest 324 on first subnet 306A as a destination address. Computing device 302B can then send the data transfer packet to host 320 via first subnet 306A. Upon receiving the data transfer packet, host 320 can forward the packet to virtual guest 324 via virtualization software 322. The packet can then be forwarded to network filter 336. Network filter 336 can inspect the packet and determine that the specific external computing device 302B associated with the incoming file transfer is not associated with an approved external relay server 308. Because the packet's source address does not belong to tunnel server 308 on first subnet 306A (instead, it belongs to second computing device 302B), the packet is blocked by network filter 336. Thus, guest process 326A may be prevented from accessing incoming file transfers.
[0161] Now refer to Figure 4 ,exist Figure 4 4 shows an example of a computer network system 400. Computer network system 400 includes a host computing device 420, a virtualized application 422, and a virtual guest 424. For ease of illustration, the features of the host computing device, virtualized application, and virtual guest described above with respect to computer network systems 100, 200, and 300 are not repeated here. However, it should be understood that such features may be used in conjunction with the features specifically described with respect to host computing device 420, virtualized application 422, and virtual guest 424.
[0162] Figure 4 Another example of a virtual guest 424 is shown in which a guest data management application running thereon includes a network filter 436 installed in the guest execution environment. The network filter 436 can be configured to manage communications between the virtual guest 424 and external servers and external computing devices. Similar to the network filter 336, the network filter 436 can be configured to enable the virtual guest 424 and the guest process 426 running in the guest execution environment of the virtual guest 424 to securely communicate with permitted external computing devices and permitted external servers.
[0163] Computer network system 400 illustrates an example of the operation of network filter 436 when the relay server is gateway 404, as compared to tunnel server 308 of computer network system 300. In the example of computer network system 400, virtual guest 424 and guest process 426 can be configured to communicate with an approved external computing device (e.g., external computing device 402T) through gateway server 408. Network filter 436 can be configured to recognize gateway 404 as an approved external relay server.
[0164] Gateway 404 may include a network adapter 442 operable to facilitate communications with and between first subnet 406A and second subnet 406B. In computer network system 400, a network filter 444 is also installed or enabled on gateway 404. Server network filter 444 and guest network filter 436 may be configured to collaborate to define a secure communication channel between virtual guest 424 and gateway 404. Network filter 436 for virtual guest 424 may be configured to exchange at least one guest encryption key with network filter 444 on gateway 404 via host computing device 420, without making the encryption key available to the host. For example, when virtual guest 424 boots up, network filter 436 may verify the encryption key and exchange the encryption key with network filter 444 on gateway 404 using standard key exchange techniques that prevent man-in-the-middle attacks via host 420 and first subnet 406A.
[0165] The specific operation of network filter 436 in computer network system 400 can vary depending on whether network address translation is enabled or disabled on gateway 404. When network address translation is disabled on gateway 404, network filter 436 can be configured to only allow attempted external file transfers from outgoing packets (i.e., packets sent from guest process 426) that have a destination address belonging to a computing device on second subnet 406B. Similarly, network filter 436 can be configured to only allow attempted external file transfers from incoming packets (i.e., packets sent to virtual guest 424) that have a source address belonging to a computing device on second subnet 406B.
[0166] For example, when guest process 426 attempts to send data to computing device 402T on second subnet 406B (i.e., an attempted external file transfer to computing device 402T), virtual guest 424 may assemble a data transfer packet. The data transfer packet may include the data as a payload; the address of virtual guest 424 on first subnet 406A as a source address; and the address of computing device 402T on second subnet 406B as a destination address. Network filter 436 may intercept the data transfer packet to determine whether to allow the attempted data transfer. Because the destination address of the data transfer packet belongs to computing device 402A on second subnet 406B, network filter 436 may allow the attempted external file transfer. Network filter 436 may encrypt the payload using an encryption key exchanged with network filter 444 on gateway 404. The data transfer packet with the encrypted payload may then be sent to network adapter 438 of virtual guest 424. The virtualization software 422 may then forward the data transmission packet to the network adapter 440 of the host 420 , which in turn may send the data transmission packet to the gateway 404 through the first subnet 406A.
