Virtual Appliance Sealing for Secure Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for an improved method and system to manage and secure virtual machines (VMs) effectively, addressing issues such as authenticity verification and unauthorized use, especially in virtualized environments where traditional control mechanisms are bypassed by virtualization.
Innovation Solution
A method and system that involves sealing virtual appliances with a sender's signature and policies, using cryptographic keys for authentication and encryption, and managing execution based on these policies, while employing Delta files to track changes and maintain integrity, ensuring secure and controlled usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual machines are deployed in virtualized environments, then computing platform efficiency and application deployment are improved, but security control and authenticity verification deteriorate
Solution Approach 1:
The patent applies preliminary action by sealing virtual machines with cryptographic signatures and policies before deployment. The sealing process embeds authentication mechanisms and usage constraints into the VM image beforehand, enabling automatic verification upon deployment without requiring manual security checks, thus maintaining both deployment efficiency and security control
Solution Approach 2:
The patent introduces a sealing mechanism as an intermediary between the VM creator and the deployment environment. This sealing layer acts as a mediator that carries cryptographic proofs and policy information, allowing the virtualized environment to verify authenticity and enforce controls without directly managing the underlying security complexity
2Ease of operation
If virtual machines are made easily deployable and transferable, then ease of operation is improved, but vulnerability to unauthorized use increases
Solution Approach 1:
The patent applies preliminary anti-action by preemptively counteracting unauthorized use through cryptographic sealing. Before the VM can be deployed or transferred, it is sealed with the creator's private key signature and usage policies, which automatically prevent unauthorized modifications and restrict execution to approved environments, thus countering security risks before they can manifest
Solution Approach 2:
The patent changes the state of the virtual machine from unsealed to sealed, transforming its security parameters. The sealing process modifies the VM image by embedding cryptographic metadata and policy constraints, changing its properties from easily copyable to securely controlled while maintaining ease of legitimate deployment through automated verification
Data Source
AI summary
Method and system for the integrated securing and managing of virtual machines and virtual appliances are presented. Sealing the virtual appliance at the computer of a sender, verifying authenticity of the sender at a recipient computer and managing the execution of the VA are performed in a seamless fashion.


