DE102012210887B4 - Verfahren zum Einrichten einer sicher verwalteten Ausführungsumgebung für eine virtuelle Maschine und eine Computervorrichtung - Google Patents
Verfahren zum Einrichten einer sicher verwalteten Ausführungsumgebung für eine virtuelle Maschine und eine Computervorrichtung Download PDFInfo
- Publication number
- DE102012210887B4 DE102012210887B4 DE102012210887.4A DE102012210887A DE102012210887B4 DE 102012210887 B4 DE102012210887 B4 DE 102012210887B4 DE 102012210887 A DE102012210887 A DE 102012210887A DE 102012210887 B4 DE102012210887 B4 DE 102012210887B4
- Authority
- DE
- Germany
- Prior art keywords
- section
- operating system
- application
- virtual machine
- security agent
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/445—Program loading or initiating
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/606—Protecting data by securing the transmission between two devices or processes
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45587—Isolation or security of virtual machine instances
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2141—Access rights, e.g. capability lists, access control lists, access tables, access matrices
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- General Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Health & Medical Sciences (AREA)
- Databases & Information Systems (AREA)
- Storage Device Security (AREA)
- Stored Programmes (AREA)
- Computer And Data Communications (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2011-143993 | 2011-06-29 | ||
| JP2011143993A JP5719244B2 (ja) | 2011-06-29 | 2011-06-29 | 安全に管理された仮想マシンの実行環境を構築する方法、プログラムおよびコンピュータ装置 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| DE102012210887A1 DE102012210887A1 (de) | 2013-01-03 |
| DE102012210887B4 true DE102012210887B4 (de) | 2022-12-15 |
Family
ID=46546537
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| DE102012210887.4A Expired - Fee Related DE102012210887B4 (de) | 2011-06-29 | 2012-06-26 | Verfahren zum Einrichten einer sicher verwalteten Ausführungsumgebung für eine virtuelle Maschine und eine Computervorrichtung |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US8595511B2 (enExample) |
| JP (1) | JP5719244B2 (enExample) |
| DE (1) | DE102012210887B4 (enExample) |
| GB (1) | GB2492448B (enExample) |
Families Citing this family (16)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP5719244B2 (ja) * | 2011-06-29 | 2015-05-13 | インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation | 安全に管理された仮想マシンの実行環境を構築する方法、プログラムおよびコンピュータ装置 |
| CN103294970B (zh) * | 2012-02-23 | 2015-12-09 | 纬创资通股份有限公司 | 双操作系统共用加密设定的方法以及电子装置 |
| CN103294545B (zh) | 2012-02-23 | 2017-07-04 | 纬创资通股份有限公司 | 切换双操作系统的方法以及电子装置 |
| CN103294562B (zh) | 2012-02-23 | 2017-03-01 | 纬创资通股份有限公司 | 双操作系统共用周边装置的方法以及电子装置 |
| US8839447B2 (en) * | 2012-02-27 | 2014-09-16 | Ca, Inc. | System and method for virtual image security in a cloud environment |
| US8938612B1 (en) * | 2013-07-31 | 2015-01-20 | Google Inc. | Limited-access state for inadvertent inputs |
| WO2015070376A1 (zh) * | 2013-11-12 | 2015-05-21 | 华为技术有限公司 | 一种实现虚拟化安全的方法和系统 |
| US9641488B2 (en) | 2014-02-28 | 2017-05-02 | Dropbox, Inc. | Advanced security protocol for broadcasting and synchronizing shared folders over local area network |
