Client Hosted Virtualization Manager for Secure VM Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems lack secure and efficient methods for supporting task-oriented devices and full volume encryption in client-hosted virtualization environments, which are essential for secure data processing and storage, especially in environments vulnerable to malicious software and data breaches.

Innovation Solution

The implementation of a secure client-hosted virtualization (CHV) architecture with a CHV manager that resides in secure memory, supports I/O port assignment and security policies, provides pre-boot authentication, and enables full volume encryption, ensuring secure access to resources and storage across multiple virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional virtualization is used without secure isolation, then device compatibility and ease of operation are improved, but security and reliability deteriorate due to vulnerability to malicious software and data breaches

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the virtualization environment into distinct secure containers (virtual machines) with isolated resource access. Each virtual machine is confined to specific I/O ports and resources assigned by the CHV manager, preventing malicious software in one VM from accessing or affecting other VMs or host resources. This segmentation provides security without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CHV manager acts as an intermediary between virtual machines and physical resources. It sits between the VMs and the I/O ports, managing resource assignment and access control. This intermediary layer enforces security policies and prevents direct unauthorized access to hardware resources, maintaining security while preserving ease of operation for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If full volume encryption is implemented, then data security and integrity are improved, but processing speed and productivity deteriorate due to encryption overhead

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary encryption actions by encrypting data at the point of storage in encrypted containers. The CHV manager and secure container architecture establish encryption mechanisms in advance, so that data is protected before it becomes vulnerable to attacks. This preliminary protection maintains data integrity without requiring continuous decryption/encryption cycles during normal operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encrypted container architecture enables self-service encryption where data is automatically encrypted and protected within isolated containers managed by the CHV manager. The system handles encryption operations autonomously within the secure container environment, reducing the performance overhead that would otherwise impact general processing speed.

Inventive Principle:
Principle #25Self-service

3Productivity

If multiple virtual machines share common storage resources, then resource utilization and productivity are improved, but security and reliability deteriorate due to potential cross-contamination from malicious software

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments storage resources into isolated encrypted containers, with each virtual machine assigned to specific container(s). The CHV manager manages this segmentation and ensures that VMs can share physical storage infrastructure while maintaining logical isolation through encrypted container boundaries. This allows high resource utilization through sharing while preventing cross-contamination between VMs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The CHV manager serves as an intermediary that controls all access to shared storage resources. It manages the assignment of encrypted containers to virtual machines and enforces access policies that prevent unauthorized cross-access. This intermediary layer enables multiple VMs to safely share storage resources while maintaining security through controlled access and isolation mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8990584B2System and method for supporting task oriented devices in a client hosted virtualization system
Publication Date: 2015.03.24 DELL PROD LP
  • US8990584B2 patent drawing
  • US8990584B2 patent drawing
  • US8990584B2 patent drawing

AI summary

A client hosted virtualization system includes a task oriented device, a processor, and non-volatile memory with BIOS code and virtualization manager code. The virtualization manager initializes the client hosted virtualization system, authenticates a virtual machine image, launches the virtual machine based on the image, receives a transaction targeted to the task oriented device, prioritizes the transaction, sends the transaction to the task oriented device, receives a response from the task oriented device, and sends the response to the virtual machine. The client hosted virtualization system is configurable to execute the BIOS or the virtualization manager.