Hypervisor Data Loss Prevention for Encrypted Traffic Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data loss prevention mechanisms in multi-tenant environments are inflexible and unable to effectively manage access and usage of data with varying security levels, particularly failing to inspect encrypted data and lacking the necessary control mechanisms for virtualized resources with multiple security permissions.
Innovation Solution
Implementing a data loss prevention service within the hypervisor or dom0 of a virtualized system, utilizing SSL-enabled services to inspect and block encrypted traffic, and enforcing secure storage policies to ensure that sensitive data is only accessible from authorized computing resources, with flexible data flow controls and multiple security levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data encryption and secure communication channels are used to prevent unauthorized access, then data security is improved, but flexibility for users with multiple security permissions to concurrently access data with different security levels deteriorates
Solution Approach 1:
The patent segments the multi-tenant environment into multiple virtual machines with distinct security contexts. Each virtual machine is assigned specific security permissions and can access data at appropriate security levels independently. This segmentation allows concurrent access to data with different security levels while maintaining security boundaries, resolving the contradiction between security and flexibility.
Solution Approach 2:
The patent implements local quality by assigning different security contexts to different virtual machines and data portions. Each virtual machine operates with its own security permissions and context, allowing tailored access control. This enables users with multiple security permissions to access different security levels concurrently while maintaining appropriate security controls for each access pattern.
2Reliability
If conventional data loss prevention mechanisms are used in multi-tenant environments, then some data protection is achieved, but the ability to inspect and control encrypted data and virtualized resources with multiple security permissions deteriorates
Solution Approach 1:
The patent implements preliminary action by establishing security contexts and permissions before data access occurs. Virtual machines are pre-configured with specific security contexts that define what data they can access and how. This preliminary setup enables the system to automatically enforce security policies and inspect data flows without needing to decrypt or deeply analyze the data itself, maintaining protection while improving detectability.
Solution Approach 2:
The patent introduces an intermediary security context layer between the virtual machines and the data. This intermediary manages security permissions and controls data access without requiring direct inspection of encrypted data. The security context acts as a mediator that enforces security policies while allowing encrypted data to remain protected, resolving the contradiction between protection and inspectability.
3Productivity
If multiple users are provisioned on the same physical device or have access to the same database in a multi-tenant environment, then resource utilization is improved, but control over what a party does with secure information once accessed deteriorates
Solution Approach 1:
The patent segments the multi-tenant environment into isolated virtual machines, each with its own security context and permissions. This segmentation allows multiple users to share physical resources while maintaining independent control over their respective data access and usage. Each virtual machine's security context ensures that users can only perform operations appropriate to their authorized data, resolving the contradiction between resource utilization and usage control.
Solution Approach 2:
The patent applies local quality by assigning specific security contexts to each virtual machine and user combination. This allows tailored control over what each party can do with secure information they access. The security context associated with each virtual machine enforces appropriate usage restrictions locally, enabling high resource utilization while maintaining granular control over data usage for each user.
Data Source
AI summary
The usage of data in a multi-tenant environment can be controlled by utilizing functionality at the hypervisor level of various resources in the environment. Data can be associated with various tags, security levels, and/or compartments. The ability of resources or entities to access the data can depend at least in part upon whether the resources or entities are also associated with the tags, security levels, and/or compartments. Limitations on the usage of the data can be controlled by one or more policies associated with the tags, security levels, and/or compartments. A control service can monitor traffic to enforce the appropriate rules or policies, and in some cases can prevent encrypted traffic from passing beyond a specified egress point unless the encryption was performed by a trusted resource with the appropriate permissions.