| US9158909B2 (en) | 2014-03-04 | 2015-10-13 | Amazon Technologies, Inc. | Authentication of virtual machine images using digital certificates |
| EP3234782A4 (en) * | 2014-12-16 | 2018-10-17 | Kyndi, Inc. | Method and apparatus for randomizing computer instruction sets, memory registers and pointers |
| US10185480B1 (en) * | 2015-06-15 | 2019-01-22 | Symantec Corporation | Systems and methods for automatically making selections in user interfaces |
| US9767318B1 (en) * | 2015-08-28 | 2017-09-19 | Frank Dropps | Secure controller systems and associated methods thereof |
| US12339979B2 (en) | 2016-03-07 | 2025-06-24 | Crowdstrike, Inc. | Hypervisor-based interception of memory and register accesses |
| US12248560B2 (en) * | 2016-03-07 | 2025-03-11 | Crowdstrike, Inc. | Hypervisor-based redirection of system calls and interrupt-based task offloading |
| JP6329331B1 (ja) * | 2016-07-04 | 2018-05-23 | 株式会社Seltech | 人工知能を有するシステム |
| CN109445902B (zh) * | 2018-09-06 | 2021-05-07 | 新华三云计算技术有限公司 | 一种数据操作方法和系统 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040239700A1 (en) | 2003-03-17 | 2004-12-02 | Baschy Leo Martin | User interface driven access control system and method |
| JP2007287078A (ja) | 2006-04-20 | 2007-11-01 | Internatl Business Mach Corp <Ibm> | 個人情報の保護を支援する情報処理装置 |
| US20090254990A1 (en) | 2008-04-05 | 2009-10-08 | Mcgee William Gerald | System and method for intelligent coordination of host and guest intrusion prevention in virtualized environment |
| US20110153853A1 (en) | 2009-12-18 | 2011-06-23 | Microsoft Corporation | Remote application presentation over a public network connection |
Family Cites Families (43)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5752005A (en) | 1996-01-22 | 1998-05-12 | Microtest, Inc. | Foreign file system establishing method which uses a native file system virtual device driver |
| US20050144072A1 (en) * | 1996-10-25 | 2005-06-30 | Perkowski Thomas J. | Internet-based brand management and marketing communication instrumentation network for deploying, installing and remotely programming brand-building server-side driven multi-mode virtual kiosks on the World Wide Web (WWW), and methods of brand marketing communication between brand marketers and consumers using the same |
| JPH10301874A (ja) * | 1997-04-22 | 1998-11-13 | Internatl Business Mach Corp <Ibm> | 遠隔操作方法、ネットワークを介して端末から遠隔操作されるサーバ及びhtmlファイルを格納する記憶媒体 |
| US6356915B1 (en) | 1999-02-22 | 2002-03-12 | Starbase Corp. | Installable file system having virtual file system drive, virtual device driver, and virtual disks |
| US7814335B2 (en) * | 1999-03-18 | 2010-10-12 | Dell Products L.P. | System and method for installing system manufacturer provided software |
| US20080021778A1 (en) * | 1999-04-21 | 2008-01-24 | Ipf, Inc. | Web-based brand marketing communication network for enabling e-commerce transactions using Multi-Mode Virtual Kiosks (MMVKS) |
| US7844492B2 (en) * | 1999-11-17 | 2010-11-30 | Ipf, Inc. | Internet-based E-commerce network for enabling commission-based E-commerce transactions along the fabric of the world wide web (WWW) using server-side driven multi-mode virtual kiosks (MMVKS) and transaction and commission tracking servers |
| US6731756B1 (en) * | 1999-06-21 | 2004-05-04 | Elisar Software Corporation, Inc. | Method for securing video images |
| WO2001050244A1 (en) * | 2000-01-06 | 2001-07-12 | Chan Kam Fu | Running microsoft windows 95/98 on ramdisk |
