US2018046809A1PendingUtilityA1
Secure host operating system running a virtual guest operating system
Est. expiryJun 11, 2032(~5.8 yrs left)· nominal 20-yr term from priority
G06F 2009/4557G06F 9/45558G06F 21/57
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Among other things, a guest operating system is refreshed from a master image of the guest operating system repeatedly in connection with use of one or more electronic devices on which the guest operating system is hosted. A guest operating system is executed on a virtual machine, and, from time to time, while the virtual machine is running, the guest operating system is reloaded from a master image of the guest operating system.
Claims
exact text as granted — not AI-modified1 . A method comprising
refreshing a guest operating system from a master image of the guest operating system repeatedly in connection with use of one or more electronic devices on which the guest operating system is hosted.
2 . The method of claim 1 in which a portion of the guest operating system is refreshed from the master image and a portion of the guest operating system is not refreshed from the master image.
3 . The method of claim 1 in which the refreshing occurs in response to an event associated with use of the one or more electronic devices.
4 . The method of claim 1 in which the refreshing occurs at prearranged times.
5 . The method of claim 1 in which the refreshing occurs at regular intervals.
6 . The method of claim 1 in which the refreshing occurs in response to a characteristic of an operation of the guest operating system.
7 . The method of claim 6 in which the characteristic comprises incorrect operation of the guest operating system.
8 . The method of claim 1 in which the refreshing occurs upon failure of the guest operating system.
9 . The method of claim 1 in which the refreshing occurs upon a moving of the master image of the guest operating system from one to another of the electronic devices.
10 . The method of claim 1 in which the guest operating system is hosted on a virtual machine exposed by a host operating system on at least one of the electronic devices.
11 . The method of claim 1 in which the guest operating system is refreshed from a master image on a portable storage device.
12 . The method of claim 1 comprising refreshing a host operating system running on one or more of the electronic devices.
13 . The method of claim 1 in which the electronic devices comprise one or more of a desktop computer, a laptop computer, a mobile computing device, a mobile phone, or a tablet computer.
14 . The method of claim 1 in which the master image is unchanged from refreshing to refreshing.
15 . A method comprising:
executing a guest operating system on a virtual machine; and from time to time, while the virtual machine is running, reloading the guest operating system from a master image of the guest operating system.
16 . The method of claim 15 in which the virtual machine is hosted by a host operating system.
17 . The method of claim 16 , in which at least some services available directly to the host operating system are not directly accessible to the guest operating system.
18 . The method of claim 16 , in which at least some services available directly to the host operating system are not directly accessible to the guest operating system, and at least some services available directly to the host operating system are directly accessible to the guest operating system.
19 . The method of claim 16 , comprising the host operating system reducing access by the guest operating system to services of an electronic device on which the host operating system is running, based on a condition of the electronic device.
20 . The method of claim 19 , in which services of the electronic device comprise a network interface.
21 . The method of claim 16 , comprising the host operating system hiding from a user, user interface elements that would otherwise be exposed to the user by the host operating system.
22 . The method of claim 15 , in which reloading the guest operating system from a master image comprises installing a user application on the guest operating system from a secondary master image.
23 . The method of claim 22 comprising detecting a condition of the user application and, based on the condition, deleting the secondary master image.
24 . The method of claim 23 in which the condition comprises a failure condition.
25 . The method of claim 23 in which the condition comprises a security condition.
26 . The method of claim 15 , comprising detecting a condition of the guest operating system and, based on the condition, refreshing the guest operating system.
27 . The method of claim 26 , in which the condition comprises a failure condition.
28 . The method of claim 26 , in which the condition comprises a security condition.
29 . The method of claim 15 , comprising disabling a user interface of the virtual machine.
30 . The method of claim 15 , in which the guest operating system is reloaded into random access memory.
31 . The method of claim 15 , in which the master image is stored in firmware.
32 . The method of claim 15 comprising executing the guest operating system after reloading it from the master image.
33 . The method of claim 15 comprising terminating the guest operating system before reloading it from the master image.
34 . The method of claim 15 in which from time to time comprises on a regular schedule.
35 . A computer system comprising:
one or more computer devices including a first computer device, wherein the first computer device comprises a first network communication device; a host operating system executing on the first computer device, wherein the host operating system is configured to directly operate the network communication device; a virtualized network communication device, whereby use of the virtualized network communication device results in direct operation of the first network communication device by the host operating system; a guest operating system, wherein the guest operating system is configured to use the virtualized network communication device for network communication activities; a first nonvolatile data storage device storing a master image of the guest operating system; and a second nonvolatile data storage device which stores user information generated by the guest operating system; wherein, in response to an instruction generated by the host operating system, the computer system is configured to automatically refresh the guest operating system from the master image stored in the first nonvolatile data storage device and the user information stored in the second nonvolatile data storage device.
