US2016196426A1PendingUtilityA1

Ultra-low cost sandboxing for application appliances

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Jul 13, 2010Filed: Mar 15, 2016Published: Jul 7, 2016
Est. expiryJul 13, 2030(~4 yrs left)· nominal 20-yr term from priority
G06F 21/53
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosed architecture facilitates the sandboxing of applications by taking core operating system components that normally run in the operating system kernel or otherwise outside the application process and on which a sandboxed application depends on to run, and converting these core operating components to run within the application process. The architecture takes the abstractions already provided by the host operating system and converts these abstractions for use by the sandbox environment. More specifically, new operating system APIs (application program interfaces) are created that include only the basic computation services, thus, separating the basic services from rich application APIs. The code providing the rich application APIs is copied out of the operating system and into the application environment—the application process.

Claims

exact text as granted — not AI-modified
1 - 9 . (canceled) 
     
     
         10 . A computer-implemented secure application execution system having computer readable media that store executable instructions executed by a processor, comprising:
 an isolation container in which an application for a first OS runs in isolation, the isolation container formed in association with a second OS;   an isolated OS subsystem that runs in the isolation container in association with and interfaces to the application to provide rich functionality to the application; and   an isolation monitor of the second OS that interfaces basic computation services of the second OS to the isolated OS subsystem to enable the application to run in isolation on the second OS.   
     
     
         11 . The system of  claim 10 , wherein the basic computation services include at least one of virtual memory management, thread creation, or thread synchronization. 
     
     
         12 . The system of  claim 10 , wherein the rich functionality provided by the isolated OS subsystem includes at least one of a graphical user interface (GUI) service, an application configuration management service, a printer service, or an audio service. 
     
     
         13 . The system of  claim 10 , wherein the isolated application uses a corresponding remote user I/O server to communicate with a user I/O client outside the isolation container. 
     
     
         14 . The system of  claim 10 , wherein the isolated application is migrated to a second computing environment by reading from some or all of an address space of the isolation container, which is in a first computing environment. 
     
     
         15 . The system of  claim 10 , wherein the isolation monitor employs a collection of rules that map from an application manifest to approval or denial of resource requests, the manifest defines which resources outside the isolation container are available to the isolated application. 
     
     
         16 - 20 . (canceled) 
     
     
         21 . A system comprising:
 one or more computer readable media storing executable instructions; and   one or more processing units configured to execute the executable instructions, wherein the executable instructions cause the one or more processing units to:   execute an isolated application in an isolation container on the system;   provide first operating system (OS) services to the isolated application using an isolated OS subsystem of the isolation container, wherein the isolated OS subsystem provides the first OS services via interfaces associated with a first OS; and   provide second OS services to the isolation container using a second OS other than the first OS.   
     
     
         22 . The system of  claim 21 , wherein the second OS services comprise basic computation services. 
     
     
         23 . The system of  claim 22 , wherein the basic computation services comprise virtual memory management, thread creation, and thread synchronization. 
     
     
         24 . The system of  claim 23 , wherein the first OS services comprise rich functionality. 
     
     
         25 . The system of  claim 24 , wherein the rich functionality comprises graphical user interface services, application configuration management services, printer services, and audio services. 
     
     
         26 . The system of  claim 25 , wherein the first OS and the second OS are provided by different vendors. 
     
     
         27 . The system of  claim 25 , wherein the first OS and the second OS are different OS versions provided by a single vendor. 
     
     
         28 . A method performed on a computer system, the method comprising:
 causing an isolated application to execute in an isolation container, the isolation container comprising an application process;   executing an isolated operating system (OS) subsystem in the application process with the isolated application, wherein the isolated OS subsystem provides first OS services associated with a first OS to the isolated application; and   providing second OS services to the isolated OS subsystem using a second OS other than the first OS.   
     
     
         29 . The method of  claim 28 , further comprising:
 migrating the application process to another computing system.   
     
     
         30 . The method of  claim 28 , further comprising:
 providing the second OS services in another process that is separate from the application process.   
     
     
         31 . The method of  claim 30 , wherein the first OS services provided in the application process include graphical user interface services. 
     
     
         32 . The method of  claim 29 , wherein the second OS services provided in the another process include virtual memory management services. 
     
     
         33 . The method of  claim 32 , wherein the first OS services provided in the application process include graphical user interface services and the second OS services provided in the another process include thread creation or thread synchronization services. 
     
     
         34 . The method of  claim 28 , wherein the computer system is a mobile phone.

Join the waitlist — get patent alerts

Track US2016196426A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.