Virtual Environment Data Protection Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods are inadequate in preventing data leakage, especially when insiders attempt to leak data, as they struggle to keep pace with the diversification of leakage points and external devices, limiting their effectiveness.
Innovation Solution
A data protection method and apparatus that utilize a virtual environment to process input and output operations, creating a virtual data storage unit accessible only within the virtual environment, and applying encryption and decryption based on predefined security rules to prevent unauthorized data access and leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in the local environment of a computer, then data accessibility and user convenience are improved, but data security and protection against leakage are worsened
Solution Approach 1:
The system segments the storage environment into a virtual environment and a local environment. Data is stored in a virtual data storage unit within the virtual environment, which is isolated from the local file system. This segmentation allows data to be accessible within the virtual environment while being protected from unauthorized access in the local environment.
Solution Approach 2:
A virtualization layer acts as an intermediary between the application program and the local file system. The virtual data storage unit provides an interface that appears like a local drive to the application, but all data operations are actually performed within the protected virtual environment, preventing direct access to local files.
2Reliability
If traditional data protection methods are used to block leakage points, then data transmission protection is improved, but adaptability to diverse leakage points and external devices is worsened
Solution Approach 1:
The invention extracts data operations from the local environment and relocates them to a dedicated virtual environment. By taking out data storage and processing from the general-purpose local file system, the system creates a specialized protected space that inherently prevents data leakage through traditional leakage points such as USB ports, network connections, and other external devices.
Solution Approach 2:
The system establishes a protected virtual environment before any data operations occur. By pre-configuring the virtual data storage unit and isolating it from the local environment, the system proactively prevents potential data leakage paths rather than reacting to threats after they occur. This preliminary protective measure covers all possible leakage points without requiring specific countermeasures for each device.
3Reliability
If a virtual environment is constructed to protect data, then data security is improved, but system complexity and implementation difficulty are worsened
Solution Approach 1:
The virtualization layer provides multiple functions through a single unified interface. It simultaneously achieves data protection, creates an isolated execution environment, manages data encryption/decryption, and presents a familiar file system interface to applications. This multi-functionality reduces the need for separate complex security mechanisms while achieving comprehensive protection.
Data Source
AI summary
The present invention relates to a method and apparatus for protecting data using a virtual environment, which creates a safe virtual environment that supports the execution of application programs being operated on a computer and which enables important data to be inputted or outputted only within the virtual environment, such that access to the important data is prevented in a general local environment. According to the present invention, data leakage is initially prevented to protect data, and convenience is provided in that a user may use the computer in a general manner while performing desired work.