[0167] After receiving the packet, network filter 444 on gateway 404 can check the source address of the data transmission packet. Because the source address corresponds to virtual guest 424, network filter 444 can decrypt the payload using the encryption key exchanged with network filter 436 and forward the data transmission packet with the decrypted payload to computing device 402T on second subnet 406b.
[0168] Alternatively, network filter 436 may determine that a given external computing device is not associated with a permitted external relay server and block the attempted data transfer by guest process 426. For example, when guest process 426 attempts to send data to computing device 402B on first subnet 406A (i.e., an attempted external file transfer to computing device 402B), the data transfer packet may be combined with a destination address of computing device 402B on first subnet 406A. Network filter 436 may therefore block the attempted data transfer because the destination address does not belong to a computing device on second subnet 406B.
[0169] The network filter 436 may also be configured to manage incoming file transfers to the virtual guest 424. The network filter 436 may be configured to allow incoming file transfers to pass to the guest process 426 based on the source address of the incoming file transfer.
[0170] For example, computing device 402T may transmit an incoming file transfer to guest process 426. Computing device 402T may assemble a data transfer packet that includes the data as a payload, the address of computing device 402T on second subnet 406B as a source address, and the address of virtual guest 424 on first subnet 406A as a destination address. Computing device 402T may then send the data transfer packet to gateway 404 via second subnet 406B. Upon receiving the data transfer packet, network filter 444 on gateway 404 may examine the destination address of the data transfer packet. In response to determining that the destination address corresponds to virtual guest 424 on first subnet 406A, network filter 444 may encrypt the payload of the data transfer packet using the encryption key exchanged with network filter 436. Network filter 444 may then forward the data transfer packet with the encrypted payload to virtual guest 424 via first subnet 406A, network adapter 440 of host 420, and virtualization software 422.
[0171] In virtual guest 424, network filter 436 can intercept the data transfer packet before it reaches any guest process 426. Network filter 436 can then inspect the packet. Network filter 436 can determine that the incoming file transfer is from a specific external computing device associated with an approved external relay server because the source address of the packet belongs to computing device 402T on second subnet 406B. Network filter 436 can then decrypt the payload. The packet with the decrypted payload can then be forwarded to guest process 426.
[0172] In contrast, when computing device 402B on first subnet 406A sends a data transmission packet to virtual guest 424, network filter 434 can be configured to block any packet combined with the address of computing device 402B on first subnet 406A because the source address does not belong to any computing device on second subnet 406B.
[0173] When network address translation is enabled on the gateway 404, the address of the computing device on the second subnet 406B is translated to the address of the gateway 404 on the first subnet 406A. Accordingly, the network filter 436 can be configured to only allow attempted external file transfers for outgoing packets (i.e., packets sent from the guest process 426) with a destination address belonging to the gateway 404 on the first subnet 406A. Similarly, the network filter 436 can be configured to only allow incoming file transfers from incoming packets (i.e., packets sent to the virtual guest 424) with a source address belonging to the gateway 404 on the first subnet 406A.
[0174] For example, when guest process 426 attempts to send data to computing device 402T on subnet 406B (i.e., an attempted external file transfer to computing device 402T), virtual guest 424 may assemble a data transfer packet. The data transfer packet may include the data as a payload; the address of virtual guest 424 on first subnet 406A as a source address; and the address of gateway 404 on first subnet 406A as a destination address. Network filter 436 may intercept the data transfer packet to determine whether to allow the attempted data transfer. Because the destination address of the data transfer packet belongs to gateway 404 on first subnet 406A, network filter 436 may allow the attempted data transfer. Network filter 436 may encrypt the payload using an encryption key exchanged with network filter 444 on gateway 404. The data transfer packet with the encrypted payload may then be sent to network adapter 438 of virtual guest 424. The virtualization software 422 may then forward the data transmission packet to the network adapter 440 of the host 420 , which in turn may send the data transmission packet to the gateway 404 through the first subnet 406A.
