Concealing Customer Data in Virtual Computing via Gateway Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers are hesitant to transition to virtual computing environments due to concerns about exposing sensitive information, as application and object names may be exposed to the virtual control plane, leading to security and compliance issues.

Innovation Solution

A computing platform receives an object with an object name from a user device, hashes or encrypts it, and transmits a concealed object name to a virtual computing platform, ensuring sensitive data is protected and only revealed when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers use virtual computing arrangements, then computing service functionality is improved, but sensitive information exposure risk increases

Engineering Contradiction:
Improvevirtual computing service functionalityVSAvoidsensitive information exposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A gateway server is introduced as an intermediary component between the virtual computing environment and external networks. This gateway server intercepts, monitors, and controls all data flows, applying security policies to prevent sensitive information from leaving the virtual environment while still allowing necessary computing operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the virtual computing environment into isolated components with controlled communication channels. By dividing the environment into separate virtual machines, containers, or sandboxes with defined boundaries, the system allows computing functionality while restricting sensitive data exposure through enforced isolation boundaries.

Inventive Principle:
Principle #1Segmentation

2Reliability

If sensitive data is concealed in virtual computing arrangements, then security is improved, but data access complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddata access complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the gateway server continuously monitors data access requests, evaluates them against security policies, and provides real-time decisions on whether to allow or block access. This automated feedback loop maintains security while reducing the complexity of manual access control management.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The virtual computing environment is configured with self-service capabilities where applications and services automatically adhere to security policies without requiring manual intervention. The system autonomously manages data concealment and access control, reducing the operational complexity of maintaining security while preserving reliable access for authorized operations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11062049B2Concealment of customer sensitive data in virtual computing arrangements
Publication Date: 2021.07.13 CITRIX SYSTEMS INC
  • US11062049B2 patent drawing
  • US11062049B2 patent drawing
  • US11062049B2 patent drawing

AI summary

Aspects described herein are directed to the concealment of customer sensitive data in virtual computing arrangements. A local computing platform may receive an object including a customer sensitive object name from a user computing device operating on a same internal domain as the local computing platform. The local computing platform may conceal the customer sensitive object name from a virtual computing platform operating on a domain external from the internal domain. The local computing platform may provide the concealed object name to the virtual computing platform for facilitating object enumeration requests from the user computing device during virtual computing sessions. During a virtual computing session between the user computing device and virtual computing platform, the local computing platform may receive the concealed object name from the user computing device and may perform one or more operations to reveal the object name to the user computing device.