Virtual Instance Enrollment via Privilege Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The growing popularity of cloud-based services has led to significant security vulnerabilities, particularly in virtualized environments, where privileged virtual instances can escape and penetrate host systems, causing harm. Current approaches are insufficient in detecting such risks before malicious activity occurs, and there is a need for solutions to identify and control privileged instances to prevent harm and manage secure access.

Innovation Solution

The solution involves performing a privileged configuration inspection on virtualized execution instances to identify attributes that allow them to access host systems, implementing control actions to prevent unauthorized access, and dynamically enrolling instances based on their privilege level, using cryptographic keys for secure communication and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access is provided to running virtual instances via host system commands, then operational functionality is enabled, but security vulnerabilities increase allowing privilege escalation

Engineering Contradiction:
Improveaccess to virtual instancesVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary access mechanism that mediates between the host system and virtual instances. Instead of direct access via host commands, a controlled intermediary layer manages connections, allowing operational functionality while preventing direct privilege escalation paths to the host system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access control mechanism by introducing distinct access paths: one for virtual instance operations and another for host system operations. This segmentation prevents confusion between privilege levels and eliminates the security vulnerability where virtual instance access could escalate to host system access.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If immutable virtual instances are used to prevent security risks, then security is improved, but system operational flexibility deteriorates

Engineering Contradiction:
Improvesecurity risksVSAvoidsystem operational flexibility
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control that adapts based on the virtual instance's privilege level. Non-privileged instances receive automated enrollment with restricted access, while privileged instances undergo manual review and receive controlled access. This dynamic approach maintains security while enabling operational flexibility where needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the access control parameters based on the virtual instance configuration. By detecting privilege levels and adjusting access policies accordingly, the system maintains security for high-privilege instances while allowing operational flexibility for low-privilege instances through automated enrollment and SSH key-based access.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If automated enrollment is implemented for virtual instances, then deployment efficiency is improved, but security control deteriorates

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent changes the enrollment parameter based on detected privilege levels. Non-privileged instances trigger automated enrollment with SSH key provisioning for efficient deployment, while privileged instances trigger manual review workflows. This parameter-based differentiation maintains both deployment efficiency and security control.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies different enrollment qualities to different virtual instances based on their privilege levels. Non-privileged instances receive streamlined automated enrollment, while privileged instances receive enhanced manual review. This local quality differentiation ensures security control is applied where needed without compromising overall deployment efficiency.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10735430B1Systems and methods for dynamically enrolling virtualized execution instances and managing secure communications between virtualized execution instances and clients
Publication Date: 2020.08.04 CYBER ARK SOFTWARE LTD
  • US10735430B1 patent drawing
  • US10735430B1 patent drawing
  • US10735430B1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for dynamically analyzing and enrolling virtualized execution instances. Techniques include identifying a request for enrollment for a virtualized execution instance configured to be deployed on a host in a virtual computing environment, the request including a result of a privileged configuration inspection for the virtualized execution instance; determining, based on the result of the privileged configuration inspection, to automatically enroll the virtualized execution instance; and including the virtualized execution instance in a group of enrolled virtualized execution instances, the group being available for secure communications with one or more clients in a manner that is isolated from the host.