| US20110238506A1 (en) * | 2000-01-14 | 2011-09-29 | Perkowski Thomas J | Internet-based brand marketing communication network for enabling commission-based e-commerce transactions along the fabric of the world wide web (www) using server-side driven multi-mode virtual kiosks (mmvks) |
| US9213836B2 (en) * | 2000-05-28 | 2015-12-15 | Barhon Mayer, Batya | System and method for comprehensive general electric protection for computers against malicious programs that may steal information and/or cause damages |
| US7117504B2 (en) * | 2001-07-10 | 2006-10-03 | Microsoft Corporation | Application program interface that enables communication for a network software platform |
| US7603440B1 (en) * | 2001-11-09 | 2009-10-13 | Persystent Technology Corporation | System and method for management of end user computing devices |
| US6978439B2 (en) | 2002-01-10 | 2005-12-20 | Microsoft Corporation | Cross-platform software development with a software development peripheral |
| US20040024710A1 (en) * | 2002-03-07 | 2004-02-05 | Llavanya Fernando | Secure input pad partition |
| US20030236889A1 (en) * | 2002-06-25 | 2003-12-25 | Microsoft Corporation | Data projection system and method |
| US7673308B2 (en) | 2002-11-18 | 2010-03-02 | Symantec Corporation | Virtual OS computing environment |
| US8141159B2 (en) * | 2002-12-31 | 2012-03-20 | Portauthority Technologies Inc. | Method and system for protecting confidential information |
| US8205072B1 (en) * | 2003-07-22 | 2012-06-19 | Cisco Technology, Inc. | Method and apparatus for electronically configuring a secured user desktop |
| US20060004667A1 (en) * | 2004-06-30 | 2006-01-05 | Microsoft Corporation | Systems and methods for collecting operating system license revenue using an emulated computing environment |
| JP4765485B2 (ja) | 2005-08-26 | 2011-09-07 | ソニー株式会社 | 情報処理装置、情報記録媒体、および情報処理方法、並びにコンピュータ・プログラム |
| US9202045B2 (en) | 2005-11-17 | 2015-12-01 | Koninklijke Philips N.V. | System for managing access control |
| US20070283389A1 (en) * | 2006-06-01 | 2007-12-06 | Sharp Laboratories Of America, Inc. | Method and system for helping operate a media-playing set |
| WO2007114456A1 (en) * | 2006-03-29 | 2007-10-11 | Casio Computer Co., Ltd. | Server apparatus of computer system |
| US8479264B2 (en) * | 2006-09-29 | 2013-07-02 | Micron Technology, Inc. | Architecture for virtual security module |
| US7987506B1 (en) * | 2006-11-03 | 2011-07-26 | Cisco Technology, Inc. | Methods and systems for dynamically updating a routing table in a virtual private network |
| JP4998019B2 (ja) * | 2007-03-06 | 2012-08-15 | 富士通株式会社 | 状態表示制御装置 |
| CN101636722B (zh) | 2007-03-20 | 2013-01-30 | 李尚奎 | 可移动的虚拟机映像 |
| JP4938576B2 (ja) | 2007-07-24 | 2012-05-23 | 日本電信電話株式会社 | 情報収集システムおよび情報収集方法 |
| JP4287485B2 (ja) | 2007-07-30 | 2009-07-01 | 日立ソフトウエアエンジニアリング株式会社 | 情報処理装置及び方法、コンピュータ読み取り可能な記録媒体、並びに、外部記憶媒体 |
| JP2009049679A (ja) | 2007-08-20 | 2009-03-05 | Fuji Xerox Co Ltd | 画像処理装置、画像処理装置制御プログラム及び画像処理システム |
| US20090158190A1 (en) * | 2007-12-13 | 2009-06-18 | Yuvee, Inc. | Computing apparatus including a personal web and application assistant |
| EP2226721B1 (en) * | 2007-12-28 | 2017-08-02 | Panasonic Intellectual Property Corporation of America | Communication device, communication system, image presentation method, and program |
