Virtual Instance Security via Service Platform Credential Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing data communications between virtual computing instances in cloud environments, such as containers and virtual machines, face challenges in providing transparent encryption without modifying the containers or virtual machines, especially when they run on different hosts.

Innovation Solution

A method and apparatus for securing data communications between virtual computing instances by creating a new virtual instance, obtaining security credentials based on its class, and using these credentials to encrypt data, which can be stored locally or remotely, and selecting the appropriate storage for credentials based on the instance's class, allowing for transparent encryption across different hosts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is implemented between virtual computing instances, then security is improved, but device complexity increases due to credential management and classification systems

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically performs instance classification and selects appropriate security credentials without manual intervention. The service platform autonomously manages the complexity of credential selection based on instance characteristics, eliminating the need for users to manually configure encryption parameters while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A service platform acts as an intermediary between virtual computing instances and the underlying security infrastructure. This intermediary automatically handles credential selection, instance classification, and encryption configuration, shielding users from the complexity of security management while ensuring proper encryption is applied.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If transparent encryption is provided without modifying containers or virtual machines, then ease of operation is improved, but the ability to secure communications between instances on different hosts is worsened

Engineering Contradiction:
Improveease of operationVSAvoidadaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The solution moves security management from the instance level to the service platform level, adding a new dimensional layer of abstraction. Instead of modifying instances directly, the service platform provides security as a separate layer that wraps around instances, enabling transparent encryption across different hosts without instance modifications.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The service platform provides universal security credentials that can be applied across multiple virtual computing instances regardless of their host location. This multi-functional approach allows the same credential management system to secure communications between instances on the same host or different hosts, providing both transparency and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11556662B2Secure communications between virtual computing instances
Publication Date: 2023.01.17 SSH COMMUNICATIONS SECURITY
  • US11556662B2 patent drawing
  • US11556662B2 patent drawing
  • US11556662B2 patent drawing

AI summary

Method and apparatus for virtualized environment where virtual computing instances interface a service platform operated on a physical computing apparatus are disclosed. A new virtual computing instance interfacing the service platform can be created, the created new virtual computing instance belonging to a class of virtual computing instances. At least one security credential is obtained from a storage of security credentials associated with the class of the new virtual computing instance. Data communicated with at least one further computing instance is secured based on the obtained at least one security credential.