TECHNIQUES FOR BINDING USER IDENTIFIES TO APPROPRIATE VIRTUAL MACHINES WITH SINGLE SIGN-ON

    公开(公告)号:US20200019430A1

    公开(公告)日:2020-01-16

    申请号:US16580623

    申请日:2019-09-24

    申请人: Hysolate Ltd.

    IPC分类号: G06F9/455 G06F21/40 G06F21/41

    摘要: A method for binding a user account operable on an air-gapped computer to an appropriate virtual machine (VM), comprising: monitoring a plurality of VMs to determine an associated user account for each of the plurality of VMs, wherein the plurality of VMs are executed over the air-gapped computer, and wherein each of the plurality of VMs is a distinct security zone in the air-gapped computer; determining a current VM from the plurality of VMs to bind an associated user account thereto; and displaying user specific indications on desktop items associated with each user account.

    Method for rendering virtual desktops on an air-gapped endpoint

    公开(公告)号:US20200279042A1

    公开(公告)日:2020-09-03

    申请号:US16879380

    申请日:2020-05-20

    申请人: Hysolate Ltd.

    摘要: A method for rendering virtual desktops on an air-gapped endpoint is provided. The method includes rendering a first window presenting a first virtual desktop of a first security zone; rendering a second window presenting a second virtual desktop display of a second security zone, wherein the first security zone and the second security zone are of a plurality of security zones instantiated on the air-gapped endpoint; and controlling, by a hypervisor, display of the first window and the second window on a desktop of the air-gapped endpoint, wherein any application in the first security zone cannot access any application in the second security zone when displayed on the same desktop.

    UNIFIED FILE SYSTEM ON AIR-GAPPED ENDPOINTS
    5.
    发明申请

    公开(公告)号:US20190303354A1

    公开(公告)日:2019-10-03

    申请号:US16443057

    申请日:2019-06-17

    申请人: Hysolate Ltd.

    摘要: A system and method for providing a unified file system on an air-gapped endpoint are provided. The method included monitoring a plurality of security zones, instantiated on the air-gapped endpoint, to intercept at least one file system operation to access files on a first security zone; determining if the detected file system operation triggers a display of the file system dialog window effecting a second security zone; and when the file system dialog window effecting the second security zone, blocking the display of the file system dialog window in the first security zone; and displaying the file system dialog window in the second security zone.

    MANAGED ISOLATED WORKSPACE ON A USER DEVICE

    公开(公告)号:US20220004623A1

    公开(公告)日:2022-01-06

    申请号:US17368355

    申请日:2021-07-06

    申请人: Hysolate LTD.

    摘要: A method and system for method for providing a managed and isolated workspace on a user device are provided. The method creating a secured workspace in the user device, wherein the secured workspace is separated from a host operating system and includes a guest operating system; monitoring activity performed in the secured workspace and host operating system; determining, based on a security policy, if the monitored activity is risky; and causing execution of any determined risky activity in the secured workspace, thereby defending the host operating system from the determined risky activity, wherein the host operating system executes sensitive applications to an organization.

    UNIFIED FILE SYSTEM ON AIR-GAPPED ENDPOINTS

    公开(公告)号:US20210109903A1

    公开(公告)日:2021-04-15

    申请号:US17108521

    申请日:2020-12-01

    申请人: Hysolate Ltd.

    摘要: A system and method for providing a unified file system on an air-gapped endpoint are provided. The method includes monitoring the first and second security zones instantiated on the virtually air-gapped endpoint to intercept at least one file system operation to access files on the first security zone; determining if the detected file system operation triggers a display of a file system dialog window of the second security zone; and when the file system dialog window of the second security zone is determined to be triggered, preventing the display of a file system dialog window in the first security zone; and displaying the file system dialog window of the second security zone in the second security zone.