AU2005292341B2

Method and apparatus for isolating execution of software applications

Abstract

A method for moving an executing process from a source isolation scope to a target isolation scope includes the step of determining that the process is in a state suitable for moving. The association of the process changes from a source isolation scope to a target isolation scope. A rule loads in association with the target isolation scope.

Term

Term ended

Expired 23 September 2025, 1 year ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

27 claims: 8 independent, 19 dependent

  1. 1
    What is claimed is:1. A method for isolating access by application programs to native resources provided by an operating system, the method comprising instructing a suitably programmed computer to perform the steps of: (a) redirecting to an isolation environment comprising a user isolation layer and an application isolation layer a request for a native resource provided by an operating system and stored in a memory element provided by a computer, the request made by a process executing on behalf of a first user;(b) failing to locate in the memory element an instance of the requested resource associated with a user isolation scope provided by the user isolation layer on behalf of a first user;(c) redirecting the request to the application isolation layer;(d) locating in the memory element an instance of the requested native resource associated with an application isolation scope provided by the application isolation layer;and (e) responding to the request for the native resource using the instance of the requested native resource located in the memory element and associated with the application isolation scope.
  2. 8
    A method for isolating access by application programs to native resources provided by an operating system, the method comprising instructing a suitably programmed computer to perform the steps of;(a-1) intercepting by a file system filter driver a request for a file system native resource provided by an operating system and stored in a memory element provided by a computer, the request made by a process executing on behalf of a first user;(a-2) redirecting to an isolation environment comprising a user isolation layer and an application isolation layer the requestfor the file system native resource;(b) locating in the memory element an instance of the requested resource associated with a user isolation scope provided by the user isolation layer on behalf of a first user;and (c) responding to the request for the native resource using the instance of the requested native resource located in the memory element and associated with the user isolation scope.
  3. 9
    A method for isolating access by application programs to native resources provided by an operating system, the method comprising instructing a suitably programmed computer to perform the steps of:(a) redirecting to an isolation environment comprising a user isolation layer and an application isoiation layer a request for a file stored in a memory element provided by a computer, the request made by a process executing on behalf of a first user;-992005292341 18 Feb 2011 (b) locating in the memory element an instance of the requested resource associated with a user isolation scope provided by the user isolation layer on behalf of a first user;and (c) responding to the request for the native resource using the instance of the requested native resource located in the memory element and associated with the user isolation scope.
  4. 10
    A method for isolating access by application programs to native resources provided by an operating system, the method comprising instructing a suitably programmed computer to perform the steps of:(a) redirecting to an isolation environment comprising a user isolation layer and an application isolation layer a request for a registry database entry stored in a memory element provided by a computer, the request made by a process executing on behalf of a first user;(b) locating in the memory element an instance of the requested resource associated with a user isolation scope provided by the user isolation layer on behalf of a first user;and (c) responding to the request for the native resource using the instance of the requested native resource located in the memory element and associated with the user isolation scope.
  5. 11
    A method for isolating access by application programs to native resources provided by an operating system, the method comprising instructing a suitably programmed computer to perform the steps of:(a) redirecting to an isolation environment comprising a user isolation layer and an application isolation layer a request for a native resource provided by an operating system and stored in a memory element provided by a computer, the request made by a process executing on behalf of a first user;(b) locating in the memory element an instance of the requested resource associated with a user isolation scope provided by the user isolation layer on behalf of a first user;(c) responding to the request for the native resource using the instance of the requested native resource located in the memory element and associated with the user isolation scope;-1002005292341 18 Feb 2011 (d) redirecting to the isolation environment a request for the native resource made by a second process executing on behalf of a second user;(e) locating in the memory element an instance of the requested native resource associated with a second user isolation scope provided by the user isolation layer on behalf of the second user;and (f) responding to the request for the native resource using the instance of the native resource located in the memory element and associated with the second user isolation scope.
