Virtual Keyboard Isolation for VM Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual machines are vulnerable to malware, particularly in sensitive applications like banking, where malware can compromise the security of user input and data.
Innovation Solution
The implementation of virtual keyboards displayed on separate electronic devices from the virtual machines, which provide user input to the virtual machines without displaying any information related to the virtual machines on the second devices, thereby reducing the effectiveness of malware loggers on the first devices. This includes using dedicated virtual keyboards or applications that authenticate with each virtual machine and send encrypted keypresses, ensuring that user input is isolated from potential malware infections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If virtual machines are used for sensitive applications like banking, then user convenience and access are improved, but vulnerability to malware compromises security
Solution Approach 1:
The system segments the user interaction interface by providing a virtual keyboard on a separate electronic device (second device) distinct from the virtual machine display device (first device). This separation isolates the input mechanism from potential malware on the first device, allowing users to interact with virtual machines securely without exposing input methods to malware infections.
Solution Approach 2:
The virtual keyboard acts as an intermediary component between the user and the virtual machine. Instead of direct keyboard input on the same device as the virtual machine, the virtual keyboard on the second device mediates the input transmission, encrypting and forwarding keypresses to the virtual machine through a secure channel, thereby preventing malware on the first device from capturing input data.
2Ease of operation
If virtual keyboards are provided on the same device as virtual machines, then ease of operation is improved, but effectiveness of malware loggers increases
Solution Approach 1:
The system divides the input-output relationship into separate components: the virtual machine runs on the first electronic device while the virtual keyboard operates on a second electronic device. This spatial segmentation prevents malware loggers on the first device from capturing keyboard input, as the input generation and transmission occur on a separate, isolated device.
Solution Approach 2:
The virtual keyboard functionality is extracted from the first electronic device and relocated to a second electronic device. This extraction removes the input mechanism from the potential malware infection environment, isolating it from malware loggers while preserving the ability to control the virtual machine through encrypted communication channels.
3Device complexity
If display information related to virtual machines is shown on the same device as input, then user interface simplicity is improved, but security against malware loggers deteriorates
Solution Approach 1:
The system segments the display and input functions across different devices: the virtual machine interface and display information are presented on the first electronic device, while the virtual keyboard input mechanism operates on a second electronic device. This segmentation prevents malware loggers from capturing both display information and input simultaneously, as they would need to operate on both devices.
Solution Approach 2:
The virtual keyboard on the second device serves as an intermediary that receives user input and transmits it securely to the virtual machine on the first device. This intermediary layer separates the display information (on the first device) from the input mechanism (on the second device), preventing malware loggers from capturing input data even though the virtual machine interface is visible on the first device.
Data Source
AI summary
In one preferred form of the present invention, show in in FIGS. 1 to 3, there is provided a computer implemented security method (10) comprising: providing users (14) with first virtual machines (12), the first virtual machines (12) for being displayed on first electronic devices (18); and providing the users with virtual keyboards (22), the virtual keyboards (22) for providing user input to control the first virtual machines (12), the virtual keyboards (22) for being displayed on second electronic devices (24) that are different to the first electronic devices (18) to reduce the effectiveness of possible malware loggers on the first electronic devices (18).


