Client Hosted Virtualization Manager Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems lack secure and efficient methods for virtualization, particularly in client-hosted environments, where secure updates, I/O port assignment, and full volume encryption are not adequately addressed, leading to vulnerabilities in data security and management.

Innovation Solution

The implementation of a secure client-hosted virtualization (CHV) architecture with a CHV manager that resides in secure memory, supports I/O port assignment and security policies, provides pre-boot authentication, and enables full volume encryption, ensuring secure and isolated operation of virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional virtualization methods are used in client-hosted environments, then system complexity is reduced and ease of operation is maintained, but data security and system integrity are compromised due to lack of secure updates, I/O port vulnerabilities, and insufficient encryption capabilities

Engineering Contradiction:
Improvedata securityVSAvoidvirtualization architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into distinct security domains including a secure client-hosted virtualization manager, isolated virtual machine environments, and separated I/O port assignment mechanisms. Each segment operates with defined security boundaries, allowing enhanced security measures in critical areas without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A CHV manager acts as an intermediary layer between the host system and virtual machines, providing secure update distribution, authenticated I/O port assignment, and coordinated encryption key management. This intermediary enables secure operations without exposing the complexity of underlying security mechanisms to end users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure memory residency and full volume encryption are implemented, then data protection and system integrity are improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improvesystem integrityVSAvoidprocessing energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Encryption keys and security credentials are pre-loaded into secure memory during system initialization or secure boot process. Volume encryption is established in advance before data operations begin. This preliminary setup eliminates the need for repeated key generation and cryptographic initialization during normal operations, reducing ongoing energy consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Full volume encryption is applied selectively to specific storage volumes and data partitions that require protection, rather than encrypting all data uniformly. The CHV manager implements encryption only for sensitive virtual machine data and configuration information, allowing unencrypted operations for non-sensitive data, thereby optimizing energy usage based on local data sensitivity requirements.

Inventive Principle:
Principle #3Local quality

3Reliability

If I/O port assignment and security policies are enforced, then security control and data protection are enhanced, but system performance and operational speed are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidI/O operation speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

I/O port assignment and security policy enforcement are implemented dynamically rather than statically. The CHV manager adjusts security check intensity and I/O access controls based on real-time threat assessments, data sensitivity levels, and operational contexts. This dynamic approach allows high-speed I/O operations for trusted, low-risk transactions while maintaining rigorous security controls for sensitive operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Security verification and I/O port validation are applied partially based on risk assessment. For routine I/O operations from authenticated virtual machines, the system uses simplified validation paths that maintain security while minimizing overhead. Enhanced security checks are applied only when anomalies are detected or when accessing particularly sensitive resources, balancing security control with operational performance.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8751781B2System and method for supporting secure subsystems in a client hosted virtualization system
Publication Date: 2014.06.10 DELL PROD LP
  • US8751781B2 patent drawing
  • US8751781B2 patent drawing
  • US8751781B2 patent drawing

AI summary

An client hosted virtualization system includes an authentication device, a processor and non-volatile memory with BIOS code and virtualization manager code. The virtualization manager initializes the client hosted virtualization system authenticates a virtual machine image, launches a portion of the virtual machine that initiates an authentication session with the authentication device, receives an authentication object from the authentication device, sends the authentication object to the portion of the virtual machine, and launches another portion of the virtual machine. The client hosted virtualization system is configurable to execute the BIOS or the virtualization manager.