  6. 16
    A method for isolating access by application programs to native resources provided by an operating system, the method comprising instructing a suitably programmed computer to perform the steps of:(a) redirecting to an isolation environment comprising a user isolation layer and an application isolation layer a request for a native resource provided by an operating system and stored in a memory element provided by a computer, the request made by a process executing on behalf of a first user;(b) locating in the memory element an instance of the requested resource associated with a user isolation scope provided by the user isolation layer on behaif of a first user;-1012005292341 18 Feb 2011 (c) responding to the request for the native resource using the instance of the requested native resource located in the memory element and associated with the user isolation scope;(d) redirecting to the isolation environment a request for a native resource made by a second process executing on behalf of a first user;(e) locating in the memory element an instance of the requested native resource associated with the user isolation scope;and (f) responding to the request for the native resource using the instance of the resource associated with the user isolation scope.
  7. 20
    An apparatus for isolating access by application programs to native resources provided by an operating system, the apparatus comprising:computer-readable program means for associating an instance of a native resource provided by an operating system with a user isolation scope provided by an isolation environment comprising an application isolation layer and a user isolation layer, the user isolation scope corresponding to a user;computer-readable program means for associating an instance of a native resource with an application isolation scope provided by the isolation environment, the application isolation scope corresponding to an application;and computer-readable program means for intercepting a request for a native resource made by a process executing on behalf of the user and redirecting the request to the instance of the resource associated with the user isolation scope. -1022005292341 18 Feb 2011
  8. 27
    An apparatus for isolating access by application programs to native resources provided by an operating system, the apparatus comprising:computer-readable program means for: (i) associating an instance of a native resource provided by an operating system with a user isolation scope provided by an isolation environment comprising an application isolation layer and a user isolation layer, the user isolation scope corresponding to a user, and for (ii) associating an instance of the native resource with a second user isolation scope, the second user isolation scope corresponding to a second user;and computer-readable program means for intercepting a request for a native resource made by a process executing on behalf of the user and redirecting the request to the instance of the resource associated with the user isolation scope. -103WO 2006/039239 PCT/US2005/034449 1/24 Η. ο (Prior Art) WO 2006/039239 PCT/US2005/034449 2/24 (Prior Art) WO 2006/039239 PCT/US2005/034449 3/24 APP2 - - Q Appl. Isolation Scope Appl. Isolation Scope 224 222 102’ 104'—^106^ 102 104 106 >200 -108 I <160 150 152 File System Y” *^-172 Registry Window Names 107 Objects System Layer Fig. 2 A 100 WO 2006/039239 PCT/US2005/034449 4/24 ο ο CM Ο CO APP2 CM OO Fig. 2B WO 2006/039239 PCT/US2005/034449 5/24 Fig. 2C WO 2006/039239 PCT/US2005/034449 6/24 Fig. 3 A WO 2006/039239 PCT/US2005/034449 7/24 From 305 > Fig. 3B 308 To 306 WO 2006/039239 PCT/US2005/034449 8/24 From 305 Fig. 3C To3M WO 2006/039239 PCT/US2005/034449 9/24 From 305 To 306 Fig. 3D WO 2006/039239 PCT/US2005/034449 10/24 Fig. 4 WO 2006/039239 PCT/US2005/034449 11/24 Fig. 5 WO 2006/039239 PCT/US2005/034449 12/24 602 Intercept/receive request to enumerate a directory Map virtual directory to literal directory name according to rule 608 620 Return result 612 Enumerate literal directory and store results in working data store Let literal directory name equal virtual directory name Enumerate system scope and store results in working data store If virtual child specified by rule exists, merge child into working data store 2- . yes Flush working data store -►« Enumerate application scope and merge results into working data store for each such rule ir-630 -► Determine set of rules applicable to immediate children X. t Enumerate user scope and merge results into working data store ^618 Flush working data store WO 2006/039239 PCT/US2005/034449 13/24 Fig. 7 WO 2006/039239 PCT/US2005/034449 14/24 Fig. 7A WO 2006/039239 PCT/US2005/034449 15/24 Key not found error Fz'g. 8 WO 2006/039239 PCT/US2005/034449 16/24 WO 2006/039239 PCT/US2005/034449 17/24 1044 WO 2006/039239 PCT/US2005/034449 18/24 WO 2006/039239 PCT/US2005/034449 19/24 Fzg. 12 WO 2006/039239 PCT/US2005/034449 20/24 Fig. 13 WO 2006/039239 PCT/US2005/034449 21/24 r From 1324 To 1328 Fig. 13A WO 2006/039239 PCT/US2005/034449 22/24 WO 2006/039239 PCT/US2005/034449 23/24 Fig. 15 WO 2006/039239 PCT/US2005/034449 24/24 Fig. 16