| JP5176655B2 (ja) * | 2008-03-31 | 2013-04-03 | 富士通株式会社 | 画像復号化装置 |
| US20100058082A1 (en) * | 2008-08-27 | 2010-03-04 | Lenovo (Singapore) Ple., Ltd. | Maintaining network link during suspend state |
| EP2373073B1 (en) * | 2008-12-26 | 2016-11-09 | Panasonic Intellectual Property Corporation of America | Communication device |
| JP5235764B2 (ja) | 2009-04-16 | 2013-07-10 | 株式会社日立製作所 | Icチップおよびこれを搭載した情報処理装置 |
| EP2264529A3 (en) * | 2009-06-16 | 2011-02-09 | ASML Netherlands B.V. | A lithographic apparatus, a method of controlling the apparatus and a method of manufacturing a device using a lithographic apparatus |
| CN102132579A (zh) * | 2009-06-26 | 2011-07-20 | 松下电器产业株式会社 | 通信装置 |
| JP2011048661A (ja) * | 2009-08-27 | 2011-03-10 | Nomura Research Institute Ltd | 仮想サーバ暗号化システム |
| JPWO2011065007A1 (ja) * | 2009-11-30 | 2013-04-11 | パナソニック株式会社 | 携帯型通信装置、通信方法、集積回路、プログラム |
| US20120133484A1 (en) * | 2010-11-29 | 2012-05-31 | Research In Motion Limited | Multiple-input device lock and unlock |
| JP5719244B2 (ja) * | 2011-06-29 | 2015-05-13 | インターナショナル・ビジネス・マシーンズ・コーポレーションInternational Business Machines Corporation | 安全に管理された仮想マシンの実行環境を構築する方法、プログラムおよびコンピュータ装置 |
-
2011
- 2011-06-29 JP JP2011143993A patent/JP5719244B2/ja not_active Expired - Fee Related
-
2012
- 2012-05-24 GB GB1209077.5A patent/GB2492448B/en active Active
- 2012-06-04 US US13/488,369 patent/US8595511B2/en not_active Expired - Fee Related
- 2012-06-26 DE DE102012210887.4A patent/DE102012210887B4/de not_active Expired - Fee Related
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20040239700A1 (en) | 2003-03-17 | 2004-12-02 | Baschy Leo Martin | User interface driven access control system and method |
| JP2007287078A (ja) | 2006-04-20 | 2007-11-01 | Internatl Business Mach Corp <Ibm> | 個人情報の保護を支援する情報処理装置 |
| US7624427B2 (en) | 2006-04-20 | 2009-11-24 | International Business Machines Corporation | Method and apparatus for supporting personal information protection |
| US20090254990A1 (en) | 2008-04-05 | 2009-10-08 | Mcgee William Gerald | System and method for intelligent coordination of host and guest intrusion prevention in virtualized environment |
| US20110153853A1 (en) | 2009-12-18 | 2011-06-23 | Microsoft Corporation | Remote application presentation over a public network connection |
| US8370510B2 (en) | 2009-12-18 | 2013-02-05 | Microsoft Corporation | Remote application presentation over a public network connection |
Also Published As
| Publication number | Publication date |
|---|---|
| GB201209077D0 (en) | 2012-07-04 |
| DE102012210887A1 (de) | 2013-01-03 |
| JP5719244B2 (ja) | 2015-05-13 |
| JP2013012018A (ja) | 2013-01-17 |
| GB2492448A (en) | 2013-01-02 |
| GB2492448B (en) | 2013-05-15 |
| US20130007469A1 (en) | 2013-01-03 |
| US8595511B2 (en) | 2013-11-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE102012210887B4 (de) | Verfahren zum Einrichten einer sicher verwalteten Ausführungsumgebung für eine virtuelle Maschine und eine Computervorrichtung | |
| DE602004011871T2 (de) | Bereitstellung einer sicheren Eingabe an ein System mit einer Hochsicherheitsumgebung | |
| DE112010003971B4 (de) | Vorübergehende Bereitstellung höherer Vorrechte für ein Rechensystem für eine Benutzerkennung | |
| DE112020000538B4 (de) | Feinkörnige zugriffskontrolle auf token-grundlage | |
| DE69706440T2 (de) | Schutzmittel in einem verteilten rechnersystem | |
