Nested Virtual Machine Monitor for Cloud App Market Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud computing environments restrict interaction between virtual machines (VMs), preventing customers from leveraging advanced security and utility tools that require cooperation between VMs, such as VMI-based intrusion detection and network security services, which are typically deployed by cloud providers rather than being accessible to customers.
Innovation Solution
Implementing a cloud-based app market that allows customers to instantiate VM apps with privileged access, enabling interactions between customer VMs and security or utility VM apps, such as VMI-based intrusion detection and network security tools, by using a customer virtual machine monitor nested on a provider virtual machine monitor, with hardware-level support or emulation through a second-level virtualization layer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VMs are completely isolated by a single privileged management VM, then security and control are improved, but interaction between customer VMs is prevented
Solution Approach 1:
The patent implements nested virtualization where a customer virtual machine monitor (VMM) is nested within the provider VMM. This allows customer VMs to interact directly with each other through the customer VMM while the provider VMM maintains overall security control. The nested structure enables multiple levels of virtualization where inner VMs can communicate freely while outer VMM ensures system-wide security policies are enforced.
Solution Approach 2:
The patent segments the virtualization control into multiple privileged VMs under customer control rather than a single management VM. This segmentation allows different VMs to have specific privileged functions (e.g., security VM, networking VM) while maintaining the ability to interact with each other through the nested customer VMM, thus resolving the contradiction between control and interaction.
2Device complexity
If a single management VM controls all privileged operations, then system control is simplified, but customer flexibility to deploy custom security tools is reduced
Solution Approach 1:
The patent enables customers to self-deploy custom security tools and utilities as privileged VMs within their own nested virtualization environment. Instead of relying on the cloud provider to manage all security functions, customers can instantiate their own security VMs with appropriate privileges through the customer VMM, allowing flexible deployment of custom security solutions while maintaining manageable control structures.
Solution Approach 2:
The customer VMM acts as a universal interface that can manage multiple different types of privileged VMs (security tools, networking utilities, storage management) with different functions. This multi-functional approach allows a single control structure to handle diverse customer needs without requiring separate management mechanisms for each tool type.
3Productivity
If cloud providers deploy security services, then service availability is improved, but customer control over security operations is reduced
Solution Approach 1:
The patent adds a new dimension of control by introducing the customer VMM layer between the provider infrastructure and customer VMs. This dimensional change allows customers to control security operations directly within their virtualization namespace while still leveraging the provider's infrastructure availability. The nested VMM structure enables customer-level security management without sacrificing the underlying service availability provided by the cloud infrastructure.
Data Source
AI summary
In a cloud app market, a cloud infrastructure customer can purchase apps for performing services such as rootkit detection and network security for a customer virtual machine run by the cloud infrastructure customer. A cloud infrastructure provider executes a provider virtual machine monitor or hypervisor on cloud infrastructure. The cloud app is provided with a customer virtual machine monitor nested on the provider virtual machine monitor. The customer virtual machine, together with a nested management domain of the customer, execute on the customer virtual machine monitor.


