SecureVM Package Encrypts Virtual Machine Files

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual machine distribution technologies lack secure methods to prevent unauthorized use while allowing authorized access across different computing systems, making it easy for confidential data to be stolen and used improperly.

Innovation Solution

The SecureVM package encrypts virtual machine files and uses a secure filesystem to manage access, authenticating users and machines based on security policies, ensuring only authorized entities can decrypt and use the virtual machines, thereby maintaining security across different environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machine files are distributed across different computing systems, then adaptability and versatility are improved, but security and reliability deteriorate due to easy theft and unauthorized use

Engineering Contradiction:
Improvevirtual machine portabilityVSAvoidvirtual machine security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting virtual machine files before distribution and establishing authentication mechanisms in advance. The security policies are configured beforehand to control access, ensuring that even if files are stolen, they cannot be used without proper authentication credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication layer between the virtual machine files and the computing systems. This intermediary verifies credentials against security policies before allowing access, preventing direct unauthorized use of distributed virtual machine files while maintaining portability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied to virtual machine files, then security is improved, but device complexity and ease of operation worsen due to authentication requirements

Engineering Contradiction:
Improvevirtual machine securityVSAvoidsecurity policy implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having the authentication system automatically verify credentials and enforce security policies without requiring manual intervention. The system autonomously manages the complexity of encryption and authentication, presenting a simplified interface to users while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication mechanisms are implemented, then security is improved, but productivity and ease of operation deteriorate due to access verification steps

Engineering Contradiction:
Improveauthorized access controlVSAvoidvirtual machine access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-configuring security policies and authentication credentials before access is needed. This allows for faster verification during actual access attempts, as the authentication mechanisms are already in place and do not require complex real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9300640B2Secure virtual machine
Publication Date: 2016.03.29 ENTRUST CORP
  • US9300640B2 patent drawing
  • US9300640B2 patent drawing
  • US9300640B2 patent drawing

AI summary

An approach to securely distributing and running virtual machines is described that addresses the inherent insecurity of mobile virtual machines by authenticating a user before establishing a specialized virtualization runtime environment that includes a filesystem driver inserted into the host operating system to provide secure access to a virtual machine by authorized hypervisors only. Further described is the creation of a SecureVM package that includes the various components used to perform the operations of installation, user authentication and establishment of the specialized virtualization runtime environment.