Policy Enforcement Point for Virtual Machine Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As the proliferation of mobile devices and 'Bring Your Own Device' policies complicates ensuring that correct security policies are enforced on client devices accessing sensitive data and networks, existing technologies face challenges in maintaining the security, integrity, and availability of these resources.
Innovation Solution
A virtual mobile system that includes a policy check controller, host virtual machine server, and enterprise server, which receives information about client devices, generates and enforces device-specific policies by comparing and modifying policy sets to ensure compliance, thereby granting secure access to sensitive assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional policy enforcement methods are used on mobile devices, then security policies can be enforced on standard devices, but it becomes difficult to ensure correct policies are enforced on diverse client devices including virtual machines
Solution Approach 1:
A policy enforcement point (PEP) component is introduced as an intermediary between the enterprise server and diverse client devices including virtual machines. The PEP receives device information, determines appropriate policies, and ensures they are correctly enforced on the specific client device type, bridging the gap between universal policy requirements and device-specific implementation challenges.
Solution Approach 2:
The policy enforcement system dynamically adapts to different client device types by receiving device information and determining device-specific policies. The system modifies policy enforcement behavior based on whether the client is a physical device, virtual machine, or other device type, allowing reliable security enforcement across diverse platforms without requiring separate static configurations for each device type.
2Reliability
If device-specific policies are generated for each client device, then security can be tailored to device characteristics, but the complexity of policy management increases
Solution Approach 1:
The system performs preliminary actions by receiving and analyzing device information before policy enforcement. The policy enforcement point pre-determines the appropriate device-specific policies based on client device type, and prepares the enforcement mechanism in advance, reducing the complexity of real-time policy management while maintaining device-specific security requirements.
3Adaptability or versatility
If virtual machine systems are used to access sensitive data, then flexible device access is enabled, but it becomes more difficult for the enterprise server to ensure all device-oriented policies are met
Solution Approach 1:
The policy enforcement point acts as an intermediary specifically for virtual machine access scenarios. It receives information about the virtual machine environment, determines appropriate policies for the VM type, and ensures compliance before granting access to sensitive enterprise data, maintaining both the flexibility of virtual machine access and the reliability of policy enforcement.
Data Source
AI summary
Systems and methods of enforcing device policies. One example method includes receiving, with an electronic processor and from a host virtual machine server, information regarding an electronic client device operating a guest virtual machine, and receiving, with the electronic processor, a policy check request from a server to the host virtual machine server. The policy check request includes a first set of policies generated by the server. The method also includes generating, with the electronic processor, a second set of policies based on information received from the host virtual machine server, and sending, from the electronic processor the second set of policies to the host virtual machine server.