[0175] After receiving the packet, network filter 444 on gateway 404 can examine the source address of the data transmission packet. Because the source address corresponds to virtual guest 424, network filter 444 can decrypt the payload using the encryption key exchanged with network filter 436. Network filter 444 can also replace the destination address with the address of computing device 402T on second subnet 406B. Network filter 444 can then forward the data transmission packet with the decrypted payload to computing device 402T on second subnet 406B.
[0176] In contrast, when guest process 426 attempts to send data to computing device 402B on first subnet 406A (i.e., an attempted external file transfer to computing device 402B), the data transfer packet may be combined with a destination address of computing device 402B on first subnet 406A. Network filter 436 may therefore prevent the attempted data transfer because the destination address does not belong to gateway 404 on first subnet 406A.
[0177] The network filter 436 may also be configured to manage incoming file transfers to the virtual guest 424 when network address translation on the gateway 404 is enabled.
[0178] For example, computing device 402T may transmit an incoming file transfer to guest process 426. Computing device 402T may assemble a data transfer packet that includes: the data as a payload; the address of computing device 402T on second subnet 406B as a source address; and the address of virtual guest 424 on first subnet 406A as a destination address. Computing device 402T may then send the data transfer packet to gateway 404 via second subnet 406B. Upon receiving the data transfer packet, network filter 444 on gateway 404 may examine the destination address of the data transfer packet. In response to determining that the destination address corresponds to virtual guest 424 on first subnet 406A, network filter 444 may encrypt the payload of the data transfer packet using the encryption key exchanged with network filter 436. Network filter 444 may also replace the source address with the address of gateway 404 on first subnet 406A. The network filter 444 may then forward the data transmission packet with the encrypted payload to the virtual guest 424 through the first subnet 406A, the network adapter 440 of the host 420 , and the virtualization software 422 .
[0179] In virtual guest 424, network filter 436 can intercept the data transfer packet before it reaches any guest process 426. Network filter 436 can then inspect the packet. Network filter 436 can determine that the incoming file transfer is from a specific external computing device associated with an approved external relay server because the source address of the packet belongs to gateway 404 on first subnet 406A. Network filter 436 can then decrypt the payload. The packet with the decrypted payload can then be forwarded to guest process 426.
[0180] In contrast, when computing device 402B on first subnet 406A sends a data transmission packet to virtual guest 424, network filter 434 may be configured to block any packet combined with the address of computing device 402B on first subnet 406A because the source address does not belong to gateway 404 on first subnet 406A.
[0181] Now refer to Figure 5 ,exist Figure 5 , an example of a computer network system 500 is shown. Computer network system 500 includes a host computing device 520, a virtualized application 522, and a virtual guest 524. For ease of illustration, the features of the host computing device, virtualized application, and virtual guest described above with respect to computer network system 100, computer network system 200, computer network system 300, and computer network system 400 are not repeated here. However, it should be understood that such features can be used in conjunction with the features specifically described with respect to host computing device 520, virtualized application 522, and virtual guest 524.
[0182] As shown in computer network system 500, the guest data management application includes a clipboard manager 550 installed and running in the guest execution environment of virtual guest 524. Clipboard manager 550 can be configured to manage copying data from process 554 on host 520 and pasting the data to process 526 on virtual guest 524. Clipboard manager 550 can also be configured to manage copying data from process 526 on virtual guest 524 and pasting the data to process 554 on host 520.
[0183] A host clipboard manager 552 also runs in the host execution environment 520. When data is copied from a host process 554 on the host 520 to the host 520 clipboard, the clipboard manager 552 on the host 520 can intercept the data. The host clipboard manager 552 can then forward the copied data to the clipboard manager 550 of the virtual guest 524 via the virtualization software 522. After receiving the copied data, the clipboard manager 550 of the virtual guest 524 can forward the data to the clipboard of the virtual guest 524. The clipboard of the virtual guest 524 can then allow the copied data to be pasted into the guest process 526.
[0184] Clipboard manager 550 may also be configured to prevent copying data from process 526 on virtual guest 524 and pasting data to process 554 on host 520. In some cases, clipboard manager 550 may be configured to never forward data in the virtual guest 524 clipboard to the host 520 clipboard.
