Hypervisor and Virtual Machine Protection via Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus programs are inadequate in protecting virtual machines (VMs) and hypervisors, often failing to detect malicious VMs before they cause damage, and existing backup and replication methods struggle to completely remove malicious software from virtual networks, leading to potential re-introduction of threats.

Innovation Solution

Implementing a centralized authority with authorization and revocation capabilities using metadata and digital signatures to verify the legitimacy of VMs and hypervisors, and providing decryption keys to securely run authorized VMs, thereby enhancing security frameworks for hypervisors and VMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard antivirus programs are used to protect VMs and hypervisors, then basic protection is provided, but malicious VMs can cause damage before being recognized and cannot be completely removed from virtual networks

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidtime for threat detection and removal
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements authorization verification before VM execution by checking digital signatures and metadata against a trusted authority. This preliminary action prevents malicious VMs from causing damage before detection, as the system validates authorization credentials during the VM startup process rather than relying on post-detection antivirus responses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a trusted authority as an intermediary that issues and manages authorization credentials (digital signatures and metadata) for VMs and hypervisors. This intermediary enables centralized control and verification, allowing the system to identify and revoke authorization for malicious entities, thereby improving both detection capability and removal effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If backup and replication practices are implemented, then VM recovery capability is improved, but malicious software can be replicated and almost impossible to completely remove from the user's portfolio of systems

Engineering Contradiction:
ImproveVM recovery capabilityVSAvoidspread of malicious software
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by verifying authorization credentials before allowing VM operations including backup and replication. The system checks digital signatures and metadata against the trusted authority's criteria, preventing malicious VMs from being replicated or backed up in the first place. This proactive approach stops the spread of malware before it can infect multiple systems through backup processes.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements a feedback mechanism where the trusted authority continuously validates authorization credentials and can revoke access when threats are detected. This feedback loop ensures that even if a malicious VM is introduced, the system can identify it through authorization verification and prevent its replication or backup, thereby stopping the propagation of malware across the virtual network portfolio.

Inventive Principle:
Principle #23Feedback

3Reliability

If authorization verification using metadata and digital signatures is implemented, then security protection is significantly improved, but system complexity increases due to centralized authority requirements

Engineering Contradiction:
Improveauthorization verification securityVSAvoidcentralized authority system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the trusted authority to perform multiple functions: issuing authorization credentials, validating digital signatures, managing metadata verification, and revoking authorization when threats are detected. This multi-functional approach consolidates security operations into a single system that handles all authorization-related tasks, reducing overall system complexity despite the enhanced security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10409978B2Hypervisor and virtual machine protection
Publication Date: 2019.09.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10409978B2 patent drawing
  • US10409978B2 patent drawing
  • US10409978B2 patent drawing

AI summary

A computer-implemented method, according to one embodiment, includes: determining, using a processor, whether a virtual machine is authorized to run using a data structure having metadata about properties of the virtual machine; determining, using the processor, whether a hypervisor is authorized to run the virtual machine using a digital signature of the data structure; and running the virtual machine on a computer system using the hypervisor in response to determining that the virtual machine is authorized to be run and that the hypervisor is authorized to run the virtual machine. Other systems, methods, and computer program products are described in additional embodiments.