Virtual Asset Agent Self-Repair via Trusted Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, virtual assets are vulnerable to security threats due to unknown vulnerabilities at creation, making detection and response challenging, and malicious entities can control or shut down communication channels, rendering traditional security measures ineffective.

Innovation Solution

A method and system that employs a virtual asset agent to monitor and self-repair by creating a new virtual asset with the agent and associated data, using secure communication channels to transfer secrets and security updates, thereby protecting and repairing the asset from potential security threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional communication channels are used for monitoring and repairing virtual assets, then the system is simple to operate, but the security reliability deteriorates when malicious entities control these channels

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted communication channel as an intermediary between the virtual asset management system and the virtual asset agent. This mediator channel, established through secure protocols like TLS or IPSec, protects communications from malicious entities controlling normal channels, thereby improving security reliability without requiring complete system redesign

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication infrastructure is segmented into two distinct channels: normal communication channels for routine operations and trusted communication channels for security-critical operations. This segmentation allows the system to maintain simplicity for everyday use while ensuring reliability for security functions through dedicated protected pathways

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If security updates are transmitted through normal communication channels, then the ease of operation is maintained, but the measurement precision of security threat detection deteriorates due to channel compromise

Engineering Contradiction:
Improvesecurity threat detection accuracyVSAvoidease of updating
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

A trusted communication channel acts as an intermediary for transmitting security updates and threat detection data. This mediator ensures that updates reach the virtual asset agent without interception or manipulation by malicious entities, maintaining detection accuracy while preserving ease of operation through automated update mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system preemptively establishes trusted communication channels before security threats can compromise normal channels. By setting up secure pathways in advance for update transmission and threat reporting, the system ensures accurate threat detection without requiring complex real-time verification procedures

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If the virtual asset agent continuously monitors for security threats, then the reliability of threat detection improves, but the energy consumption increases

Engineering Contradiction:
Improvethreat detection reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The virtual asset agent performs security monitoring through periodic scans and event-driven triggers rather than continuous analysis. This periodic action maintains reliable threat detection by checking at regular intervals and responding to specific security events, while significantly reducing energy consumption compared to constant monitoring

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The virtual asset agent autonomously manages its own security monitoring, using lightweight agents and efficient algorithms that minimize resource consumption. The agent self-regulates its monitoring intensity based on threat levels and system state, maintaining reliable detection while optimizing energy usage without requiring external control

Inventive Principle:
Principle #25Self-service

4Reliability

If a new virtual asset is created to replace a compromised asset, then the security reliability improves, but the loss of time increases due to recreation and data transfer

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidtime for asset recreation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining ready-to-use templates and configurations for virtual assets. When compromise is detected, pre-prepared replacement assets can be rapidly instantiated with essential configurations already in place, significantly reducing the time required for asset recreation while ensuring security reliability through the use of hardened templates

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3654582B1Method and system for secure delivery of information to computing environments
Publication Date: 2022.08.03 INTUIT INC
  • EP3654582B1 patent drawingFigure 1
  • EP3654582B1 patent drawingFigure 2
  • EP3654582B1 patent drawingFigure 3

AI summary

A method and system for protecting and repairing a current virtual asset from damage by potential security threats, according to one embodiment. The method and system include monitoring a current a current virtual asset for potential security threats, with a virtual asset agent, according to one embodiment. The method and system include determining a severity of the potential security threats that are identified by the virtual asset agent, according to one embodiment. The method and system include creating a new virtual asset with the virtual asset agent and decommissioning the current virtual asset, according to one embodiment. The system and method receiving, with the new virtual asset, secrets that are associated with the current virtual asset to enable the new virtual asset to continue operations of the current virtual asset, according to one embodiment.