Nested Virtual Machine Monitor for Cloud App Market Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing environments restrict interaction between virtual machines (VMs), preventing customers from leveraging advanced security and utility tools that require cooperation between VMs, such as VMI-based intrusion detection and network security services, which are typically deployed by cloud providers rather than being accessible to customers.

Innovation Solution

Implementing a cloud-based app market that allows customers to instantiate VM apps with privileged access, enabling interactions between customer VMs and security or utility VM apps, such as VMI-based intrusion detection and network security tools, by using a customer virtual machine monitor nested on a provider virtual machine monitor, with hardware-level support or emulation through a second-level virtualization layer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VMs are completely isolated by a single privileged management VM, then security and control are improved, but interaction between customer VMs is prevented

Engineering Contradiction:
Improvesecurity controlVSAvoidVM interaction capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements nested virtualization where a customer virtual machine monitor (VMM) is nested within the provider VMM. This allows customer VMs to interact directly with each other through the customer VMM while the provider VMM maintains overall security control. The nested structure enables multiple levels of virtualization where inner VMs can communicate freely while outer VMM ensures system-wide security policies are enforced.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent segments the virtualization control into multiple privileged VMs under customer control rather than a single management VM. This segmentation allows different VMs to have specific privileged functions (e.g., security VM, networking VM) while maintaining the ability to interact with each other through the nested customer VMM, thus resolving the contradiction between control and interaction.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a single management VM controls all privileged operations, then system control is simplified, but customer flexibility to deploy custom security tools is reduced

Engineering Contradiction:
Improvecontrol structureVSAvoidcustom security tool deployment
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent enables customers to self-deploy custom security tools and utilities as privileged VMs within their own nested virtualization environment. Instead of relying on the cloud provider to manage all security functions, customers can instantiate their own security VMs with appropriate privileges through the customer VMM, allowing flexible deployment of custom security solutions while maintaining manageable control structures.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The customer VMM acts as a universal interface that can manage multiple different types of privileged VMs (security tools, networking utilities, storage management) with different functions. This multi-functional approach allows a single control structure to handle diverse customer needs without requiring separate management mechanisms for each tool type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If cloud providers deploy security services, then service availability is improved, but customer control over security operations is reduced

Engineering Contradiction:
Improveservice availabilityVSAvoidcustomer control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent adds a new dimension of control by introducing the customer VMM layer between the provider infrastructure and customer VMs. This dimensional change allows customers to control security operations directly within their virtualization namespace while still leveraging the provider's infrastructure availability. The nested VMM structure enables customer-level security management without sacrificing the underlying service availability provided by the cloud infrastructure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10210014B2Richer model of cloud app markets
Publication Date: 2019.02.19 AT&T INTELLECTUAL PROPERTY I L P
  • US10210014B2 patent drawing
  • US10210014B2 patent drawing
  • US10210014B2 patent drawing

AI summary

In a cloud app market, a cloud infrastructure customer can purchase apps for performing services such as rootkit detection and network security for a customer virtual machine run by the cloud infrastructure customer. A cloud infrastructure provider executes a provider virtual machine monitor or hypervisor on cloud infrastructure. The cloud app is provided with a customer virtual machine monitor nested on the provider virtual machine monitor. The customer virtual machine, together with a nested management domain of the customer, execute on the customer virtual machine monitor.