Remote Integrity Assurance for Secured Virtual Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern enterprise systems face challenges in securing business data as employees access it from various locations, with malicious software compromising IHSs, leading to data theft and ransomware threats, making it difficult to balance employee productivity with data protection.
Innovation Solution
Implementing a method to remotely configure a secured virtual environment on IHSs by receiving reference and updated signatures, validating system integrity, and using a trusted resource to launch and periodically verify the security of virtual environments, ensuring data protection and user access while preventing compromised systems from operating.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If employees access business data from various locations using different IHSs, then employee productivity is improved, but data security and system protection become more difficult to maintain
Solution Approach 1:
The patent segments the enterprise system into multiple isolated virtual environments that run on employee IHSs. Each virtual environment is a self-contained secure container that separates business data and applications from the host system and other users' data. This allows employees to access business data from various locations while maintaining security through isolation - each virtual environment can be individually validated and controlled without compromising the entire system.
Solution Approach 2:
The patent introduces a remote attestation service as an intermediary between the IHS and the enterprise system. This service validates the integrity of the IHS and virtual environment by comparing measured states against reference states, acting as a trusted mediator that enables secure remote access without requiring physical presence or sacrificing security. The intermediary validates each virtual environment before allowing access to business data.
2Reliability
If traditional security measures are implemented to protect business data, then data protection is improved, but employee productivity and data accessibility are reduced
Solution Approach 1:
The patent implements dynamic security validation through periodic remote attestation during virtual environment operation. Instead of static security measures that block access, the system continuously validates the integrity of running virtual environments by periodically comparing their measured state against the reference state. This dynamic approach maintains data protection while allowing employees to work productively within validated secure containers.
Solution Approach 2:
The patent performs preliminary validation of the IHS and virtual environment configuration before allowing access to business data. The remote attestation service validates the integrity of the virtual environment by comparing its measured state against a reference state obtained during a trusted configuration phase. This preliminary action ensures security is established before productivity activities begin, rather than impeding them.
3Reliability
If malicious software is detected on an IHS, then data security is improved, but the complexity of detection and response increases
Solution Approach 1:
The patent implements continuous feedback loops through periodic remote attestation during virtual environment operation. The system continuously measures the state of the virtual environment and compares it against the reference state, providing ongoing feedback about the integrity status. This feedback mechanism automatically detects malicious software or unauthorized modifications by identifying deviations from the validated reference state, making detection simpler and more reliable than traditional methods.
Data Source
AI summary
A secured virtual environment provides access to enterprise data and may be configured remotely while isolated from the operating system of an Information Handling System (IHS). In secured booting of the IHS, references signatures are received via an out-of-band connection to the IHS. The reference signatures specify reference states for components of the IHS. Prior to launching a secured virtual environment, a trusted resource of the IHS, such as embedded controller isolated from the operating system, is queried for updated signatures specifying operating states of the component. The integrity of the IHS is validated based on comparisons of the respective reference signatures and updated signatures. If the integrity of the IHS is validated, a secured virtual environment is configured such that particular user may access the enterprise data according to applicable policies that may be periodically revalidated. The secured virtual environment may then be launched on the IHS.


