Security Virtual Machine for Cloud Data Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, the absence of edge devices renders traditional network security measures ineffective, as attackers can exploit vulnerabilities to access and modify data between virtual machines sharing the same hardware platform.

Innovation Solution

A security virtual machine is deployed to create encrypted channels between virtual machines, preventing direct communication and ensuring that all data traffic is routed through the security virtual machine, thereby enhancing network security without relying on edge devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines share the same hardware resource in cloud computing, then resource utilization efficiency is improved, but network security deteriorates because attackers can exploit vulnerabilities to access and modify data between virtual machines

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a security gateway virtual machine as an intermediary component between resource virtual machines. This gateway VM acts as a mediator that intercepts, inspects, and controls all network traffic between shared hardware resources and individual virtual machines, preventing direct unauthorized access while maintaining efficient resource sharing. The gateway VM serves as a trusted third party that enforces security policies without disrupting the underlying shared infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security function from the resource sharing function by creating a dedicated security gateway virtual machine separate from the resource virtual machines. This segmentation isolates security-critical operations into a distinct component that can be independently managed, monitored, and updated without affecting the resource allocation and sharing mechanisms. The segmentation allows security policies to be applied at the gateway layer while resource management continues at the hypervisor layer.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional edge devices are used to provide network security, then security functionality is improved, but device complexity increases and edge devices disappear in cloud computing environments

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security gateway virtual machine performs multiple security functions within a single virtualized platform, including network traffic inspection, intrusion detection, access control, and data encryption. By consolidating these previously separate edge device functions into a unified gateway VM that operates within the cloud infrastructure, the system achieves comprehensive security functionality without requiring multiple specialized physical devices. The gateway VM serves as a universal security component that adapts to different security requirements through software configuration rather than hardware specialization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements security functionality through virtualization by creating a virtual copy of edge device capabilities within the cloud environment. Instead of requiring physical edge devices at each network perimeter, the security gateway VM replicates edge device security functions in software, allowing the same security functionality to be deployed consistently across multiple cloud infrastructure locations. This virtual copying enables security operations to follow the workloads wherever they are distributed in the cloud environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9473472B1Enterprise cloud security gateway
Publication Date: 2016.10.18 TREND MICRO INC
  • US9473472B1 patent drawing
  • US9473472B1 patent drawing
  • US9473472B1 patent drawing

AI summary

A security virtual machine is provided in a network including a resource shared among two or more virtual machines. All data traffic from each virtual machine to or from the shared resource is transmitted over an encrypted channel to the security virtual machine. Each connection between a virtual machine and the security virtual machine is maintained as a separate encrypted channel, preventing one virtual machine from accessing data sent to or from another virtual machine, even though the virtual machines are all sharing the same resource.