Portable Encryption Module for Secure VM-Native OS Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to provide a secure communication environment and services between applications and virtual machines, especially in untrusted environments like third-party data centers or host computers, where users' data and credentials may be exposed.

Innovation Solution

A portable device with onboard database and memory, configured to negotiate user authentication and establish a secure communication channel between applications running on a virtual machine and a native operating system, using encryption and authentication services to facilitate secure data transfer and interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access third-party data centers or host computers for cloud computing and storage, then easy access and sharing of resources and data is enabled, but users are exposed to potentially hostile environments where their data and credentials may be compromised

Engineering Contradiction:
Improveaccess to cloud resourcesVSAvoidexposure to hostile environment
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtual machine as an intermediary layer between the user's application and the third-party host computer. This VM runs a secure operating system that mediates all communications, preventing direct exposure of user credentials and data to the potentially hostile host environment while still enabling cloud resource access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a hypervisor is used to manage keys and inject encrypted data into VMs, then secure exchange of encrypted data between VMs is achieved, but the system is limited to VMs running on a given hypervisor and does not provide general secure communication services

Engineering Contradiction:
Improvesecure data exchangeVSAvoidcommunication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual machine with a secure operating system that provides universal secure communication capabilities across different applications and platforms. Rather than being limited to specific hypervisor-VM pairs, this VM can serve multiple applications and communicate with various external systems through standardized interfaces

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a secure VM is used as a proxy for sensitive web communications, then communication security is improved, but the system fails to provide an environment and services for secure communication between applications and VMs

Engineering Contradiction:
Improvecommunication securityVSAvoidapplication integration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the system into distinct functional layers: a secure virtual machine environment for sensitive operations, a host operating system for resource management, and application layers that can interact with either. This segmentation allows each layer to be optimized for its specific function while providing secure communication pathways between them

Inventive Principle:
Principle #1Segmentation

4Object-affected harmful factors

If security by isolation is implemented using VMs with limited access, then protection from external threats is achieved, but the system fails to provide an environment and services for secure communication between applications and VMs

Engineering Contradiction:
Improveprotection from threatsVSAvoidsecure communication services
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent uses the virtual machine as an intermediary that provides both isolation and communication services. The VM's secure operating system acts as a mediator that enforces security policies while simultaneously providing structured interfaces for applications to communicate securely with the VM and through it to external systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10230693B2Safechannel encrypted messaging system
Publication Date: 2019.03.12 WEBCLOAK LLC
  • US10230693B2 patent drawing
  • US10230693B2 patent drawing
  • US10230693B2 patent drawing

AI summary

Portable, hand-held electronic devices for and methods to enabling a user to interact with a native operating system (OS) running on a host device and a virtual machine running on top of the native OS are presented. The host device includes a processor to communicate with an application having a target network address. The devices includes an onboard database that stores user credential information and a portable encryption and authentication service module (PPEASM) that allows to make a secure communication channel with the host device. The PPEASM configures the processor to negotiate authentication of the user with an application running on top of the native OS utilizing the user credential information, render an application running on top of the virtual machine, and pass data between the application running on top of the virtual machine and a second application running on top of the native OS.