[0185] Now refer to Figure 6 ,exist Figure 6 6 shows an example of a computer network system 600. Computer network system 600 includes a host computing device 620, a virtualized application 622, and a virtual guest 624. For ease of illustration, the features of the host computing device, virtualized application, and virtual guest described above with respect to computer network system 100, computer network system 200, computer network system 300, computer network system 400, and computer network system 500 are not repeated here. However, it should be understood that such features may be used in conjunction with the features specifically described with respect to host computing device 620, virtualized application 622, and virtual guest 624.
[0186] As shown in computer network system 600, the guest data management application includes a hardware device filter 656 installed and running in the guest execution environment of virtual guest 624. The device filter 656 can be configured to manage data transfer between a process 626 on the virtual guest 624 and a peripheral device 658.
[0187] In some examples, device filter 656 can be configured to identify at least one permitted peripheral device connected to host execution environment 620. For example, permitted peripheral device 658 can be an output device, such as a visual display or speakers connected to the host computing device, or an input device, such as a mouse. In some cases, device filter 656 can maintain a whitelist of permitted peripheral devices to identify which peripheral devices are allowed to receive unencrypted data transmissions from process 626 on virtual guest 624.
[0188] Device filter 656 can be configured to prevent unencrypted data transfers between the guest execution environment and any peripheral device 658 except approved peripheral devices. Device filter 656 can be configured to intercept all attempted file transfers between guest process 626 and peripheral device 658 to ensure that only approved data transfers are allowed.
[0189] For example, the guest process 626 may attempt to send data to a peripheral device 658 that the virtual guest 624 can access (an attempted data transfer to the peripheral device). The device filter 656 may intercept the attempted data transfer before it leaves the virtual guest 624. The device filter 656 may be configured to determine whether the target peripheral device is a permitted peripheral device (e.g., by checking a whitelist of permitted peripheral devices). In response to determining that the target peripheral device is a permitted peripheral device, the device filter 656 may forward the data in the attempted data transfer to the permitted peripheral device. The data in the attempted data transfer may be forwarded in an unencrypted / plain format.
[0190] In some cases, device filter 656 may determine that the target peripheral device is not an approved peripheral device. In response to determining that the target peripheral device is not an approved peripheral device, device filter 656 may encrypt the data in the attempted file transfer. The data may be encrypted using an encryption key stored by the guest data management application, but not available to host 620. The encrypted data may then be forwarded to the peripheral device.
[0191] The device filter 656 can also intercept attempted incoming file transfers from the peripheral device 656 to the guest process 626. The device filter 656 can determine whether the attempted incoming file transfer is received from an approved peripheral device (e.g., using a peripheral device whitelist). In response to determining that the attempted incoming file transfer is received from a peripheral device that is an approved peripheral device, the device filter 656 can forward the data in the attempted incoming file transfer.
[0192] Alternatively, device filter 656 can determine that the attempted incoming file transfer is from a peripheral device that is not a permitted peripheral device. In response to determining that the attempted incoming file transfer is from a peripheral device that is not a permitted peripheral device, device filter 656 can decrypt the data in the attempted incoming file transfer. Device filter 656 can then pass the decrypted data to guest process 626.
[0193] In some cases, device filter 656 can be configured to prevent all data transfers between the guest execution environment and any peripheral device 658 other than permitted peripheral devices. In response to determining that an attempted data transfer is intended for a peripheral device that is not a permitted peripheral device, device filter 656 can prevent / block the attempted data transfer. Similarly, in response to determining that an attempted incoming file transfer is received from a peripheral device that is not a permitted peripheral device, device filter 656 can prevent / block the attempted file transfer from reaching guest process 626.
[0194] It will be appreciated that the systems and processes for providing isolated workspaces described herein, as well as the modules, routines, processes, threads, or other software components that implement the methods / processes, can be implemented using standard computer programming techniques and languages. This application is not limited to a particular processor, computer language, computer programming convention, data structure, or other such implementation details. Those skilled in the art will recognize that the methods / processes can be implemented as part of a computer executable code stored in a volatile or non-volatile memory, as part of an application specific integrated circuit (ASIC), or the like.
