Virtual Environment Security Management via Intermediary Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In container-type virtualization technologies, there is a need to dynamically manage the execution authority of applications across multiple virtual environments, while ensuring security by checking the virtual environment's security settings, which can lead to vulnerabilities if unauthorized processing occurs within the virtual environment.
Innovation Solution
An information processing apparatus that includes managers to manage virtual environments and a management controller to control these managers. When software execution is detected in a virtual environment, the management controller instructs the corresponding manager to determine whether to execute the software based on a security file stored within the virtual environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the host reads security files stored in virtual environments, then security management flexibility is improved, but system vulnerability increases due to potential unauthorized processing
Solution Approach 1:
The patent introduces a file access management unit as an intermediary between the host file reading unit and virtual environment files. This intermediary component intercepts file access requests from the host, validates them against security policies, and either permits or blocks access accordingly. This resolves the contradiction by enabling flexible security management through host file reading while preventing unauthorized processing that would create vulnerabilities.
Solution Approach 2:
The system implements a feedback mechanism where the file access management unit continuously monitors file access requests, checks them against stored security policies, and dynamically controls access based on the validation results. This feedback loop ensures that security management remains flexible and adaptive while maintaining system security by blocking potentially harmful access attempts.
2Measurement precision
If execution authority is dynamically managed for each virtual environment, then security control precision is improved, but system complexity increases
Solution Approach 1:
The patent segments the security management functionality into distinct modular components: a file access management unit, a host file reading unit, and security policy storage. Each component has a specific responsibility, which simplifies the overall system architecture while enabling precise security control for each virtual environment. This segmentation resolves the contradiction by achieving high security control precision without excessive system complexity.
Solution Approach 2:
The system implements self-service mechanisms where the file access management unit automatically validates file access requests against stored security policies without requiring external intervention. This automation maintains precise security control while reducing the operational complexity of managing multiple virtual environment permissions manually.
Data Source
AI summary
An information processing apparatus includes one or more managers that manage one or more virtual environments, and a management controller that controls the one or more managers. When the execution of the software is detected in any of the one or more virtual environments, the management controller instructs the manager that manages the detected virtual environment to determine whether to execute the software in the detected virtual environment. The manager reads a file stored in the detected virtual environment, and determines whether to execute the software in the detected virtual environment based on information indicated in the file.


