Location-Aware VM Multi-Factor Authentication With VM Blocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual machine (VM) environments face security threats such as VM attacks, denial of service attacks, Man-in-the-middle attacks, and authentication vulnerabilities like password spraying, credential stuffing, and brute force attacks, which current security measures fail to adequately address.

Innovation Solution

Implementing location-aware multi-factor authentication using a lightweight secure operating system (LSOS) with a prohibited users list, monitoring user activity, and employing a secure VM manager to block or terminate VMs based on user behavior, combined with a hypervisor and OEM secure VM manager.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in VM environments, then ease of operation is maintained, but security reliability is insufficient against modern threats

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication actions by establishing location-based authorization mappings before actual VM access attempts. The authenticator pre-generates authorization data tuples containing location information and stores them in secure storage, so that when authentication is needed, the verification is already prepared and can be performed efficiently without adding operational burden.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authenticator as an intermediary component between the VM user module and the hypervisor. This authenticator acts as a mediator that handles the complex multi-factor authentication process, including location verification and authorization mapping management, thereby shielding users from the complexity while enhancing security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If location-aware multi-factor authentication is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into distinct functional modules: the authenticator for generating and managing authorization mappings, the VM user module for initiating authentication requests, and the hypervisor for enforcing authentication decisions. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while maintaining high security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates authorization mapping copies stored in both volatile memory (for quick access) and non-volatile storage (for persistence). These copies enable fast authentication verification without requiring complex real-time computations, thereby reducing device complexity while maintaining security reliability.

Inventive Principle:
Principle #26Copying

3Reliability

If authorization mappings are stored in multiple locations, then security reliability is enhanced, but loss of information risk increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidloss of information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Different copies of the authorization mapping are stored with different quality characteristics: one copy is stored in volatile memory for fast access during authentication, while another copy is stored in non-volatile storage for persistence and backup. This local quality differentiation ensures that the loss of one copy does not result in complete information loss, thereby enhancing security reliability while managing information loss risk.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250323920A1Location-Aware Multi-Factor Authentication for Virtual Machine Users
Publication Date: 2025.10.16 DELL PROD LP
  • US20250323920A1 patent drawing
  • US20250323920A1 patent drawing
  • US20250323920A1 patent drawing

AI summary

Disclosed systems and methods provide location-aware multi-factor authentication for VM users in combination with the prohibited users lists and disconnecting VMs based on user behavior or activity. Implementations may employ a hypervisor enabled by a lightweight, secure operating system (LSOS) as a foundational, enabling, and OS-agnostic technology for multiple uses cases. An LSOS authenticator module may generate IP location based authentication number for user authentication. An OEM Secure VM manager in Domain0 (Dom0) of a Xen cloud computing model may monitor user activity while Secure OEM Hypercall communication is employed for all communication from VM to LSOS. Embodiments may employ a LSOS VM prohibited users module and hypervisor action module to remove users and destroy VMs based on data received from Dom0, VM Manager and the user module in the VM.