Content Filter Server for Secure Virtualized File Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure virtualized environments for online banking prevent direct interaction between malware-infected client machines and banking sites, limiting users' ability to securely send or download files, as doing so could compromise system security due to potential malware infection.

Innovation Solution

A method involving a content filter server that pulls uploaded files from a drop server, filters them for security threats, and sends the filtered files to a remote application server, ensuring secure communication and preventing malware transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users directly send files to the secure virtualized environment, then file exchange capability is improved, but system security deteriorates due to potential malware infection

Engineering Contradiction:
Improvefile exchange capabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a content filter server as an intermediary component between the unsecure network and the secure virtualized environment. This mediator receives files from users, filters them for malware using antivirus software, and only transfers cleaned files to the virtual machine. This resolves the contradiction by enabling file exchange while maintaining security through the intermediary filtering mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users access banking sites through a secure virtualized environment, then protection from malware is improved, but ability to exchange files with personal machines deteriorates

Engineering Contradiction:
Improveprotection from malwareVSAvoidability to exchange files
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The content filter server acts as a mediator that enables file exchange between the isolated virtual environment and external networks. Users can upload files through the filter server, which cleans them before making them available to the virtual machine, and can download files from the virtual machine through the same intermediary. This maintains ease of operation while preserving malware protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the file transfer process into distinct stages: upload to content filter server, malware filtering, and transfer to virtual machine. This segmentation allows the virtual machine to remain isolated and secure while still enabling file exchange through the segmented, controlled interface provided by the content filter server.

Inventive Principle:
Principle #1Segmentation

3Speed

If the system allows direct file uploads from client machines, then file transfer speed is improved, but malware transmission risk increases

Engineering Contradiction:
Improvefile transfer speedVSAvoidmalware transmission risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary malware filtering at the content filter server before files reach the virtual machine environment. By conducting the security check in advance (preliminary action), the system maintains efficient file transfer speeds while eliminating malware risks beforehand, preventing harmful factors from entering the secure environment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8782174B1Uploading and downloading unsecured files via a virtual machine environment
Publication Date: 2014.07.15 EMC IP HLDG CO LLC
  • US8782174B1 patent drawing
  • US8782174B1 patent drawing
  • US8782174B1 patent drawing

AI summary

Methods, computer program products, and apparatuses are provided for securely exchanging a data file between a client machine and a remote application server (e.g., a banking application operating on a banking server) in the context of a user communicating with the remote application server through a secure virtualized environment running on a virtualization server.