[0195] It will be apparent to those skilled in the art that the characteristics of the hosts described in the context of host computing device 120, host computing device 220, host computing device 320, host computing device 420, host computing device 520, and host computing device 620 may generally be combined and / or interchanged depending on the specific application of the computer network system.
[0196] It will be apparent to those skilled in the art that the features of the virtualization applications described in the context of virtualization software 122, virtualization software 222, virtualization software 322, virtualization software 422, virtualization software 522, and virtualization software 622 may generally be combined and / or interchanged depending on the specific application of the computer network system.
[0197] It will be apparent to those skilled in the art that the features of the virtual guests described in the context of virtual guest 124, virtual guest 224, virtual guest 324, virtual guest 424, virtual guest 524, and virtual guest 624 may generally be combined and / or interchanged depending on the particular application of the computer network system.
[0198] It will be apparent to those skilled in the art that certain adaptations and modifications may be made to the described methods, and the above-discussed embodiments of systems and methods for providing an isolated workspace should be considered as illustrative rather than restrictive.
[0199] Although the features of the exemplary embodiments are described above, it will be understood that some features and / or functions of the described embodiments may be modified without departing from the spirit and operating principles of the described embodiments. For example, the various features described by the represented embodiments or examples may be selectively combined with each other. In other cases, well-known methods, procedures, and components are not described in detail to avoid obscuring the description of the embodiments. Therefore, what has been described above is intended to illustrate the concepts claimed and is non-restrictive. It will be understood by those skilled in the art that other variations and modifications may be made without departing from the scope of the invention as defined in the claims appended hereto. The scope of the claims should not be limited to the preferred embodiments and examples, but should be given the broadest interpretation consistent with the overall description.
Claims
1. A method for providing an isolated working environment on a host computing device having a host processor and non-transitory host device memory, wherein: The host processor defines a host execution environment of the host computing device and runs a plurality of host processes including a virtualized application in the host execution environment, wherein the plurality of host processes include a plurality of non-kernel host processes, and the virtualized application simulates a guest execution environment, wherein a guest operating system is installed in the guest execution environment, and a plurality of guest application processes are run in the guest operating system, the method comprising: a) running a guest data management application in the guest operating system, wherein the guest data management application is configured to: control data transfers from the plurality of guest application processes to any location outside the guest execution environment; b) storing, by the guest data management application, at least one guest encryption key, wherein the at least one guest encryption key is accessible by the guest data management application in the guest execution environment and is inaccessible to: i) the host execution environment; and ii) a user of the host computing device; c) identifying, by the guest data management application, an attempted data transfer from a specific guest application process among the plurality of guest application processes to a specific location outside the guest execution environment, wherein the attempted data transfer comprises: the specific guest application process attempting to transfer at least one data file to the specific location outside the guest execution environment; d) determining, by the guest data management application, that the at least one data file comprises a secure data file; e) encrypting, by the guest data management application, the secure data file using a specific guest encryption key from the at least one guest encryption key; f) allowing, by the guest data management application, the attempted data transfer only after encrypting the secure data file, thereby transferring the secure data file from the guest execution environment as an encrypted secure data file; g) identifying, by the guest data management application, at least one permitted host process from the plurality of host processes running in the host execution environment; and h) preventing unencrypted data transmission from any guest application process among the multiple guest application processes to any non-kernel host process other than the multiple permitted host processes, while allowing unencrypted data transmission from the non-kernel host process to any guest application process among the multiple guest application processes.
2. The method according to claim 1, wherein The method further comprises: a) identifying, by the guest data management application, at least one secure guest application running in the guest operating system; and b) determining that the at least one data file includes a security data file by: i) determining that the specific guest application process corresponds to a specific secure guest application among the at least one secure guest application; and ii) in response to determining that the specific guest application process corresponds to the specific secure guest application, identifying all data files of the at least one data file as secure data files.
3. The method according to claim 1 or 2, wherein: The method further comprises: a) identifying, by the guest data management application, at least one permitted external computing device, wherein the guest execution environment is coupled to each permitted external computing device via the host computing device and an external computer network; and b) preventing, by the guest data management application, file transfers between the guest execution environment and any external computing devices other than permitted external computing devices.
