Virtual Appliance Sealing for Secure Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for an improved method and system to manage and secure virtual machines (VMs) effectively, addressing issues such as authenticity verification and unauthorized use, especially in virtualized environments where traditional control mechanisms are bypassed by virtualization.

Innovation Solution

A method and system that involves sealing virtual appliances with a sender's signature and policies, using cryptographic keys for authentication and encryption, and managing execution based on these policies, while employing Delta files to track changes and maintain integrity, ensuring secure and controlled usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are deployed in virtualized environments, then computing platform efficiency and application deployment are improved, but security control and authenticity verification deteriorate

Engineering Contradiction:
Improveapplication deployment efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by sealing virtual machines with cryptographic signatures and policies before deployment. The sealing process embeds authentication mechanisms and usage constraints into the VM image beforehand, enabling automatic verification upon deployment without requiring manual security checks, thus maintaining both deployment efficiency and security control

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a sealing mechanism as an intermediary between the VM creator and the deployment environment. This sealing layer acts as a mediator that carries cryptographic proofs and policy information, allowing the virtualized environment to verify authenticity and enforce controls without directly managing the underlying security complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If virtual machines are made easily deployable and transferable, then ease of operation is improved, but vulnerability to unauthorized use increases

Engineering Contradiction:
Improvedeployment easeVSAvoidunauthorized use risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preemptively counteracting unauthorized use through cryptographic sealing. Before the VM can be deployed or transferred, it is sealed with the creator's private key signature and usage policies, which automatically prevent unauthorized modifications and restrict execution to approved environments, thus countering security risks before they can manifest

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent changes the state of the virtual machine from unsealed to sealed, transforming its security parameters. The sealing process modifies the VM image by embedding cryptographic metadata and policy constraints, changing its properties from easily copyable to securely controlled while maintaining ease of legitimate deployment through automated verification

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8549313B2Method and system for integrated securing and managing of virtual machines and virtual appliances
Publication Date: 2013.10.01 FLEXERA SOFTWARE LLC
  • US8549313B2 patent drawing
  • US8549313B2 patent drawing
  • US8549313B2 patent drawing

AI summary

Method and system for the integrated securing and managing of virtual machines and virtual appliances are presented. Sealing the virtual appliance at the computer of a sender, verifying authenticity of the sender at a recipient computer and managing the execution of the VA are performed in a seamless fashion.