Location-Aware VM Multi-Factor Authentication With VM Blocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual machine (VM) environments face security threats such as VM attacks, denial of service attacks, Man-in-the-middle attacks, and authentication vulnerabilities like password spraying, credential stuffing, and brute force attacks, which current security measures fail to adequately address.
Innovation Solution
Implementing location-aware multi-factor authentication using a lightweight secure operating system (LSOS) with a prohibited users list, monitoring user activity, and employing a secure VM manager to block or terminate VMs based on user behavior, combined with a hypervisor and OEM secure VM manager.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in VM environments, then ease of operation is maintained, but security reliability is insufficient against modern threats
Solution Approach 1:
The system performs preliminary authentication actions by establishing location-based authorization mappings before actual VM access attempts. The authenticator pre-generates authorization data tuples containing location information and stores them in secure storage, so that when authentication is needed, the verification is already prepared and can be performed efficiently without adding operational burden.
Solution Approach 2:
The patent introduces an authenticator as an intermediary component between the VM user module and the hypervisor. This authenticator acts as a mediator that handles the complex multi-factor authentication process, including location verification and authorization mapping management, thereby shielding users from the complexity while enhancing security reliability.
2Reliability
If location-aware multi-factor authentication is implemented, then security reliability is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into distinct functional modules: the authenticator for generating and managing authorization mappings, the VM user module for initiating authentication requests, and the hypervisor for enforcing authentication decisions. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while maintaining high security reliability.
Solution Approach 2:
The system creates authorization mapping copies stored in both volatile memory (for quick access) and non-volatile storage (for persistence). These copies enable fast authentication verification without requiring complex real-time computations, thereby reducing device complexity while maintaining security reliability.
3Reliability
If authorization mappings are stored in multiple locations, then security reliability is enhanced, but loss of information risk increases
Solution Approach 1:
Different copies of the authorization mapping are stored with different quality characteristics: one copy is stored in volatile memory for fast access during authentication, while another copy is stored in non-volatile storage for persistence and backup. This local quality differentiation ensures that the loss of one copy does not result in complete information loss, thereby enhancing security reliability while managing information loss risk.
Data Source
AI summary
Disclosed systems and methods provide location-aware multi-factor authentication for VM users in combination with the prohibited users lists and disconnecting VMs based on user behavior or activity. Implementations may employ a hypervisor enabled by a lightweight, secure operating system (LSOS) as a foundational, enabling, and OS-agnostic technology for multiple uses cases. An LSOS authenticator module may generate IP location based authentication number for user authentication. An OEM Secure VM manager in Domain0 (Dom0) of a Xen cloud computing model may monitor user activity while Secure OEM Hypercall communication is employed for all communication from VM to LSOS. Embodiments may employ a LSOS VM prohibited users module and hypervisor action module to remove users and destroy VMs based on data received from Dom0, VM Manager and the user module in the VM.


