US2017132430A1PendingUtilityA1

Apparatus for and Method of Preventing Unsecured Data Access

Assignee: SIKKA NEILPriority: Jul 15, 2014Filed: Jun 17, 2015Published: May 11, 2017
Est. expiryJul 15, 2034(~8 yrs left)· nominal 20-yr term from priority
Inventors:Neil Sikka
G06F 21/6218G06F 21/6245G06F 2009/45591G06F 21/6254G06F 9/45558G06F 21/602
31
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Shown and depicted is preventing sensitive data from being exfiltrated from an organization using hypervisors. A Data Loss Prevention system is composed using virtual machines or domains to segment memory between domains which are assumed to be untrusted and domains which are known to be trusted. Sensitive data is cypher text when observed by software in Untrusted Domains, and clear text when observed by software in Trusted Domains. Sensitive data is unencrypted when it is in the address space of a protected process running inside a trusted domain.

Claims

exact text as granted — not AI-modified
1 . Computer comprising a processor configured to: execute a domain, a trusted domain and a process in the trusted domain that is executed in response to a request from within the domain; and secure writes from the trusted domain; wherein the request is not a request to connect. 
     
     
         2 . Computer of  claim 1 , wherein said processor is configured to route without an untrusted domain: input, output, device assignment and combinations thereof. 
     
     
         3 . Computer of  claim 1 , wherein said processor is configured to permit data from a domain to be input into a trusted domain. 
     
     
         4 . Computer of  claim 1 , wherein said processor is configured to prevent output of unsecured data from a trusted domain other than as necessary for user sensory stimulation. 
     
     
         5 . Computer of  claim 1 , wherein said processor is configured to execute a designated domain to which display output from domains is forwarded. 
     
     
         6 . Computer of  claim 1 , wherein said processor is configured to transmit data and/or receive data. 
     
     
         7 . Computer of  claim 1 , wherein the request comprises selecting a file from a medium. 
     
     
         8 . Computer of  claim 7 , wherein said processor is configured to execute a process appropriate for a file type associated with the file in a trusted domain. 
     
     
         9 . Computer of  claim 7 , wherein said processor is configured to unsecure data of a file. 
     
     
         10 . Method of securing data comprising:
 executing a domain;   executing a trusted domain;   executing a process in the trusted domain; and   writing data; and, if said writing is from the trusted domain, prior to said writing, securing the data;   
       wherein said executing a process is responsive to a request within the domain and is not a request to connect. 
     
     
         11 . Method of  claim 10 , further comprising routing without an untrusted domain: input, output, device assignment and combinations thereof. 
     
     
         12 . Method of  claim 10 , further comprising permitting data from a domain to be input into a trusted domain. 
     
     
         13 . Method of  claim 10 , further comprising preventing output of unsecured data from a trusted domain other than as necessary for user sensory stimulation. 
     
     
         14 . Method of  claim 10 , further comprising:
 executing a designated domain; and   forwarding display output from domains to the designated domain.   
     
     
         15 . Method of  claim 10 , further comprising transmitting data and/or receiving data. 
     
     
         16 . Method of  claim 10 , wherein the request comprises selecting a file from a medium. 
     
     
         17 . Method of  claim 16 , further comprising executing a process appropriate for a file type associated with the file in a trusted domain. 
     
     
         18 . Method of  claim 16 , further comprising unsecuring the data of the file. 
     
     
         19 . (canceled) 
     
     
         20 . Method of securing data comprising routing input and output according to a domain contemporaneously having focus.

Join the waitlist — get patent alerts

Track US2017132430A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.