Remote Integrity Assurance for Secured Virtual Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern enterprise systems face challenges in securing business data as employees access it from various locations, with malicious software compromising IHSs, leading to data theft and ransomware threats, making it difficult to balance employee productivity with data protection.

Innovation Solution

Implementing a method to remotely configure a secured virtual environment on IHSs by receiving reference and updated signatures, validating system integrity, and using a trusted resource to launch and periodically verify the security of virtual environments, ensuring data protection and user access while preventing compromised systems from operating.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees access business data from various locations using different IHSs, then employee productivity is improved, but data security and system protection become more difficult to maintain

Engineering Contradiction:
Improveemployee productivityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the enterprise system into multiple isolated virtual environments that run on employee IHSs. Each virtual environment is a self-contained secure container that separates business data and applications from the host system and other users' data. This allows employees to access business data from various locations while maintaining security through isolation - each virtual environment can be individually validated and controlled without compromising the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a remote attestation service as an intermediary between the IHS and the enterprise system. This service validates the integrity of the IHS and virtual environment by comparing measured states against reference states, acting as a trusted mediator that enables secure remote access without requiring physical presence or sacrificing security. The intermediary validates each virtual environment before allowing access to business data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security measures are implemented to protect business data, then data protection is improved, but employee productivity and data accessibility are reduced

Engineering Contradiction:
Improvedata protectionVSAvoidemployee productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic security validation through periodic remote attestation during virtual environment operation. Instead of static security measures that block access, the system continuously validates the integrity of running virtual environments by periodically comparing their measured state against the reference state. This dynamic approach maintains data protection while allowing employees to work productively within validated secure containers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary validation of the IHS and virtual environment configuration before allowing access to business data. The remote attestation service validates the integrity of the virtual environment by comparing its measured state against a reference state obtained during a trusted configuration phase. This preliminary action ensures security is established before productivity activities begin, rather than impeding them.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If malicious software is detected on an IHS, then data security is improved, but the complexity of detection and response increases

Engineering Contradiction:
Improvedata securityVSAvoidmalicious software detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements continuous feedback loops through periodic remote attestation during virtual environment operation. The system continuously measures the state of the virtual environment and compares it against the reference state, providing ongoing feedback about the integrity status. This feedback mechanism automatically detects malicious software or unauthorized modifications by identifying deviations from the validated reference state, making detection simpler and more reliable than traditional methods.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10846408B2Remote integrity assurance of a secured virtual environment
Publication Date: 2020.11.24 DELL PROD LP
  • US10846408B2 patent drawing
  • US10846408B2 patent drawing
  • US10846408B2 patent drawing

AI summary

A secured virtual environment provides access to enterprise data and may be configured remotely while isolated from the operating system of an Information Handling System (IHS). In secured booting of the IHS, references signatures are received via an out-of-band connection to the IHS. The reference signatures specify reference states for components of the IHS. Prior to launching a secured virtual environment, a trusted resource of the IHS, such as embedded controller isolated from the operating system, is queried for updated signatures specifying operating states of the component. The integrity of the IHS is validated based on comparisons of the respective reference signatures and updated signatures. If the integrity of the IHS is validated, a secured virtual environment is configured such that particular user may access the enterprise data according to applicable policies that may be periodically revalidated. The secured virtual environment may then be launched on the IHS.