发明名称 Method for secure access to multiple secure networks
摘要 Disclosed is a method for providing secure access to multiple secure networks from a single workstation. The architecture can use multiple layers of protection to isolate applications running at different security levels. The first means of isolation is a virtual machine monitor that isolates multiple operating systems running within separate virtual machines on the host operating system. The second layer is the use of multiple user security contexts on the host operating system to isolate each virtual machine. The third level of protection is a highly secured and restricted host operating system where all unnecessary services are removed and user actions are restricted to just the virtual machine monitor using software restriction policies. Finally, the operating system and virtual machine monitor can be run from read-only media to prevent any changes by an attacker from persisting.
申请公布号 US7506170(B2) 申请公布日期 2009.03.17
申请号 US20040857431 申请日期 2004.05.28
申请人 MICROSOFT CORPORATION 发明人 FINNEGAN SEAN ROBERT
分类号 G06F9/00;G06F11/30;G06F12/14;G06F21/00;H04L9/00;H04L9/32;H04L29/06 主分类号 G06F9/00
代理机构 代理人
主权项
地址