Policy Engine Automates Red Green Virtual Machine Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Red/Green security schemes require users to manually switch between trusted and untrusted computers, leading to inconvenience and security risks due to the lack of centralized authority for delegating computing actions.

Innovation Solution

A policy engine automatically selects virtual machines for computing actions based on predefined categories, directing trusted actions to a Green virtual machine and untrusted actions to a Red virtual machine, eliminating the need for manual switching and providing a centralized security policy management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually switch between Red and Green machines, then security delegation can be maintained, but user convenience and productivity deteriorate due to continual switching requirements

Engineering Contradiction:
Improvesecurity delegationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a browser extension that acts as an intermediary between the user and the Red/Green machines. The extension automatically determines which machine should handle a given computing action and routes requests accordingly, eliminating the need for users to manually switch machines while maintaining security delegation integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users manually switch between Red and Green machines, then security delegation can be maintained, but productivity deteriorates due to time consumption and user confusion

Engineering Contradiction:
Improvesecurity delegationVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service automation where the browser extension autonomously manages machine selection and switching based on the computing action being performed. The extension automatically classifies actions as trusted or untrusted and routes them to the appropriate machine without requiring user intervention, thereby maintaining security delegation while eliminating productivity losses from manual switching

Inventive Principle:
Principle #25Self-service

3Device complexity

If no centralized authority controls machine delegation, then system complexity is reduced, but security reliability deteriorates due to uncoordinated policy lists between machines

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity consistency
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The browser extension serves as a centralized authority that coordinates policy lists across Red and Green machines. It maintains the authoritative classification of computing actions and ensures consistent delegation decisions, preventing security failures while adding minimal system complexity through a single coordinating component

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8683548B1Computing with policy engine for multiple virtual machines
Publication Date: 2014.03.25 EMC IP HLDG CO LLC
  • US8683548B1 patent drawing
  • US8683548B1 patent drawing
  • US8683548B1 patent drawing

AI summary

An improved technique for delegating computing actions among different machines includes a policy engine that receives inputs specifying computing actions to be performed and automatically selects a virtual machine to perform each action. Machine selection is based on a policy, which recognizes multiple categories of computing actions, classifies each input as belonging to one of the categories, and directs each computing action to a virtual machine designated for performing only that one category of computing actions.