Virtualized Group Policy Injection for Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The application of corporate security policies, such as Group Policy from Active Directory, becomes challenging with the advent of application virtualization, as it is difficult to deliver and apply these policies to virtualized applications without affecting the target computer's file and registry system.

Innovation Solution

A method is developed to create a virtualized group policy object that is injected into a virtualized application stream, allowing policy settings to be delivered and applied within the virtualized application's file and registry system independently of the target computer's system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Group Policy settings are applied to virtualized applications, then security and consistency of virtualized applications are improved, but the complexity of policy delivery and management increases

Engineering Contradiction:
Improvesecurity and consistency of virtualized applicationsVSAvoidcomplexity of policy delivery and management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds Group Policy settings directly within the virtualized application package, creating a nested structure where policy objects are contained inside the application's virtual file system. This allows policies to be delivered alongside the application without requiring separate policy management infrastructure, thus improving security while avoiding increased management complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces a policy injection mechanism that acts as an intermediary between the virtualized application and the target computer's operating system. This mediator injects policy settings into the virtualized application's environment without affecting the host system, enabling secure policy enforcement while simplifying the overall delivery process by handling policy integration automatically.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If policy settings are delivered with virtualized applications, then policy enforcement within virtualized environments is improved, but the difficulty of detecting and measuring policy application increases

Engineering Contradiction:
Improvepolicy enforcement within virtualized environmentsVSAvoiddifficulty of detecting and measuring policy application
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism that tracks and reports policy application status within virtualized environments. The system monitors whether policies have been successfully injected and applied to virtualized applications, providing visibility into policy enforcement without requiring complex external detection methods.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates copies of policy settings within the virtualized application's file system and registry. These policy copies mirror the host system's policies but exist independently within the virtual environment, making them detectable through standard file system operations while maintaining isolation from the host system.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If traditional Group Policy methods are used with virtualized applications, then compatibility with existing infrastructure is improved, but the ability to apply policies without affecting target computer system is worsened

Engineering Contradiction:
Improvecompatibility with existing infrastructureVSAvoidimpact on target computer's file and registry system
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the policy application process by separating virtualized application policies from the host operating system policies. Policy settings are divided into distinct virtualized containers that operate independently, allowing traditional Group Policy methods to be used for host management while new virtualized policy mechanisms handle application-specific settings without cross-contamination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts policy settings from the host system's file and registry structures and places them into the virtualized application's isolated environment. This extraction ensures that policies are applied only where needed within the virtualized context, preventing any unwanted side effects on the target computer's underlying system while maintaining compatibility with existing policy infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8078713B1Delivering policy settings with virtualized applications
Publication Date: 2011.12.13 FULL ARMOR CORP
  • US8078713B1 patent drawing
  • US8078713B1 patent drawing
  • US8078713B1 patent drawing

AI summary

In an embodiment, a method includes receiving a group policy object from an active directory, combining the group policy object and logic for using the group policy object with a virtualized application to provide a virtualized group policy object and delivering the virtualized application and the virtualized group policy object to a targeted computer system.