US2016196449A1PendingUtilityA1
Apparatus for and Method of Preventing Unsecured Data Access
Est. expiryJul 15, 2034(~8 yrs left)· nominal 20-yr term from priority
Inventors:Neil Sikka
G06F 21/6218G06F 21/6254G06F 9/45558G06F 2009/45591G06F 21/602G06F 21/6245
33
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Shown and depicted is preventing sensitive information from being exfiltrated from an organization using hypervisors. A Data Loss Prevention system is composed using virtual machines or domains to segment memory between domains which are assumed to be untrusted and domains which are known to be trusted. Sensitive information is cypher text when observed by software in Untrusted Domains, and clear text when observed by software in Trusted Domains. Sensitive information is unencrypted when it is in the address space of a protected process running inside a trusted domain.
Claims
exact text as granted — not AI-modifiedI claim:
1 . Computer comprising a processor configured to:
execute a trusted domain and a process in the trusted domain that is executed in response to a request that is without an authentication protocol; prevent output of unsecured content from the trusted domain other than as necessary for user sensory stimulation; and one or both of: secure content from the trusted domain so as to be unsecurable only within a controlled environment; and unsecure content from data that is unsecurable only within a controlled environment.
2 . Computer of claim 1 , wherein said processor is configured to route without an untrusted domain: input, output, device assignment and combinations thereof.
3 . Computer of claim 1 , wherein said processor is configured to permit content from a domain to be input into the trusted domain.
4 . Computer of claim 1 , wherein said processor is configured to execute a designated domain to which sensory output from another domain is forwarded.
5 . Computer of claim 1 , wherein said processor is configured to transmit and/or receive data.
6 . Computer of claim 1 , wherein said processor is configured to route input and/or output according to a domain contemporaneously having focus.
7 . Computer of claim 1 , wherein the request comprises selecting data from a medium.
8 . Computer of claim 7 , wherein said processor is configured to execute a process appropriate for a content type associated with the data in a trusted domain.
9 . Method of securing content comprising:
executing a trusted domain; executing a process in the trusted domain responsive to a request without an authentication protocol; preventing output of unsecured content from the trusted domain other than as necessary for user sensory stimulation; and one or both of: securing content from the trusted domain so as to be unsecurable only within a controlled environment; and unsecuring content from data that is unsecurable only within a controlled environment.
10 . Method of claim 9 , further comprising routing without an untrusted domain: input, output, device assignment and combinations thereof.
11 . Method of claim 9 , further comprising permitting content from a domain to be input into a trusted domain.
12 . Method of claim 9 , further comprising:
executing a designated domain; and forwarding sensory output to the designated domain from another domain.
13 . Method of claim 9 , further comprising transmitting and/or receiving data.
14 . Method of claim 9 , further comprising routing input and/or output according to a domain contemporaneously having focus.
15 . Method of claim 9 , wherein the request comprises selecting data from a medium.
16 . Method of claim 15 , further comprising executing a process appropriate for a content type associated with the data in a trusted domain.Join the waitlist — get patent alerts
Track US2016196449A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.