4. The method according to claim 1 or 2, wherein: The method further comprises: a) identifying, by the guest data management application, at least one approved external relay server, wherein the guest execution environment is coupled to each approved external relay server via the host computing device and an external computer network; and b) preventing, by the guest data management application, file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the approved external relay servers.
5. The method according to claim 4, wherein The method further comprises: a) identifying, by the guest data management application, an attempted external file transfer from a given guest application process to a given external computing device, wherein the attempted external file transfer comprises: the given guest application process attempting to transfer at least one given data file to the given external computing device via the host execution environment; b) determining, via the guest data management application, that the given external computing device is not associated with any approved external relay server; and c) in response to determining that the given external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, the given guest application process from transferring the at least one given data file to any location external to the guest execution environment, thereby preventing the attempted external file transfer to the given external computing device.
6. The method according to claim 4, wherein: The method further comprises: a) identifying, by the guest data management application, an incoming file transfer from a specific external computing device, wherein the incoming file transfer comprises: at least one specific data file transferred from the specific external computing device through the host execution environment; b) determining, through the guest data management application, that the particular external computing device is not associated with any approved external relay server; and c) in response to determining that the specific external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, access to the at least one specific data file by any guest application process of the plurality of guest application processes.
7. The method according to claim 4, wherein: The method further comprises: a) securely exchanging, through the guest data management application, the at least one guest encryption key with a specific permitted external relay server, wherein the guest data management application is configured to exchange the at least one guest encryption key with the specific permitted external relay server through the host execution environment without exposing the at least one guest encryption key to the host execution environment outside of the guest execution environment.
8. The method according to claim 1 or 2, wherein: The method further comprises: a) identifying, by the guest data management application, at least one permitted peripheral device associated with the host execution environment; and b) preventing, by the guest data management application, unencrypted data transmission between the guest execution environment and any peripheral devices other than permitted peripheral devices.
9. The method according to claim 8, wherein The method also includes preventing, by the guest data management application, any data transfer between the guest execution environment and any peripheral devices other than permitted peripheral devices.
10. The method according to claim 1 or 2, wherein: The at least one permitted host process running in the host execution environment includes a host process corresponding to the virtualized application.
11. A computer program product for providing an isolated working environment on a host computing device, the host computing device having a host processor, the host processor defining a host execution environment of the host computing device and running a plurality of host processes including a virtualized application in the host execution environment, wherein: The multiple host processes include multiple non-kernel host processes, the virtualization application simulates a guest execution environment, wherein a guest operating system is installed in the guest execution environment and multiple guest application processes are run in the guest operating system, and the computer program product includes a computer-readable medium having computer-executable instructions stored thereon, the instructions being used to configure the host processor of the host computing device to: a) running a guest data management application in the guest operating system, wherein the guest data management application is configured to: control data transfers from the plurality of guest application processes to any location outside the guest execution environment; b) storing, by the guest data management application, at least one guest encryption key, wherein the at least one guest encryption key is accessible by the guest data management application in the guest execution environment and is inaccessible to: i) the host execution environment; and ii) a user of the host computing device; c) identifying, by the guest data management application, an attempted data transfer from a specific guest application process among the plurality of guest application processes to a specific location outside the guest execution environment, wherein the attempted data transfer comprises: the specific guest application process attempting to transfer at least one data file to the specific location outside the guest execution environment; d) determining, by the guest data management application, that the at least one data file comprises a secure data file; e) encrypting, by the guest data management application, the secure data file using a specific guest encryption key from the at least one guest encryption key; f) allowing, by the guest data management application, an attempted data transfer only after encrypting the secure data file, thereby transferring the secure data file from the guest execution environment as an encrypted secure data file; g) identifying, by the guest data management application, at least one permitted host process from the plurality of host processes running in the host execution environment; and h) preventing unencrypted data transmission from any guest application process among the plurality of guest application processes to any non-kernel host process other than the plurality of permitted host processes, while allowing unencrypted data transmission from the non-kernel host process to any guest application process among the plurality of guest application processes.
