Portable Virtual Machine for Secure Online Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing online transactions on untrusted computers is challenging due to the difficulty in ensuring the security of shared or publicly available computers, limiting the mobility and convenience of performing confidential transactions.

Innovation Solution

A secured computing environment is loaded from a portable storage device, which creates a virtual machine on a host computer running a secured operating system, restricting access to only authorized network addresses and applications, using a security profile to enforce protection policies and maintain data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users perform online confidential transactions on untrusted computers, then mobility and instant access are improved, but security is worsened

Engineering Contradiction:
ImprovemobilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the computing environment by creating a virtual machine that is isolated from the host operating system. This virtual machine contains only the necessary components for confidential transactions, separating the secure computing environment from the untrusted host system, thereby enabling mobility without compromising security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nesting by placing a secured operating system within a virtual machine, which itself runs on the host operating system of the untrusted computer. This nested structure allows the secure environment to be contained within the untrusted system without being compromised by it, resolving the contradiction between mobility and security

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If users exclusively use their own computers for confidential transactions, then security is improved, but mobility and convenience are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidmobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system creates a portable copy of a secure computing environment that can be loaded onto any untrusted computer. This copy contains the secured operating system and necessary applications, allowing users to replicate their secure computing experience on any machine without needing to physically own or control the host computer, thus maintaining security while improving mobility

Inventive Principle:
Principle #26Copying

3Reliability

If protective measures such as antivirus programs are used on personal computers, then security is improved, but device complexity and difficulty of securing other computers are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security measures from the host operating system and embeds them within the virtual machine's secured operating system. This extraction allows the security functionality to be self-contained within the virtual environment, eliminating the need for complex antivirus programs on the host system while maintaining security, thus reducing device complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8024790B2Portable secured computing environment for performing online confidential transactions in untrusted computers
Publication Date: 2011.09.20 TREND MICRO INC
  • US8024790B2 patent drawing
  • US8024790B2 patent drawing
  • US8024790B2 patent drawing

AI summary

A portable secured computing environment for performing online confidential transactions in an untrusted host computer. The secured computing environment may be loaded from a portable storage device, such as a USB stick, plugged into a peripheral port of the host computer. The secured computing environment may include a virtual machine running under a host operating system of the host computer. A secured operating system may be running in the virtual machine. An online application, such as a web browser in communication with an online service, may be run under the secured operating system. Operation of the online application may be restricted by a security profile. For example, the online application may only access network addresses specifically indicated in a whitelist of the security profile.