Virtualized Group Policy Injection for Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The application of corporate security policies, such as Group Policy from Active Directory, becomes challenging with the advent of application virtualization, as it is difficult to deliver and apply these policies to virtualized applications without affecting the target computer's file and registry system.
Innovation Solution
A method is developed to create a virtualized group policy object that is injected into a virtualized application stream, allowing policy settings to be delivered and applied within the virtualized application's file and registry system independently of the target computer's system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Group Policy settings are applied to virtualized applications, then security and consistency of virtualized applications are improved, but the complexity of policy delivery and management increases
Solution Approach 1:
The patent embeds Group Policy settings directly within the virtualized application package, creating a nested structure where policy objects are contained inside the application's virtual file system. This allows policies to be delivered alongside the application without requiring separate policy management infrastructure, thus improving security while avoiding increased management complexity.
Solution Approach 2:
The patent introduces a policy injection mechanism that acts as an intermediary between the virtualized application and the target computer's operating system. This mediator injects policy settings into the virtualized application's environment without affecting the host system, enabling secure policy enforcement while simplifying the overall delivery process by handling policy integration automatically.
2Reliability
If policy settings are delivered with virtualized applications, then policy enforcement within virtualized environments is improved, but the difficulty of detecting and measuring policy application increases
Solution Approach 1:
The patent implements a feedback mechanism that tracks and reports policy application status within virtualized environments. The system monitors whether policies have been successfully injected and applied to virtualized applications, providing visibility into policy enforcement without requiring complex external detection methods.
Solution Approach 2:
The patent creates copies of policy settings within the virtualized application's file system and registry. These policy copies mirror the host system's policies but exist independently within the virtual environment, making them detectable through standard file system operations while maintaining isolation from the host system.
3Adaptability or versatility
If traditional Group Policy methods are used with virtualized applications, then compatibility with existing infrastructure is improved, but the ability to apply policies without affecting target computer system is worsened
Solution Approach 1:
The patent segments the policy application process by separating virtualized application policies from the host operating system policies. Policy settings are divided into distinct virtualized containers that operate independently, allowing traditional Group Policy methods to be used for host management while new virtualized policy mechanisms handle application-specific settings without cross-contamination.
Solution Approach 2:
The patent extracts policy settings from the host system's file and registry structures and places them into the virtualized application's isolated environment. This extraction ensures that policies are applied only where needed within the virtualized context, preventing any unwanted side effects on the target computer's underlying system while maintaining compatibility with existing policy infrastructure.
Data Source
AI summary
In an embodiment, a method includes receiving a group policy object from an active directory, combining the group policy object and logic for using the group policy object with a virtualized application to provide a virtualized group policy object and delivering the virtualized application and the virtualized group policy object to a targeted computer system.


