Virtual Execution Environment Security Administration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing security services in multi-server environments are inefficient and costly, requiring extensive manual operations and lacking a unified, secure mechanism for administration and security management, especially for remote users, which can lead to service disruptions and security breaches.

Innovation Solution

A system and method that utilize one or more Virtual Execution Environments (VEEs) to manage and provide security services, including firewall services, spam filtering, and anti-virus protection, where a designated VEE controls and delivers these services to other VEEs based on their specific needs, reducing operational overhead and enhancing security by isolating and standardizing administrative functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security services are provided for each individual computer system or VEE, then security coverage is comprehensive, but system complexity and administrative overhead increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple VEEs are merged into a single host VEE, allowing security services to be implemented at the host level rather than individually in each guest VEE. This consolidation reduces the number of security implementations from many individual systems to one unified system, thereby reducing complexity while maintaining comprehensive security coverage across all VEEs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host VEE serves multiple functions: it acts as both a guest VEE requiring security services and as a security service provider for other VEEs. This universal role allows a single security implementation to protect multiple systems, reducing overall system complexity while ensuring comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If manual operations are used for administering security services across multiple servers, then flexibility in configuration is maintained, but administrative cost and time consumption increase

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidadministrative time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system enables automated self-service administration where the host VEE automatically manages security services for guest VEEs without requiring manual intervention for each individual VEE. Configuration changes propagate automatically across the virtualized environment, reducing administrative time while maintaining flexibility through centralized control interfaces.

Inventive Principle:
Principle #25Self-service

3Reliability

If security services are distributed across multiple independent systems, then service availability is maintained, but operational costs and resource utilization increase

Engineering Contradiction:
Improveservice availabilityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Security services are merged from multiple distributed implementations into a single consolidated security system running on the host VEE. This consolidation eliminates redundant security processes across multiple systems, reducing operational costs and resource consumption while maintaining service availability through the unified security architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host VEE's security services provide universal protection to multiple guest VEEs simultaneously, replacing the need for separate security implementations in each system. This multi-functional approach reduces operational costs by eliminating redundant resources while maintaining comprehensive security coverage and service availability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If administrative functions are centralized in a single VEE, then management efficiency improves, but single point of failure risk increases

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsystem stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The host VEE acts as an intermediary layer between the virtualization infrastructure and guest VEEs, centralizing administrative functions for improved management efficiency. The host VEE mediates security service delivery and administrative operations, providing a single point of control that enhances productivity while the virtualized architecture itself provides redundancy and isolation to mitigate single point of failure risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8074276B1Method and system for administration of security services within a virtual execution environment (VEE) infrastructure
Publication Date: 2011.12.06 VIRTUOZZO INT GMBH
  • US8074276B1 patent drawing
  • US8074276B1 patent drawing
  • US8074276B1 patent drawing

AI summary

A system and method for managing administration of security services provided to users includes a computer system and an operating system running on the computer system. A plurality of Virtual Execution Environments (VEEs) are executed on the computer system. The VEEs can be any of a Virtual Private Server, a Virtual Machine, a Hypervisor-based Virtual Machine, and a Lightweight Hypervisor-based Virtual Machine, a session of Terminal Server and a session of Presentation Server, Lightweight Hypervisor-based Virtual Machines, VMM-based VMs or hypervisor-based VMs. Each VEE provides a set of services to remote users. One or more designated VEE(s) provide security services to each of the VEEs based on the needs of the remote users of the particular VEEs. The security services provided by the designated VEE can be firewall services, spam filtering and anti-virus protection. The security services are controlled and administered by each of the VEEs requesting a particular service via control means of the designated VEE(s).