Securing Checked-Out Virtual Machines in VDI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Checked-out virtual machines in a virtual desktop infrastructure (VDI) lack endpoint security functionality, posing a significant security risk as they are not adequately secured when transferred from a datacenter to a user device.

Innovation Solution

A method and system for securing a checked-out guest virtual machine by configuring a security module based on information gathered from the client network element, which includes transmitting a probe packet to gather information about the client network element and configuring the security module to provide security services such as antivirus, antimalware, firewall, and intrusion prevention software, ensuring the virtual machine remains secure even when decoupled from the server network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machines are checked-out from datacenter to user device, then user access flexibility is improved, but endpoint security functionality deteriorates

Engineering Contradiction:
Improveuser access flexibilityVSAvoidendpoint security functionality
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by configuring and provisioning security modules (antivirus, antimalware, firewall, intrusion prevention) to the virtual machine before it is checked-out to the user device. This ensures that security functionality is already in place and activated when the VM transitions to the endpoint environment, preventing the security gap that would otherwise occur during the check-out process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security module as an intermediary component that mediates between the virtual machine and the endpoint device. This security module acts as a protective layer that accompanies the VM when it is checked-out, providing continuous security services regardless of whether the VM is running in the datacenter or at the user's endpoint device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security module is configured based on client network element information, then security effectiveness is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies local quality by gathering specific information about the client network element (such as device type, operating system, existing security posture) and using that information to configure the security module with appropriate settings and capabilities tailored to that specific endpoint environment. This ensures the security configuration is optimized for the local context rather than using a one-size-fits-all approach.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs self-service by automatically gathering information about the client network element and using that information to autonomously configure the security module without requiring manual intervention. The system probes the endpoint, analyzes the collected information, and automatically adjusts security settings, which reduces the operational complexity despite the increased configurational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2686804B1Techniques for securing a checked-out virtual machine in a virtual desktop infrastructure
Publication Date: 2018.08.08 GEN DIGITAL INC
  • EP2686804B1 patent drawingFigure 1
  • EP2686804B1 patent drawingFigure 2
  • EP2686804B1 patent drawingFigure 3

AI summary

Techniques for securing checked-out virtual machines in a virtual desktop infrastructure (VDI) are disclosed. In one particular exemplary embodiment, the techniques may be realized as a method for securing a checked-out guest virtual machine including receiving a request for checking-out a guest virtual machine hosted by a server network element, wherein checking-out the guest virtual machine comprises transferring hosting of the guest virtual machine from the server network element to a client network element. The method for securing a checked-out guest virtual machines may also include configuring a security module for the guest virtual machine in order to secure the guest virtual machine and providing the security module to the guest virtual machine when the guest virtual machine is checked-out.