Patents Assigned to BlueRock Security, Inc.
  • Patent number: 12505050
    Abstract: Physical memory isolation in a virtualized system is described. A notification is received from a guest in the virtualized system that an address space isolation component has been created in the guest. At the host of the virtualized system, a memory isolation domain that is bound with the address space isolation component is created. The memory isolation domain includes a set of second level address translation tables dedicated for that memory isolation domain. Guest-physical address (GPA) range(s) are received from the guest that are mapped into memory of the guest, and memory access permissions for the GPA range(s) are received and are being mapped for a process into the created memory isolation domain. The host determines whether the mapping for the process into the created memory isolation domain is permitted. If not permitted, the mapping is blocked thereby preventing access. If permitted, the mapping is granted thereby allowing access.
    Type: Grant
    Filed: April 26, 2024
    Date of Patent: December 23, 2025
    Assignee: BLUEROCK SECURITY, INC.
    Inventors: Sergej Proskurin, Sebastian Wolfgang Vogl, Jonas Pfoh
  • Patent number: 12443694
    Abstract: Process credential protection in a virtualized system is described. In-guest process credentials of a guest operating system are registered including binding the process credentials with the following values: a guest address of a first structure that includes subjective credentials, a guest address of a second structure that includes a context in which the process credentials reside, and data fields of the first structure that are not subject to change. A first tag is created from at least the information bound with the process credentials and stored. An integrity verification check is performed at a verification point that is triggered by a function or system call being called by the guest operating system, and includes creating a second tag from at least the information bound with the process credentials and determining if the first tag and second tag match. If they do not match, then the integrity of the in-guest process credentials has been compromised and remedial action is taken.
    Type: Grant
    Filed: August 30, 2023
    Date of Patent: October 14, 2025
    Assignee: BLUEROCK SECURITY, INC.
    Inventors: Sergej Proskurin, Sebastian Wolfgang Vogl, Robert Gawlik, Jonas Pfoh
  • Patent number: 12099864
    Abstract: A formally verified trusted computing base with active security and policy enforcement is described. The formally verified trusted computing base includes a formally verified microkernel and multiple formally verified hyper-processes including a virtual machine monitor (VMM), virtual machine introspection (VMI), policy enforcers including an active security policy enforcer (ASPE), and a virtual switch. The active security and policy enforcement continuously monitors for semantic behavior detection or policy violations and enforces the policies at the virtualization layer. Further, policies can be attached to the network layer to provide granular control of the communication of the computing device.
    Type: Grant
    Filed: September 12, 2022
    Date of Patent: September 24, 2024
    Assignee: BlueRock Security, Inc.
    Inventors: Osman Abdoul Ismael, Ashar Aziz, Jonas Pfoh