Policy Engine Automates Red Green Virtual Machine Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Red/Green security schemes require users to manually switch between trusted and untrusted computers, leading to inconvenience and security risks due to the lack of centralized authority for delegating computing actions.
Innovation Solution
A policy engine automatically selects virtual machines for computing actions based on predefined categories, directing trusted actions to a Green virtual machine and untrusted actions to a Red virtual machine, eliminating the need for manual switching and providing a centralized security policy management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manually switch between Red and Green machines, then security delegation can be maintained, but user convenience and productivity deteriorate due to continual switching requirements
Solution Approach 1:
The patent introduces a browser extension that acts as an intermediary between the user and the Red/Green machines. The extension automatically determines which machine should handle a given computing action and routes requests accordingly, eliminating the need for users to manually switch machines while maintaining security delegation integrity
2Reliability
If users manually switch between Red and Green machines, then security delegation can be maintained, but productivity deteriorates due to time consumption and user confusion
Solution Approach 1:
The system enables self-service automation where the browser extension autonomously manages machine selection and switching based on the computing action being performed. The extension automatically classifies actions as trusted or untrusted and routes them to the appropriate machine without requiring user intervention, thereby maintaining security delegation while eliminating productivity losses from manual switching
3Device complexity
If no centralized authority controls machine delegation, then system complexity is reduced, but security reliability deteriorates due to uncoordinated policy lists between machines
Solution Approach 1:
The browser extension serves as a centralized authority that coordinates policy lists across Red and Green machines. It maintains the authoritative classification of computing actions and ensures consistent delegation decisions, preventing security failures while adding minimal system complexity through a single coordinating component
Data Source
AI summary
An improved technique for delegating computing actions among different machines includes a policy engine that receives inputs specifying computing actions to be performed and automatically selects a virtual machine to perform each action. Machine selection is based on a policy, which recognizes multiple categories of computing actions, classifies each input as belonging to one of the categories, and directs each computing action to a virtual machine designated for performing only that one category of computing actions.


