Concealing Customer Data in Virtual Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual computing environments, customer sensitive data remains exposed due to the disclosure of application and object names, hindering adoption and increasing administrative overhead, as existing security measures are inadequate to ensure compliance and data protection.

Innovation Solution

A computing platform receives an object name from a user device, hashes or encrypts it, and transmits the concealed name to a virtual computing platform, allowing secure presentation and later decoding for display, thereby protecting sensitive information from exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If object names are disclosed in the virtual control plane, then virtual computing operations can be executed, but customer sensitive data is exposed to external third parties

Engineering Contradiction:
Improvevirtual computing operation executionVSAvoidsensitive data exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a naming service as an intermediary component between the virtual computing platform and the control plane. This naming service receives object name requests, retrieves them from the directory service, and returns concealed names to the virtual computing platform. The intermediary prevents direct exposure of sensitive object names in the control plane while enabling virtual computing operations to proceed with concealed identifiers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates concealed copies of object names that can be used in the virtual control plane without exposing the original sensitive names. The directory service stores both the original object names and concealed name mappings, allowing the virtual computing platform to operate with concealed name copies while the original sensitive names remain protected within the enterprise directory service.

Inventive Principle:
Principle #26Copying

2Reliability

If sensitive information is manually reviewed to ensure compliance, then data security can be maintained, but administrative overhead increases

Engineering Contradiction:
Improvedata security complianceVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements an automated self-service system where the naming service automatically retrieves object names from the directory service, conceals them according to defined policies, and provides them to the virtual computing platform without requiring manual administrative review. The system self-manages the concealment process, eliminating the need for administrators to manually review each object name for compliance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary concealment of object names before they are exposed to the virtual control plane. The naming service pre-processes object names by retrieving them from the directory service and applying concealment algorithms in advance, so that only concealed names are ever presented to the external virtual computing platform, eliminating the need for subsequent manual compliance reviews.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If object names are concealed using encryption or hashing, then sensitive data protection is improved, but system complexity increases

Engineering Contradiction:
Improvesensitive data protectionVSAvoidconcealment system complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal naming service that handles multiple functions within a single system component. The naming service performs directory service communication, name concealment through encryption or hashing, policy enforcement, and response generation all within one service. This multi-functional approach consolidates what would otherwise be separate complex systems into a single manageable service that protects sensitive data while maintaining operational simplicity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11057358B2Concealment of customer sensitive data in virtual computing arrangements
Publication Date: 2021.07.06 CITRIX SYSTEMS INC
  • US11057358B2 patent drawing
  • US11057358B2 patent drawing
  • US11057358B2 patent drawing

AI summary

Aspects described herein are directed to the concealment of customer sensitive data in virtual computing arrangements. A local computing platform may receive an object including a customer sensitive object name from a user computing device operating on a same internal domain as the local computing platform. The local computing platform may conceal the customer sensitive object name from a virtual computing platform operating on a domain external from the internal domain. The local computing platform may provide the concealed object name to the virtual computing platform for facilitating object enumeration requests from the user computing device during virtual computing sessions. During a virtual computing session between the user computing device and virtual computing platform, the local computing platform may receive the concealed object name from the user computing device and may perform one or more operations to reveal the object name to the user computing device.