Invention Application
US20140201734A1 COMPARTMENTALIZATION OF THE USER NETWORK INTERFACE TO A DEVICE 有权
用户网络接口对设备的分层化

COMPARTMENTALIZATION OF THE USER NETWORK INTERFACE TO A DEVICE
Abstract:
A device has physical network interface port through which a user can monitor and configure the device. A backend process and a virtual machine (VM) execute on a host operating system (OS). A front end user interface process executes on the VM, and is therefore compartmentalized in the VM. There is no front end user interface executing on the host OS outside the VM. The only management access channel into the device is via a first communication path through the physical network interface port, to the VM, up the VM's stack, and to the front end process. If the backend process is to be instructed to take an action, then the front end process forwards an application layer instruction to the backend process via a second communication path. The instruction passes down the VM stack, across a virtual secure network link, up the host stack, and to the backend process.
Public/Granted literature
Information query
Patent Agency Ranking
0/0