Client authentication and data management system
Abstract
Methods and systems for performing an authenticated boot; performing a continuous data protection; performing automatic protection and optionally a consolidation; and performing other defenses and protection of a protected computing device (such as a computer system) are provided. The aspects include integrating security mechanisms (which may include a “call home” function, role and rule-based policies, validating technologies, encryption and decryption technologies, data compression technologies, protected and segmented boot technologies, and virtualization technologies. Booting and operating (either fully or in a restricted manner) are permitted only under a control of a specified role-set, rule-set, and/or a controlling supervisory process or server system(s). The methods and systems make advantageous use of hypervisors and other virtual machine monitors or managers.
Claims
exact text as granted — not AI-modifiedI claim:
1 . A system for protecting a computing device from unauthorized use comprising:
(a) a computing device configured for communication over a network, said computing device having memory, storage, and input/output functions, said computing device capable of being connected to a network; (b) a virtual machine configured to run on the device and a virtual machine operating system configured to run in said virtual machine, said server configured for authenticating said computing device, said virtual machine configured to communicate a request for authentication to said server prior to launching said virtual machine operating system, said virtual machine configured to either launch or not launch said virtual machine operating system based upon a response from said server to said request for authentication.
2 . The system of claim 1 , wherein the computing device boots a host operating system prior to the launch of said virtual machine and said virtual machine operating system.
3 . The system of claim 1 , wherein said virtual machine is launched during the boot of said computing device to run on said computing device without an underlying host operating system.
4 . The system of claim 1 , wherein said computing device is selected from the group consisting of a server computer, a desktop computer, a personal computer, a notebook computer, a laptop computer, a mobile computing device, a personal digital assistant, a hand-held computer, a tablet computer, a cellular telephone, and a satellite telephone.
5 . The system of claim 1 , wherein said network is selected from the group consisting of a wireless network, a wired network, a broadband network, a cellular telephone network, a satellite telephone network, a Wi-Fi network, a WiMax network, a local area network (LAN), a wide area network (WAN), the Internet, and a virtual network.
6 . The system of claim 1 , wherein said server is remote from said computing device and said computing device communicates with said server over said network.
7 . The system of claim 1 wherein said server is an authentication server and said request for authentication comprises information provided by a user, information stored on said computing device, information stored on the server, or a combination thereof.
8 . The system of claim 1 , wherein said virtual machine comprises a virtual machine manager, and said virtual machine manager comprises a hypervisor.
9 . The system of claim 8 , wherein said virtual machine manager further comprises a network communications stack.
10 . The system of claim 1 , wherein said virtual machine comprises a protected partition.
11 . The system of claim 10 , wherein said protected partition is encrypted.
12 . The system of claim 11 , wherein said protected partition is either decrypted or not decrypted based on said response to said request for authentication.
13 . The system of claim 1 wherein said virtual machine operating system is limited in its ability to access said memory, storage, input/output functions, or network capabilities of said computing device according to a set of policies stored in a location selected from said virtual machine and said server.
14 . A system for protecting a computing device from unauthorized use comprising:
(a) a computing device configured for communication over a network, said computing device having a virtual machine manager configured to run on said computing device, said computing device having memory, storage, input/output functions, and network capabilities; (b) a virtual machine controlled by said virtual machine manager; (c) a virtual machine operating system configured to run in said virtual machine; and (d) a server configured for authenticating said computing device, said virtual machine manager configured to communicate a request for authentication to said server prior to launching said virtual machine, said virtual machine manager configured to either launch said virtual machine and boot said virtual machine operating system, or to not launch said virtual machine, based upon a response from said server to said request for authentication.
15 . The system of claim 14 , wherein said virtual machine is limited in its ability to access said memory, storage, input/output functions, and network capabilities of said computing device based upon said response to said request for authentication.
16 . The system of claim 15 , wherein said computing device boots a host operating system prior to the launch of said virtual machine manager and said virtual machine.
17 . The system of claim 14 , wherein said virtual machine manager is launched during boot of said computing device to run on said computing device without an underlying host operating system.
18 . A system comprising:
(a) a computing device configured for communication over a network (b) a virtual machine manager configured to communicate over said network; (c) a virtual machine configured to communicate with and be controlled by said virtual machine manager; (d) a server program configured for authenticating said computing device, said virtual machine manager configured to communicate a request for authentication to said server program prior to launching said virtual machine, and said virtual machine manager configured to either launch or not launch said virtual machine to run on said computing device based upon a response to said request for authentication.
19 . The system of claim 18 , wherein said server program, said virtual machine manager, and said virtual machine execute on said computing device.
20 . The system of claim 18 , wherein said server program executes in a server computer separate from said computing device.Join the waitlist — get patent alerts
Track US2016078230A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.