Virtual Appliance Machine for Guest VM Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments lack effective access control and data protection for guest virtual machines, leading to potential misuse and exposure of data in unused or dormant machines, with current systems relying on manual de-provisioning and lacking compliance reports.

Innovation Solution

A system and method that assigns status indicators to guest virtual machines, utilizing a virtual appliance machine to enforce access control by determining whether the machine is active or inactive, preventing unauthorized use and providing alerts and reports for compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud providers delete or cleanup guest virtual machines upon termination, then resource utilization is improved, but data security deteriorates because data may remain exposed on dormant machines

Engineering Contradiction:
Improveresource utilizationVSAvoiddata exposure risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by assigning an inactive status and locking the guest virtual machine immediately upon termination indication, before any cleanup or deletion occurs. This prevents data exposure by ensuring the machine cannot be accessed or reused while maintaining it in the environment for potential recovery

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary status indicator (active/inactive) and a locking mechanism that mediates between resource cleanup and security requirements. The inactive status acts as an intermediary state that prevents unauthorized access while the machine remains in the cloud environment, resolving the contradiction between resource utilization and data security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If formal de-provisioning and clearance processes are implemented, then data security is improved, but operational complexity increases due to lack of automated control

Engineering Contradiction:
Improvedata exposure riskVSAvoidde-provisioning process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically assigning inactive status and locking guest virtual machines when termination is indicated, without requiring manual intervention. The cloud consumer automatically triggers the security measure through their termination action, and the system automatically enforces the lock, eliminating the need for complex manual de-provisioning processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the status parameter of the guest virtual machine from active to inactive, which automatically triggers security measures. This simple parameter change drives the entire de-provisioning process, simplifying complexity by using a single status indicator to control multiple security and operational aspects

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If guest virtual machines are locked and access is prevented upon termination, then data security is improved, but adaptability deteriorates because machines cannot be re-instantiated to basic state

Engineering Contradiction:
Improvedata exposure riskVSAvoidmachine re-instantiation flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic control where the guest virtual machine status can transition between active and inactive states based on operational needs. The lock is not permanent but conditional, allowing the machine to be re-instantiated and returned to basic state when needed, while maintaining security during the dormant period

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9436832B2System and method for virtual image security in a cloud environment
Publication Date: 2016.09.06 CA TECH INC
  • US9436832B2 patent drawing
  • US9436832B2 patent drawing
  • US9436832B2 patent drawing

AI summary

Systems and methods enabling secure virtual image access in a virtual or cloud computing environment. The systems and methods include assigning a status to indicator to guest virtual machines (virtual images) that provide applications and other services to cloud consumers in the cloud environment. A virtual appliance machine in the cloud environment maintains the status of the guest virtual machines and makes decisions based on the status as to whether to allow access to the guest virtual machines. These decisions are transmitted to local elements on the guest virtual machines, which enforce access control on a local level. In this manner, unauthorized virtual image access is prevented providing increased security and data integrity.