Hypervisor and Virtual Machine Protection via Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current antivirus programs are inadequate in protecting virtual machines (VMs) and hypervisors, often failing to detect malicious VMs before they cause damage, and existing backup and replication methods struggle to completely remove malicious software from virtual networks, leading to potential re-introduction of threats.
Innovation Solution
Implementing a centralized authority with authorization and revocation capabilities using metadata and digital signatures to verify the legitimacy of VMs and hypervisors, and providing decryption keys to securely run authorized VMs, thereby enhancing security frameworks for hypervisors and VMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard antivirus programs are used to protect VMs and hypervisors, then basic protection is provided, but malicious VMs can cause damage before being recognized and cannot be completely removed from virtual networks
Solution Approach 1:
The patent implements authorization verification before VM execution by checking digital signatures and metadata against a trusted authority. This preliminary action prevents malicious VMs from causing damage before detection, as the system validates authorization credentials during the VM startup process rather than relying on post-detection antivirus responses.
Solution Approach 2:
The patent introduces a trusted authority as an intermediary that issues and manages authorization credentials (digital signatures and metadata) for VMs and hypervisors. This intermediary enables centralized control and verification, allowing the system to identify and revoke authorization for malicious entities, thereby improving both detection capability and removal effectiveness.
2Reliability
If backup and replication practices are implemented, then VM recovery capability is improved, but malicious software can be replicated and almost impossible to completely remove from the user's portfolio of systems
Solution Approach 1:
The patent applies preliminary anti-action by verifying authorization credentials before allowing VM operations including backup and replication. The system checks digital signatures and metadata against the trusted authority's criteria, preventing malicious VMs from being replicated or backed up in the first place. This proactive approach stops the spread of malware before it can infect multiple systems through backup processes.
Solution Approach 2:
The patent implements a feedback mechanism where the trusted authority continuously validates authorization credentials and can revoke access when threats are detected. This feedback loop ensures that even if a malicious VM is introduced, the system can identify it through authorization verification and prevent its replication or backup, thereby stopping the propagation of malware across the virtual network portfolio.
3Reliability
If authorization verification using metadata and digital signatures is implemented, then security protection is significantly improved, but system complexity increases due to centralized authority requirements
Solution Approach 1:
The patent applies universality by designing the trusted authority to perform multiple functions: issuing authorization credentials, validating digital signatures, managing metadata verification, and revoking authorization when threats are detected. This multi-functional approach consolidates security operations into a single system that handles all authorization-related tasks, reducing overall system complexity despite the enhanced security capabilities.
Data Source
AI summary
A computer-implemented method, according to one embodiment, includes: determining, using a processor, whether a virtual machine is authorized to run using a data structure having metadata about properties of the virtual machine; determining, using the processor, whether a hypervisor is authorized to run the virtual machine using a digital signature of the data structure; and running the virtual machine on a computer system using the hypervisor in response to determining that the virtual machine is authorized to be run and that the hypervisor is authorized to run the virtual machine. Other systems, methods, and computer program products are described in additional embodiments.


