Policy Enforcement Point for Virtual Machine Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As the proliferation of mobile devices and 'Bring Your Own Device' policies complicates ensuring that correct security policies are enforced on client devices accessing sensitive data and networks, existing technologies face challenges in maintaining the security, integrity, and availability of these resources.

Innovation Solution

A virtual mobile system that includes a policy check controller, host virtual machine server, and enterprise server, which receives information about client devices, generates and enforces device-specific policies by comparing and modifying policy sets to ensure compliance, thereby granting secure access to sensitive assets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional policy enforcement methods are used on mobile devices, then security policies can be enforced on standard devices, but it becomes difficult to ensure correct policies are enforced on diverse client devices including virtual machines

Engineering Contradiction:
Improvepolicy enforcement reliabilityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A policy enforcement point (PEP) component is introduced as an intermediary between the enterprise server and diverse client devices including virtual machines. The PEP receives device information, determines appropriate policies, and ensures they are correctly enforced on the specific client device type, bridging the gap between universal policy requirements and device-specific implementation challenges.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The policy enforcement system dynamically adapts to different client device types by receiving device information and determining device-specific policies. The system modifies policy enforcement behavior based on whether the client is a physical device, virtual machine, or other device type, allowing reliable security enforcement across diverse platforms without requiring separate static configurations for each device type.

Inventive Principle:
Principle #15Dynamics

2Reliability

If device-specific policies are generated for each client device, then security can be tailored to device characteristics, but the complexity of policy management increases

Engineering Contradiction:
Improvedevice-specific securityVSAvoidpolicy management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by receiving and analyzing device information before policy enforcement. The policy enforcement point pre-determines the appropriate device-specific policies based on client device type, and prepares the enforcement mechanism in advance, reducing the complexity of real-time policy management while maintaining device-specific security requirements.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If virtual machine systems are used to access sensitive data, then flexible device access is enabled, but it becomes more difficult for the enterprise server to ensure all device-oriented policies are met

Engineering Contradiction:
Improvedevice access flexibilityVSAvoidpolicy compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The policy enforcement point acts as an intermediary specifically for virtual machine access scenarios. It receives information about the virtual machine environment, determines appropriate policies for the VM type, and ensures compliance before granting access to sensitive enterprise data, maintaining both the flexibility of virtual machine access and the reliability of policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10581917B2Systems and methods for enforcing device policies
Publication Date: 2020.03.03 MOTOROLA SOLUTIONS INC
  • US10581917B2 patent drawing
  • US10581917B2 patent drawing
  • US10581917B2 patent drawing

AI summary

Systems and methods of enforcing device policies. One example method includes receiving, with an electronic processor and from a host virtual machine server, information regarding an electronic client device operating a guest virtual machine, and receiving, with the electronic processor, a policy check request from a server to the host virtual machine server. The policy check request includes a first set of policies generated by the server. The method also includes generating, with the electronic processor, a second set of policies based on information received from the host virtual machine server, and sending, from the electronic processor the second set of policies to the host virtual machine server.