Encryption Virtual Machine for Cloud VM Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based data storage solutions lack adequate protection and customer control over encryption and storage of virtual machine data, with vendors often managing encryption keys and not providing sufficient security measures, making data vulnerable to breaches and hackers.

Innovation Solution

Implementing an encryption virtual machine that manages encryption keys and performs boot disk encryption in a cloud environment, allowing customers to control their data encryption and storage, using a dedicated virtual machine to decrypt OS boot disks before booting and maintaining encryption keys separately from the storage volumes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If vendors manage encryption and storage of data in the cloud, then data storage service is provided, but customer control and awareness of security measures is insufficient

Engineering Contradiction:
Improvecustomer control over encryptionVSAvoidencryption management structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments encryption management by separating the encryption virtual machine (which customers control) from the storage infrastructure (managed by vendors). This allows customers to maintain control over encryption keys and processes while vendors handle the underlying storage infrastructure, resolving the contradiction between customer control and service provision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption virtual machine acts as an intermediary between customers and the cloud storage infrastructure. It enables customers to control encryption operations while the vendor manages the physical storage resources, thus providing both customer control and vendor-managed storage service simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are stored with storage volumes, then data can be accessed efficiently, but data is vulnerable to breaches and hackers

Engineering Contradiction:
Improvedata securityVSAvoiddata access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the encryption key storage from the data storage volumes. Encryption keys are stored in the encryption virtual machine while data is stored in separate storage volumes. This separation ensures that even if storage volumes are compromised, the encryption keys remain protected, maintaining security while allowing efficient data access through the encryption virtual machine.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption virtual machine serves as an intermediary that holds and manages encryption keys separately from storage volumes. This intermediary structure enables secure key management while maintaining efficient data access by processing encryption/decryption operations centrally rather than distributing keys across multiple storage locations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If vendors implement security infrastructure, then data protection is provided, but customers are not aware or made aware of security measures

Engineering Contradiction:
Improvedata protectionVSAvoidcustomer awareness of security
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The encryption virtual machine enables customers to directly manage and control their own encryption operations. Customers can view, manage, and control their encryption keys and security settings themselves, making them directly aware of the security measures in place while maintaining strong data protection through their own actions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of vendors implementing security infrastructure behind the scenes (which customers wouldn't know about), the system inverts the approach by giving customers direct control over encryption through the encryption virtual machine. This makes security measures visible and controllable by customers while maintaining vendor-provided infrastructure support.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11200327B1Protecting virtual machine data in cloud environments
Publication Date: 2021.12.14 COHESITY INC
  • US11200327B1 patent drawing
  • US11200327B1 patent drawing
  • US11200327B1 patent drawing

AI summary

Disclosed are methods and systems that include receiving updated operating system information, encrypting the updated operating system information, and updating a map file. The updated operating system information is received at an encryption virtual machine. The encrypting the updated operating system information results in the encrypted updated operating system information. The encrypting the updated operating system information is managed by the encryption virtual machine. The updated operating system information is encrypted in response to receipt of the updated operating system information. The updated operating system information is encrypted using an encryption key. In certain embodiments, the updating includes storing operating system metadata in the map file (where the operating system metadata is associated with the encrypted updated operating system information) and storing the encryption key in the map file (where the storing the encryption key in the map file associates the encryption key with the operating system metadata).