Trusted Cloud Security Architecture via Latency-Based Trust Ring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security implementations in virtual computerized environments, such as cloud computing, are inadequate to ensure trust and security during virtual machine migration, as they rely on a chain of trust that does not verify the trust status of guest OS at boot time and may move secured applications to untrusted hosts, leading to potential data loss and security breaches.
Innovation Solution
A system and method for creating a trusted cloud security architecture using a trust ring formed by primary and secondary agents with disparate IP addresses, exchanging data packets to determine a trust status based on latency metrics, and utilizing a processing engine to continuously validate the trust status of virtual machines across hosts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If virtual machine migration is supported transparently by the hypervisor, then ease of operation is improved, but security reliability deteriorates as the guest OS cannot detect host changes
Solution Approach 1:
The patent introduces a trust verification service as an intermediary component that operates between the hypervisor and guest OS. This service receives migration notifications from the hypervisor and performs trust verification by comparing the new host's security attributes against a baseline, thereby enabling security verification without breaking migration transparency.
Solution Approach 2:
The system implements a feedback mechanism where the trust verification service continuously monitors virtual machine migration events and provides security status information back to the guest OS. This feedback loop allows the guest OS to be informed of host changes while maintaining the transparency of the migration process.
2Device complexity
If the hypervisor trusts the boot process based on hardware register checks, then device complexity is reduced, but security reliability worsens as guest OS boot is not verified
Solution Approach 1:
The patent extends the trust verification from the traditional single-dimension hardware register check at hypervisor boot to a multi-dimensional approach that includes guest OS boot verification. This is achieved by measuring security attributes during guest OS boot and comparing them against a baseline, adding a new dimension of verification without significantly increasing overall system complexity.
3Ease of manufacture
If conventional security implementations are used in virtualized environments, then ease of manufacture is improved, but security reliability deteriorates due to inadequate protection against host manipulation
Solution Approach 1:
The patent creates a security baseline copy of the virtual machine's security attributes when it is in a known trusted state. This baseline copy is then used for comparison during trust verification operations, enabling detection of host manipulation without requiring complex real-time monitoring of all system operations.
Data Source
AI summary
The present invention provides a method for providing a computer implemented method and system for creating a trusted cloud security architecture having the following steps: a primary agent communicating with two or more secondary agents creating a trust ring or other shape of agent communications, the primary agent operating on a primary guest OS and two or more secondary agents operating on two or more secondary guest OSs; implementing a latency based topology for the trust ring having a network of links between disparate IP addresses, the disparate IP addresses corresponding with the primary agent and two or more secondary agents; the primary agent and two or more secondary agents exchanging data packets between the latency based topology within the trust ring; and outputting the exchanged data packets to a processing engine, the processing engine determining a trust status for the trust ring, the trust status based on the data packets between the latency based topology.


