Shrouded Virtual Server Hosting System Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing clients face security concerns regarding data protection, as they need assurance that their virtual servers are deployed on platforms with specific hardware and software components, and are shielded from access by cloud providers or their employees, especially in a multi-tenant hosting environment where data security and privacy are paramount.
Innovation Solution
A method and system for extending shrouding capability in virtual server hosting systems, which involves deploying a guest server with preconfigured hypervisor in an immutable mode, using a predetermined set of hardware components, and ensuring that only the client can access the virtual server, by employing tamper-proof hardware and encryption schemes to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud providers deploy datacenters in each country to comply with data protection policies, then data security compliance is improved, but system complexity and cost increase
Solution Approach 1:
The patent segments the hosting system into multiple isolated virtual servers, each with dedicated hardware components and encrypted storage. This allows a single datacenter to serve multiple clients with different data protection requirements without requiring separate physical datacenters for each country or client, thus maintaining compliance while reducing system complexity.
Solution Approach 2:
The patent implements local quality by allowing each virtual server to have customized security configurations, encryption keys, and hardware specifications tailored to specific client requirements. This enables differentiated data protection levels within a unified hosting system, avoiding the need for homogeneous complex infrastructure across all clients.
2Reliability
If cloud providers deploy remote datacenters for disaster recovery, then data protection capability is improved, but geographic constraints limit the distance between primary and backup sites
Solution Approach 1:
The patent introduces encryption and virtualization as intermediaries that enable secure data replication and disaster recovery capabilities within the same geographic location. By encrypting data at rest and using virtual server isolation, the system achieves disaster recovery functionality without requiring physical separation, effectively using encryption as a mediator that replaces geographic distance as the security barrier.
3Ease of operation
If administrators are given access to hosting system resources for maintenance, then system operability is improved, but security risk increases as administrators can access client data
Solution Approach 1:
The patent implements preliminary action by pre-configuring virtual servers with immutable encryption keys and security settings before deployment. The encryption keys are generated and stored in secure hardware modules prior to any administrative access, ensuring that even when administrators perform maintenance tasks, they cannot access or modify the encryption keys that protect client data.
Solution Approach 2:
The patent extracts the encryption key management function from the general administrative control system. Encryption keys are generated, stored, and managed in dedicated secure hardware modules separate from the main system administration interfaces, creating an independent security layer that administrators cannot access through normal maintenance procedures.
Data Source
AI summary
Technical solutions are described for extending shrouding capability of a virtual server hosting system. An example method includes receiving a request to deploy a shrouded virtual server using a predetermined set of hardware components, and using a shrouded mode. The method also includes adding a guest server to the hosting system, the guest server including the predetermined set of hardware components. The method also includes deploying a preconfigured hypervisor on the guest server, where the preconfigured hypervisor is deployed in an immutable mode that disables changes to security settings of the preconfigured hypervisor. The method also includes deploying, by the preconfigured hypervisor, a preconfigured boot image as an instance of the virtual server on the preconfigured hypervisor. The method also includes sending an identifier of the virtual server for receipt by the client device.