12. The computer program product of claim 11, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) identifying, by the guest data management application, at least one secure guest application running in the guest operating system; as well as b) determining that the at least one data file includes a security data file by: i) determining that the specific guest application process corresponds to a specific secure guest application among the at least one secure guest application; as well as ii) in response to determining that the specific guest application process corresponds to the specific secure guest application, identifying all data files of the at least one data file as secure data files.
13. The computer program product according to claim 11 or 12, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) identifying, by the guest data management application, at least one permitted external computing device, wherein the guest execution environment is coupled to each permitted external computing device via the host computing device and an external computer network; and b) preventing, by the guest data management application, file transfers between the guest execution environment and any external computing devices other than permitted external computing devices.
14. The computer program product according to claim 11 or 12, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) identifying, by the guest data management application, at least one approved external relay server, wherein the guest execution environment is coupled to each approved external relay server via the host computing device and an external computer network; and b) preventing, by the guest data management application, file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the approved external relay servers.
15. The computer program product of claim 14, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) identifying, by the guest data management application, an attempted external file transfer from a given guest application process to a given external computing device, wherein the attempted external file transfer comprises: the given guest application process attempting to transfer at least one given data file to the given external computing device via the host execution environment; b) determining, via the guest data management application, that the given external computing device is not associated with any approved external relay server; and c) in response to determining that the given external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, the given guest application process from transferring the at least one given data file to any location external to the guest execution environment, thereby preventing the attempted external file transfer to the given external computing device.
16. The computer program product of claim 14, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) identifying, by the guest data management application, an incoming file transfer from a specific external computing device, wherein the incoming file transfer comprises: at least one specific data file transferred from the specific external computing device through the host execution environment; b) determining, through the guest data management application, that the particular external computing device is not associated with any approved external relay server; and c) in response to determining that the specific external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, access to the at least one specific data file by any guest application process of the plurality of guest application processes.
17. The computer program product of claim 14, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) securely exchanging, through the guest data management application, the at least one guest encryption key with a specific permitted external relay server, wherein the guest data management application is configured to exchange the at least one guest encryption key with the specific permitted external relay server through the host execution environment without exposing the at least one guest encryption key to the host execution environment outside of the guest execution environment.
18. The computer program product according to claim 11 or 12, wherein: The computer program product further includes instructions for configuring the host processor of the host computing device to: a) identifying, by the guest data management application, at least one permitted peripheral device associated with the host execution environment; as well as b) preventing, by the guest data management application, unencrypted data transmission between the guest execution environment and any peripheral devices other than permitted peripheral devices.
19. The computer program product of claim 18, wherein: The computer program product also includes instructions for configuring the host processor of the host computing device to prevent, by the guest data management application, any data transfer between the guest execution environment and any peripheral device other than permitted peripheral devices.
20. The computer program product according to claim 11 or 12, wherein: The at least one permitted host process running in the host execution environment includes a host process corresponding to the virtualized application.
21. A device for providing an isolated working environment, the device comprising: a) processor; and b) a non-volatile device memory having stored thereon instructions for configuring the processor to: i) limit the host execution environment; ii) running a plurality of host processes including a virtualized application in the host execution environment, wherein the plurality of host processes include a plurality of non-kernel host processes, and the virtualized application simulates a guest execution environment, wherein a guest operating system is installed in the guest execution environment, and a plurality of guest application processes are running in the guest operating system; iii) running a guest data management application in the guest operating system, wherein the guest data management application is configured to: control data transfers from the plurality of guest application processes to any location outside the guest execution environment; iv) storing, by the guest data management application, at least one guest encryption key, wherein the at least one guest encryption key is accessible by the guest data management application in the guest execution environment and is inaccessible to: the host execution environment; and the user of the device; v) identifying, by the guest data management application, an attempted data transfer from a specific guest application process among the plurality of guest application processes to a specific location external to the guest execution environment, wherein the attempted data transfer comprises an attempt by the specific guest application process to transfer at least one data file to the specific location external to the guest execution environment; vi) determining, by the guest data management application, that the at least one data file comprises a secure data file; vii) encrypting, by the guest data management application, the secure data file using a specific guest encryption key from the at least one guest encryption key; and viii) allowing, by the guest data management application, an attempted data transfer only after encrypting the secure data file, thereby transferring the secure data file from the guest execution environment as an encrypted secure data file; ix) identifying, by the guest data management application, at least one permitted host process from the plurality of host processes running in the host execution environment; and x) preventing unencrypted data transmission from any guest application process among the multiple guest application processes to any non-kernel host process other than the multiple permitted host processes, while allowing unencrypted data transmission from the non-kernel host process to any guest application process among the multiple guest application processes.