| DE112015004555B4 (de) | Verarbeiten eines Gast-Ereignisses in einem von einem Hypervisor gesteuerten System | |
| DE69530128T2 (de) | Sicherheit für rechnerbetriebsmittel | |
| EP2642395B1 (de) | Verfahren und Vorrichtung zum Ausführen von Workflow-Skripten | |
| DE69724862T2 (de) | Verfahren und Anordnung für die Zugangs- und Informationsverfälschungskontrolle in Rechnersystemen | |
| DE102007057901A1 (de) | Anordnung und Verfahren zur sicheren Aktualisierung von Firmwarevorrichtungen unter Verwendung eines Hypervisor | |
| DE112012003988T5 (de) | Schützen des Arbeitsspeichers eines virtuellen Gasts | |
| DE10248981A1 (de) | System und Verfahren zum Installieren von Anwendungen in einer vertrauenswürdigen Umgebung | |
| DE112007001321T5 (de) | Ausführung eines Sichere-Umgebungs-Initialisierungsbefehls in einem Punkt-zu-Punkt-Verbindungssystem | |
| DE69707022T2 (de) | System und verfahren zur sicheren verwaltung von desktop-umgebungen über ein netzwerk | |
| DE112011103164T5 (de) | Datenverteilungsvorrichtung, Datenverteilungssystem, Client-Vorrichtung, Datenverteilungsverfahren, Datenempfangsverfahren, Programm und Datenträger, | |
| DE102011103218A1 (de) | Systeme, Verfahren und Vorrichtung zum Virtualisieren von TPM- Zugriffen | |
| DE112012001389T5 (de) | Sichere Ausführung einer ungesicherten App auf einem Gerät | |
| EP2823429B1 (de) | Pc absicherung durch bios/(u) efi erweiterungen | |
| DE102018132970A1 (de) | Verfahren und Vorrichtung zur Isolation von sensiblem nichtvertrauenswürdigem Programmcode auf mobilen Endgeräten | |
| DE102009054128A1 (de) | Verfahren und Vorrichtung zum Zugriff auf Dateien eines sicheren Fileservers | |
| DE112022003368T5 (de) | Verschlüsselungsüberwachungsregister und -system | |
| DE112021004115B4 (de) | Sicherheitssystem für eine Segmentierung von Computerdatei-Metadaten | |
| DE102015208665B4 (de) | Verfahren und System zum Implementieren eines sicheren Sperrbildschirms | |
| DE19954358A1 (de) | Benutzerrollenzugriffssteuerung | |
| DE60211900T2 (de) | Verfahren und vorrichtung zur bewahrung von sicherer dateneingabe und datenausgabe |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| R012 | Request for examination validly filed | ||
| R016 | Response to examination communication | ||
| R082 | Change of representative |
Representative=s name: SPIES & BEHRNDT PATENTANWAELTE PARTG MBB, DE Representative=s name: LIFETECH IP SPIES & BEHRNDT PATENTANWAELTE PAR, DE Representative=s name: LIFETECH IP SPIES DANNER & PARTNER PATENTANWAE, DE |
|
| R082 | Change of representative |
Representative=s name: SPIES & BEHRNDT PATENTANWAELTE PARTG MBB, DE Representative=s name: LIFETECH IP SPIES & BEHRNDT PATENTANWAELTE PAR, DE Representative=s name: LIFETECH IP SPIES DANNER & PARTNER PATENTANWAE, DE |
|
| R082 | Change of representative |
Representative=s name: SPIES & BEHRNDT PATENTANWAELTE PARTG MBB, DE Representative=s name: LIFETECH IP SPIES & BEHRNDT PATENTANWAELTE PAR, DE |
|
| R082 | Change of representative |
Representative=s name: SPIES & BEHRNDT PATENTANWAELTE PARTG MBB, DE |
|
| R016 | Response to examination communication | ||
| R018 | Grant decision by examination section/examining division | ||
| R084 | Declaration of willingness to licence | ||
| R020 | Patent grant now final | ||
| R119 | Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal fee |