Virtual Environment Security via External Packet Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The density of virtual machines in a shared virtual environment poses challenges in securing the environment from network threats, particularly when implementing resource-intensive security policies like Deep Packet Inspection, which can burden the host platform and reduce the number of virtual machines it can support.
Innovation Solution
Offloading resource-intensive network security tasks to an external security device by using tunneling protocols to redirect packets between the host device and the external security device, allowing the host device to conserve resources and focus on virtual machine operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate virtual appliance is incorporated into the virtual environment to enforce packet-level security policies, then network security is improved, but the processing resources of the host platform are burdened, reducing the number of virtual machines that can be implemented
Solution Approach 1:
The patent extracts the resource-intensive security processing functions from the host platform and places them in an external security device. The host platform retains only lightweight security policy enforcement, while Deep Packet Inspection and other intensive operations are performed externally, resolving the contradiction between security and performance.
Solution Approach 2:
The patent introduces an external security device as an intermediary between the virtual environment and network traffic. This mediator handles resource-intensive security tasks without burdening the host platform, allowing the host to maintain high virtual machine density while external devices perform intensive security processing.
2Reliability
If Deep Packet Inspection policies are implemented to ensure a desired level of network security, then network security is improved, but the processing resources required increase substantially, reducing the capacity of the host platform
Solution Approach 1:
The patent extracts Deep Packet Inspection functionality from the host platform and implements it in external security devices. This allows DPI policies to be enforced without consuming host platform resources, maintaining both high security and high platform capacity for running virtual machines.
Solution Approach 2:
The patent segments security processing into two parts: lightweight policy enforcement on the host platform and intensive Deep Packet Inspection on external devices. This segmentation allows the host to maintain high virtual machine density while external devices handle resource-intensive inspection tasks.
3Productivity
If multiple virtual machines are implemented on a shared host platform to increase hardware utilization, then hardware utilization is improved, but the density of virtual machines creates challenges in securing the environment from network threats
Solution Approach 1:
The patent introduces external security devices as intermediaries that can enforce security policies across high-density virtual machine environments without being constrained by host platform resource limitations. This allows secure operation of dense virtual machine deployments.
Solution Approach 2:
The patent moves security processing from the host platform dimension to an external dimension, allowing security capabilities to scale independently of virtual machine density. This enables both high hardware utilization and strong security enforcement.
Data Source
AI summary
Securing a virtual environment includes: in a host device, intercepting a packet addressed to a virtual machine implemented by the host device; redirecting the packet to a security device external to the host device through an egress tunnel; and delivering the packet to the virtual machine if the host device receives an indication from the security device that the packet is approved.


