Encryption Virtual Machine for Cloud VM Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based data storage solutions lack adequate protection and customer control over encryption and storage of virtual machine data, with vendors often managing encryption keys and not providing sufficient security measures, making data vulnerable to breaches and hackers.
Innovation Solution
Implementing an encryption virtual machine that manages encryption keys and performs boot disk encryption in a cloud environment, allowing customers to control their data encryption and storage, using a dedicated virtual machine to decrypt OS boot disks before booting and maintaining encryption keys separately from the storage volumes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If vendors manage encryption and storage of data in the cloud, then data storage service is provided, but customer control and awareness of security measures is insufficient
Solution Approach 1:
The system segments encryption management by separating the encryption virtual machine (which customers control) from the storage infrastructure (managed by vendors). This allows customers to maintain control over encryption keys and processes while vendors handle the underlying storage infrastructure, resolving the contradiction between customer control and service provision.
Solution Approach 2:
The encryption virtual machine acts as an intermediary between customers and the cloud storage infrastructure. It enables customers to control encryption operations while the vendor manages the physical storage resources, thus providing both customer control and vendor-managed storage service simultaneously.
2Reliability
If encryption keys are stored with storage volumes, then data can be accessed efficiently, but data is vulnerable to breaches and hackers
Solution Approach 1:
The system segments the encryption key storage from the data storage volumes. Encryption keys are stored in the encryption virtual machine while data is stored in separate storage volumes. This separation ensures that even if storage volumes are compromised, the encryption keys remain protected, maintaining security while allowing efficient data access through the encryption virtual machine.
Solution Approach 2:
The encryption virtual machine serves as an intermediary that holds and manages encryption keys separately from storage volumes. This intermediary structure enables secure key management while maintaining efficient data access by processing encryption/decryption operations centrally rather than distributing keys across multiple storage locations.
3Reliability
If vendors implement security infrastructure, then data protection is provided, but customers are not aware or made aware of security measures
Solution Approach 1:
The encryption virtual machine enables customers to directly manage and control their own encryption operations. Customers can view, manage, and control their encryption keys and security settings themselves, making them directly aware of the security measures in place while maintaining strong data protection through their own actions.
Solution Approach 2:
Instead of vendors implementing security infrastructure behind the scenes (which customers wouldn't know about), the system inverts the approach by giving customers direct control over encryption through the encryption virtual machine. This makes security measures visible and controllable by customers while maintaining vendor-provided infrastructure support.
Data Source
AI summary
Disclosed are methods and systems that include receiving updated operating system information, encrypting the updated operating system information, and updating a map file. The updated operating system information is received at an encryption virtual machine. The encrypting the updated operating system information results in the encrypted updated operating system information. The encrypting the updated operating system information is managed by the encryption virtual machine. The updated operating system information is encrypted in response to receipt of the updated operating system information. The updated operating system information is encrypted using an encryption key. In certain embodiments, the updating includes storing operating system metadata in the map file (where the operating system metadata is associated with the encrypted updated operating system information) and storing the encryption key in the map file (where the storing the encryption key in the map file associates the encryption key with the operating system metadata).