22. The apparatus according to claim 21, wherein The instructions are defined to configure the processor to further: a) identifying, by the guest data management application, at least one secure guest application running in the guest operating system; and b) determining that the at least one data file includes a security data file by: i) determining that the specific guest application process corresponds to a specific secure guest application among the at least one secure guest application; as well as ii) in response to determining that the specific guest application process corresponds to the specific secure guest application, identifying all data files of the at least one data file as secure data files.
23. The apparatus according to claim 21 or 22, wherein The instructions are defined to configure the processor to further: a) identifying, by the guest data management application, at least one permitted external computing device, wherein the guest execution environment is coupled to each permitted external computing device via the device and an external computer network; and b) preventing, by the guest data management application, file transfers between the guest execution environment and any external computing devices other than permitted external computing devices.
24. The apparatus according to claim 21 or 22, wherein The instructions are defined to configure the processor to further: a) identifying, by the guest data management application, at least one approved external relay server, wherein the guest execution environment is coupled to each approved external relay server via the device and an external computer network; and b) preventing, by the guest data management application, file transfers between the guest execution environment and any external computing device other than an external computing device associated with one of the approved external relay servers.
25. The apparatus of claim 24, wherein: The instructions are defined to configure the processor to further: a) identifying, by the guest data management application, an attempted external file transfer from a given guest application process to a given external computing device, wherein the attempted external file transfer comprises: the given guest application process attempting to transfer at least one given data file to the given external computing device via the host execution environment; b) determining, via the guest data management application, that the given external computing device is not associated with any approved external relay server; and c) in response to determining that the given external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, the given guest application process from transferring the at least one given data file to any location external to the guest execution environment, thereby preventing the attempted external file transfer to the given external computing device.
26. The apparatus of claim 24, wherein: The instructions are defined to configure the processor to further: a) identifying, by the guest data management application, an incoming file transfer from a specific external computing device, wherein the incoming file transfer comprises: at least one specific data file transferred from the specific external computing device through the host execution environment; b) determining, through the guest data management application, that the particular external computing device is not associated with any approved external relay server; and c) in response to determining that the specific external computing device is not associated with any permitted external relay server, preventing, by the guest data management application, access to the at least one specific data file by any guest application process of the plurality of guest application processes.
27. The apparatus of claim 24, wherein: The instructions are defined to configure the processor to further: a) securely exchanging, through the guest data management application, the at least one guest encryption key with a specific permitted external relay server, wherein the guest data management application is configured to exchange the at least one guest encryption key with the specific permitted external relay server through the host execution environment without exposing the at least one guest encryption key to the host execution environment outside of the guest execution environment.
28. The apparatus according to claim 21 or 22, wherein The instructions are defined to configure the processor to further: a) identifying, by the guest data management application, at least one permitted peripheral device associated with the host execution environment; as well as b) preventing, by the guest data management application, unencrypted data transmission between the guest execution environment and any peripheral devices other than permitted peripheral devices.
29. The apparatus of claim 28, wherein The instructions are defined to further configure the processor to: prevent, by the guest data management application, any data transfer between the guest execution environment and any peripheral device other than permitted peripheral devices.
30. The apparatus according to claim 21 or 22, wherein The at least one permitted host process running in the host execution environment includes a host process corresponding to the virtualized application.
Citation Information
Patent Citations
Techniques to secure computation data in a computing environment
CN107851167A
System and method for securing a computer comprising a microkernel
US20110035586A1