Portable Encryption Module for Secure VM-Native OS Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies fail to provide a secure communication environment and services between applications and virtual machines, especially in untrusted environments like third-party data centers or host computers, where users' data and credentials may be exposed.
Innovation Solution
A portable device with onboard database and memory, configured to negotiate user authentication and establish a secure communication channel between applications running on a virtual machine and a native operating system, using encryption and authentication services to facilitate secure data transfer and interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users access third-party data centers or host computers for cloud computing and storage, then easy access and sharing of resources and data is enabled, but users are exposed to potentially hostile environments where their data and credentials may be compromised
Solution Approach 1:
The patent introduces a virtual machine as an intermediary layer between the user's application and the third-party host computer. This VM runs a secure operating system that mediates all communications, preventing direct exposure of user credentials and data to the potentially hostile host environment while still enabling cloud resource access
2Reliability
If a hypervisor is used to manage keys and inject encrypted data into VMs, then secure exchange of encrypted data between VMs is achieved, but the system is limited to VMs running on a given hypervisor and does not provide general secure communication services
Solution Approach 1:
The patent creates a virtual machine with a secure operating system that provides universal secure communication capabilities across different applications and platforms. Rather than being limited to specific hypervisor-VM pairs, this VM can serve multiple applications and communicate with various external systems through standardized interfaces
3Reliability
If a secure VM is used as a proxy for sensitive web communications, then communication security is improved, but the system fails to provide an environment and services for secure communication between applications and VMs
Solution Approach 1:
The patent segments the system into distinct functional layers: a secure virtual machine environment for sensitive operations, a host operating system for resource management, and application layers that can interact with either. This segmentation allows each layer to be optimized for its specific function while providing secure communication pathways between them
4Object-affected harmful factors
If security by isolation is implemented using VMs with limited access, then protection from external threats is achieved, but the system fails to provide an environment and services for secure communication between applications and VMs
Solution Approach 1:
The patent uses the virtual machine as an intermediary that provides both isolation and communication services. The VM's secure operating system acts as a mediator that enforces security policies while simultaneously providing structured interfaces for applications to communicate securely with the VM and through it to external systems
Data Source
AI summary
Portable, hand-held electronic devices for and methods to enabling a user to interact with a native operating system (OS) running on a host device and a virtual machine running on top of the native OS are presented. The host device includes a processor to communicate with an application having a target network address. The devices includes an onboard database that stores user credential information and a portable encryption and authentication service module (PPEASM) that allows to make a secure communication channel with the host device. The PPEASM configures the processor to negotiate authentication of the user with an application running on top of the native OS utilizing the user credential information, render an application running on top of the virtual machine, and pass data between the application running on top of the virtual machine and a second application running on top of the native OS.


