Secured Virtual Environment Integrity Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern enterprise systems face challenges in securing business data as employees access it from various locations, with malicious software compromising IHSs, leading to data theft and ransomware threats, making it difficult to balance employee productivity with data protection.

Innovation Solution

A method is implemented on Information Handling Systems (IHS) to host a secured virtual environment by accessing policies stored in a secured memory, validating the integrity of the IHS through a trusted resource, configuring a virtual environment for secure data access, and periodically confirming the integrity and policy changes, with the virtual environment isolating secured data from the operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If employees access business data from various locations using different IHSs, then employee productivity is improved, but the risk of data compromise and security breaches increases

Engineering Contradiction:
Improveemployee productivityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the virtual environment into isolated containers that run on any employee's IHS. Each virtual environment is a self-contained unit with its own policy set, separating secured data and applications from the host operating system and other applications. This allows employees to access business data from any location while maintaining security boundaries that prevent compromise of the underlying system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted resource as an intermediary between the employee's IHS and the secured data. This trusted resource validates the integrity of the IHS and the virtual environment before allowing access to secured data. The intermediary layer ensures that even if the employee's IHS is compromised, the secured data remains protected by the verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional security measures are implemented to protect business data, then data protection is improved, but employee productivity and data accessibility are reduced

Engineering Contradiction:
Improvedata protectionVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts security verification based on the context. The trusted resource periodically revalidates the integrity of the IHS and virtual environment during runtime, rather than requiring constant user authentication or restricting access. This dynamic approach maintains strong security while allowing employees to work productively without frequent interruptions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the security parameter from static access control to dynamic integrity verification. Instead of restricting data access based on user credentials alone, the system continuously monitors and verifies the integrity state of the IHS and virtual environment. This parameter change enables broad data accessibility while maintaining protection through automated verification rather than restrictive policies.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If integrity validation is performed continuously to ensure security, then security reliability is improved, but system performance and operational speed are reduced

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The trusted resource performs integrity validation periodically rather than continuously. The system revalidates the integrity of the IHS and virtual environment at scheduled intervals during runtime, rather than constantly monitoring every operation. This periodic approach maintains high security reliability while minimizing performance overhead by conducting verification at appropriate intervals rather than every transaction.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11750654B2Integrity assurance of a secured virtual environment
Publication Date: 2023.09.05 DELL PROD LP
  • US11750654B2 patent drawing
  • US11750654B2 patent drawing
  • US11750654B2 patent drawing

AI summary

Embodiments provide access to enterprise data via a secured virtual environment hosted on an Information Handling System (IHS), with the integrity of the IHS validated prior to launching the virtual environment. The integrity of the IHS may also be continuously validated during operation of the launched virtual environment. Policies for accessing the enterprise data are stored in a secured memory that is isolated from the operating system of the IHS. A virtual environment is configured, according to the policies, with resources for a particular user to access the enterprise data. If the integrity of the IHS is validated by a trusted resource on the IHS, the virtual environment is launched. During operation of the virtual environment, the trusted resource periodically confirms the integrity of the IHS. If the integrity of the IHS is not verified or policy changes are identified, access to the secured workspace may be revoked.