Virtual Environment Security via External Packet Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The density of virtual machines in a shared virtual environment poses challenges in securing the environment from network threats, particularly when implementing resource-intensive security policies like Deep Packet Inspection, which can burden the host platform and reduce the number of virtual machines it can support.

Innovation Solution

Offloading resource-intensive network security tasks to an external security device by using tunneling protocols to redirect packets between the host device and the external security device, allowing the host device to conserve resources and focus on virtual machine operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate virtual appliance is incorporated into the virtual environment to enforce packet-level security policies, then network security is improved, but the processing resources of the host platform are burdened, reducing the number of virtual machines that can be implemented

Engineering Contradiction:
Improvenetwork securityVSAvoidhost platform performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the resource-intensive security processing functions from the host platform and places them in an external security device. The host platform retains only lightweight security policy enforcement, while Deep Packet Inspection and other intensive operations are performed externally, resolving the contradiction between security and performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an external security device as an intermediary between the virtual environment and network traffic. This mediator handles resource-intensive security tasks without burdening the host platform, allowing the host to maintain high virtual machine density while external devices perform intensive security processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Deep Packet Inspection policies are implemented to ensure a desired level of network security, then network security is improved, but the processing resources required increase substantially, reducing the capacity of the host platform

Engineering Contradiction:
Improvenetwork securityVSAvoidhost platform capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts Deep Packet Inspection functionality from the host platform and implements it in external security devices. This allows DPI policies to be enforced without consuming host platform resources, maintaining both high security and high platform capacity for running virtual machines.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments security processing into two parts: lightweight policy enforcement on the host platform and intensive Deep Packet Inspection on external devices. This segmentation allows the host to maintain high virtual machine density while external devices handle resource-intensive inspection tasks.

Inventive Principle:
Principle #1Segmentation

3Productivity

If multiple virtual machines are implemented on a shared host platform to increase hardware utilization, then hardware utilization is improved, but the density of virtual machines creates challenges in securing the environment from network threats

Engineering Contradiction:
Improvehardware utilizationVSAvoidenvironment security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces external security devices as intermediaries that can enforce security policies across high-density virtual machine environments without being constrained by host platform resource limitations. This allows secure operation of dense virtual machine deployments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves security processing from the host platform dimension to an external dimension, allowing security capabilities to scale independently of virtual machine density. This enables both high hardware utilization and strong security enforcement.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9460289B2Securing a virtual environment
Publication Date: 2016.10.04 TREND MICRO INC
  • US9460289B2 patent drawing
  • US9460289B2 patent drawing
  • US9460289B2 patent drawing

AI summary

Securing a virtual environment includes: in a host device, intercepting a packet addressed to a virtual machine implemented by the host device; redirecting the packet to a security device external to the host device through an egress tunnel; and delivering the packet to the virtual machine if the host device receives an indication from the security device that the packet is approved.