36 . The system of claim 35 , further comprising:
a virtual machine which includes the virtualized network communication device and the virtualized data storage device, wherein the guest operating system executes within the virtual machine.
37 . The system of claim 36 , wherein
the virtual machine executes within the host operating system.
38 . The system of claim 35 , further comprising:
a first display device configured to display images; a first input device for manual or verbal instructions from a user; a virtualized display device, whereby use of the virtualized display device results in operation of the first display device by the host operating system; and a virtualized input device, whereby input received by the host operating system via the first input device is provided to an operating system using the virtualized input device; wherein the guest operating system is configured to use the virtualized display device to display a user interface and is configured to use the virtualized input device to provide input for operating the user interface.
39 . The system of claim 38 , wherein
the host operating system does not provide a user interface for use via the first display device.
40 . The system of claim 35 , wherein
the first computer device further comprises a first data storage device; the host operating system is configured to directly operate the first data storage unit; the system further comprises a virtualized data storage device, whereby use of the virtualized data storage device results in direct operation of the first data storage device by the host operating system; and the guest operating system is configured to use the virtualized data storage device for data storage activities.
41 . The system of claim 35 , further comprising:
a third nonvolatile data storage device which stores data for installation of a first application program on the guest operating system; wherein, in response to the instruction from the host operating system, the computer system is configured to install the first application program on the guest operating system from the third nonvolatile data storage device.
42 . The system of claim 41 , further comprising:
a fourth nonvolatile data storage device which stores data for installation of a second application program on the guest operating system; wherein the host operating system is configured to identify and record a problem associated with the second application; and wherein, in response to the instruction from the host operating system, the computer system is configured to install the second application program on the guest operating system from the fourth nonvolatile data storage device, unless the host operating system has recorded a problem associated with the second application.
43 . The system of claim 42 , wherein
the host operating system is configured to generate the instruction in response to identifying a problem associated with the second application.
44 . The system of claim 35 , wherein
the system is configured to monitor operation of the guest operating system; and the host operating system is configured to generate the instruction in response to the monitoring of the guest operating system.
45 . The system of claim 44 , wherein
the host operating system is configured to generate the instruction in response to a detected misoperation or failure of the guest operating system.
46 . The system of claim 44 , wherein
the host operating system is configured to generate the instruction in response to a detection of unauthorized access of the guest operating system.
47 . The system of claim 35 , wherein
the host operating system in configured to periodically generate the instruction.
48 . The system of claim 35 , wherein
the master image is unchanged from refreshing to refreshing of the guest operating system.
49 . The system of claim 35 , wherein
the host operating system is configured to required encrypted communication via the first network communication device in response to use of the virtualized network communication device by the guest operating system.
50 . The system of claim 35 , wherein
the host operating system is configured to perform monitoring and control of network communications requested by the guest operating system.
51 . The system of claim 35 , wherein
the host operating system is configured to perform automatic maintenance of device drivers without requiring user interaction and without requiring termination of the guest operating system.
52 . The system of claim 37 , wherein
the host operating includes a kernel abstraction layer which isolates the virtual machine from the first computer device.
53 . A method of configuring one or more computer devices including a first computer device, the first computer device comprising a first network communication device, the method comprising:
executing a host operating system on the first computer device, wherein the host operating system is configured to directly operate the network communication device; executing a guest operating system on one of the one or more computer devices, wherein the guest operating system is configured to use a virtualized network communication device for network communication activities, whereby use of the virtualized network communication device results in direct operation of the first network communication device by the host operating system; and refreshing the guest operating system, in response to an instruction generated by the host operating system, from a master image of the guest operating system stored in a first nonvolatile data storage device and user information stored in a second nonvolatile data storage device.
54 . The method of claim 53 , further comprising:
executing a virtual machine which provides the virtualized network communication device, wherein the executing of the guest operating system is within the virtual machine.
55 . The method of claim 54 , wherein
the executing of the virtual machine is within the host operating system.
56 . The method of claim 53 , further comprising:
providing a kernel abstraction layer in the host operating system to isolate the virtual machine from the first computer device.
57 . The method of claim 53 , wherein
the host operating stores one or more passwords for use with user applications executing on the guest operating system.Join the waitlist — get patent alerts
Track US2018046809A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.