Virtual Environment Security Management via Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise environments face challenges in managing and optimizing software services across both virtualized and non-virtualized platforms, particularly in ensuring service level agreements (SLAs) and resource allocation, leading to inefficiencies and potential service disruptions.

Innovation Solution

A system and method that employs a centralized controller and agents to manage software processes and resources, using mutual and one-way authentication for secure communication, to enforce policies and dynamically allocate resources based on SLA requirements, ensuring efficient operation and compliance with quality of service goals across diverse environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized control and management is implemented across virtualized and non-virtualized environments, then service level agreement compliance and resource optimization improve, but system complexity and deployment difficulty increase

Engineering Contradiction:
Improveservice level agreement complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized controller as an intermediary component that manages both virtualized and non-virtualized environments through a unified interface. This controller acts as a mediator between diverse computing environments and the management system, abstracting away environment-specific complexities while maintaining centralized control over resource allocation and SLA enforcement across heterogeneous platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The controller is designed with universal functionality to manage both virtualized and non-virtualized computing environments through a single system. It provides multi-functional capabilities including resource provisioning, performance monitoring, and SLA enforcement that work across different environment types, eliminating the need for separate management systems and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If mutual authentication is implemented for secure communication between agents and controller, then security is improved, but communication overhead and authentication time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by establishing secure credentials and certificates for agents before they connect to the controller. This pre-configuration of authentication materials allows for faster mutual authentication during actual communication, as the cryptographic handshaking can proceed more efficiently with pre-established trust relationships.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system implements feedback mechanisms where the controller and agents exchange verification information in a structured manner. The mutual authentication process includes feedback loops that allow for efficient verification of credentials, with the system optimizing the exchange of authentication data to minimize communication rounds and reduce overall authentication time while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9129104B2System and method of security management for a virtual environment
Publication Date: 2015.09.08 ORACLE INT CORP
  • US9129104B2 patent drawing
  • US9129104B2 patent drawing
  • US9129104B2 patent drawing

AI summary

A system and method can support security management in a computing environment that includes one or more virtualized machines to which one or more applications can be deployed. The system can include a plurality of agents, wherein each agent resides on one of a plurality of machines in the computing environment and operates to manage software processes and resources running in the computing environment. The system also includes a controller that collects data from the plurality of agents about current operating performance of the computing environment, and uses the data gathered to enforce policies and to deploy services in a way that honors one or more service level agreements of the deployed services. Furthermore, the communication between each of the plurality of agents and the controller can be secured with a mutual authentication method, and the communication between an agent and an application is secured with a one-way authentication method.