Virtual Image Management via Encrypted Privilege Descriptions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a lack of secure methods to manage the life cycle of virtual images outside specialized environments, as existing technologies do not provide effective controls for access and usage privileges, making it difficult to control alteration and cloning of virtual images.

Innovation Solution

The solution involves creating a virtual image, defining usage privileges in a description file, encrypting the file, generating a coded summary, and associating it with the image, allowing hypervisors to authenticate and grant access based on these privileges, thus enabling secure management of virtual images across various environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtual images are made freely accessible and modifiable, then ease of operation and versatility improve, but security and control over the virtual image life cycle deteriorate

Engineering Contradiction:
Improveaccessibility of virtual imagesVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-defining usage privileges and creating a coded summary of the virtual image's authorized operations before the image is accessed or modified. This coded summary acts as a pre-established control mechanism that hypervisors can authenticate, ensuring that security policies are embedded in advance rather than enforced reactively, thus maintaining both accessibility and security control.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If controls for altering and cloning virtual images are implemented, then security improves, but device complexity and ease of operation worsen

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses copying by creating a coded summary (a simplified representation) of the virtual image's usage privileges and metadata. This coded summary can be independently authenticated and verified without requiring access to the full virtual image or complex security infrastructure, thereby reducing system complexity while maintaining security controls for alteration and cloning.

Inventive Principle:
Principle #26Copying

3Reliability

If coded summaries and encrypted description files are associated with virtual images, then security and reliability improve, but device complexity and processing requirements worsen

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies taking out by extracting the essential security information (usage privileges and authentication data) from the full virtual image and placing it into a separate, lightweight coded summary. This extracted summary can be authenticated independently by hypervisors without requiring complex processing of the entire virtual image, thus improving security while minimizing processing overhead and system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8479015B2Virtual image management
Publication Date: 2013.07.02 ORACLE INT CORP
  • US8479015B2 patent drawing
  • US8479015B2 patent drawing
  • US8479015B2 patent drawing

AI summary

Apparatus, systems, and methods may operate to create a virtual image, define usage privileges associated with the virtual image in a description file, and associate a coded summary of an encrypted version of the description file with the virtual image. Other activities may include receiving a request to access the virtual image, authenticating a transmitted version of the coded summary to determine validity of the encrypted version, and processing the encrypted version to determine whether the request to access will be granted. Additional apparatus, systems, and methods are disclosed.