Virtual Keyboard Isolation for VM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machines are vulnerable to malware, particularly in sensitive applications like banking, where malware can compromise the security of user input and data.

Innovation Solution

The implementation of virtual keyboards displayed on separate electronic devices from the virtual machines, which provide user input to the virtual machines without displaying any information related to the virtual machines on the second devices, thereby reducing the effectiveness of malware loggers on the first devices. This includes using dedicated virtual keyboards or applications that authenticate with each virtual machine and send encrypted keypresses, ensuring that user input is isolated from potential malware infections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtual machines are used for sensitive applications like banking, then user convenience and access are improved, but vulnerability to malware compromises security

Engineering Contradiction:
Improveuser access to virtual machinesVSAvoidmalware compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the user interaction interface by providing a virtual keyboard on a separate electronic device (second device) distinct from the virtual machine display device (first device). This separation isolates the input mechanism from potential malware on the first device, allowing users to interact with virtual machines securely without exposing input methods to malware infections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual keyboard acts as an intermediary component between the user and the virtual machine. Instead of direct keyboard input on the same device as the virtual machine, the virtual keyboard on the second device mediates the input transmission, encrypting and forwarding keypresses to the virtual machine through a secure channel, thereby preventing malware on the first device from capturing input data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If virtual keyboards are provided on the same device as virtual machines, then ease of operation is improved, but effectiveness of malware loggers increases

Engineering Contradiction:
Improveinput control convenienceVSAvoidmalware logger effectiveness
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system divides the input-output relationship into separate components: the virtual machine runs on the first electronic device while the virtual keyboard operates on a second electronic device. This spatial segmentation prevents malware loggers on the first device from capturing keyboard input, as the input generation and transmission occur on a separate, isolated device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual keyboard functionality is extracted from the first electronic device and relocated to a second electronic device. This extraction removes the input mechanism from the potential malware infection environment, isolating it from malware loggers while preserving the ability to control the virtual machine through encrypted communication channels.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If display information related to virtual machines is shown on the same device as input, then user interface simplicity is improved, but security against malware loggers deteriorates

Engineering Contradiction:
Improveinterface simplicityVSAvoidmalware logger capture
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system segments the display and input functions across different devices: the virtual machine interface and display information are presented on the first electronic device, while the virtual keyboard input mechanism operates on a second electronic device. This segmentation prevents malware loggers from capturing both display information and input simultaneously, as they would need to operate on both devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual keyboard on the second device serves as an intermediary that receives user input and transmits it securely to the virtual machine on the first device. This intermediary layer separates the display information (on the first device) from the input mechanism (on the second device), preventing malware loggers from capturing input data even though the virtual machine interface is visible on the first device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11893145B2Virtual machines—computer implemented security methods and systems
Publication Date: 2024.02.06 BANKVAULT PTY LTD
  • US11893145B2 patent drawing
  • US11893145B2 patent drawing
  • US11893145B2 patent drawing

AI summary

In one preferred form of the present invention, show in in FIGS. 1 to 3, there is provided a computer implemented security method (10) comprising: providing users (14) with first virtual machines (12), the first virtual machines (12) for being displayed on first electronic devices (18); and providing the users with virtual keyboards (22), the virtual keyboards (22) for providing user input to control the first virtual machines (12), the virtual keyboards (22) for being displayed on second electronic devices (24) that are different to the first electronic devices (18) to reduce the effectiveness of possible malware loggers on the first electronic devices (18).