Secure Enclave for Virtual Machine Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud computing systems face security challenges due to the risk of breaches from malicious IT staff or service providers, as automation increases the risk of attackers hiding among legitimate actions, and existing virtual machine management systems are complex and difficult to secure.

Innovation Solution

Implementing a method to deploy an encrypted entity on a trusted entity by using a trust credential from an authority to obtain a key from a key distribution service, ensuring secure deployment and management of virtual machines through a trusted execution environment and cryptographic operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automation is increased to lower operational costs and improve scalability, then productivity and efficiency are improved, but the risk of security breaches increases as attackers can hide among legitimate automated actions

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity breach risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure enclave as an intermediary component that mediates between the automated management systems and the virtual machines. This secure enclave provides a trusted execution environment that verifies the authenticity of automated actions, allowing high-level automation while preventing attackers from impersonating legitimate automated processes. The secure enclave acts as a mediator that can distinguish between genuine automated actions and malicious attempts to exploit automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If virtual machine management systems are made more accessible and easier to operate, then ease of operation is improved, but the complexity of the trusted computing base increases making security harder to ensure

Engineering Contradiction:
Improvemanagement accessibilityVSAvoidtrusted computing base complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the security-critical functions from the complex management systems and places them in a separate, dedicated secure enclave. This extraction allows the main management systems to remain simple and accessible while the security functions are isolated in a minimized trusted computing base. The secure enclave handles only the essential security operations, reducing the overall complexity of the trusted computing base while maintaining ease of operation for the management systems.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If service provider staff are given broad access to manage fabric and virtual machines, then ease of operation is improved, but the risk of malicious actions or credential theft increases

Engineering Contradiction:
Improvestaff access capabilityVSAvoidmalicious access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments access rights by implementing a secure enclave that holds cryptographic keys and credentials separately from the staffed management systems. This segmentation allows staff to operate management systems with ease while the actual security-critical operations require authentication through the secure enclave. The separation ensures that even if staff credentials are compromised, attackers cannot access the segmented security functions without compromising the secure enclave itself.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10956321B2Secure management of operations on protected virtual machines
Publication Date: 2021.03.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10956321B2 patent drawing
  • US10956321B2 patent drawing
  • US10956321B2 patent drawing

AI summary

A virtual secure mode is enabled for a virtual machine operating in a computing environment that is associated with a plurality of different trust levels. First, a virtual secure mode image is loaded into one or more memory pages of a virtual memory space of the virtual machine. Then, the one or more memory pages of the virtual memory space are made inaccessible to one or more trust levels having a relatively lower trust level than a launching trust level that is used by a virtual secure mode loader to load the virtual secure mode image. A target virtual trust level is also enabled on a launching virtual processor for the virtual machine that is higher than the launching trust level.