Virtual Machine Isolation for Untrusted Code Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for electronic devices are inefficient in allowing users to install untrusted executable code without compromising the device's security, as administrators may not verify the usefulness or trustworthiness of such code, leading to potential malware detection delays and reduced user productivity.

Innovation Solution

Implementing a virtual machine system that allows users to test untrusted executable code in an isolated environment, monitored by a processor to detect malware and determine trustworthiness, enabling users to access code that enhances work performance while maintaining security by generating reports and terminating malicious installations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators perform testing to determine trustworthiness of untrusted executable code, then security is improved, but user productivity deteriorates due to delayed access to useful code

Engineering Contradiction:
ImprovesecurityVSAvoiduser productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the code review process by separating administrative security approval from user-level testing. Users can install untrusted code in virtual machines without administrator approval, while administrators retain the ability to review and approve code through the enterprise allowlist system. This segmentation resolves the contradiction by enabling users to access useful code immediately while administrators can still perform security testing independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual machine acts as an intermediary environment between untrusted executable code and the host system. By isolating code execution in a virtualized environment, users can test potentially malicious code without compromising the host system's security. This intermediary approach allows productivity improvement through faster code access while maintaining security through isolated testing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If users are enabled to install untrusted executable code without verification, then user productivity is improved, but security deteriorates due to potential malware installation

Engineering Contradiction:
Improveuser productivityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The virtual machine serves as an intermediary layer that enables users to install and execute untrusted code without direct access to the host system. The virtualization environment provides isolation, allowing productive use of untrusted code while preventing malware from compromising the host system. This resolves the contradiction by decoupling productivity needs from security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The virtual machine creates an inert or isolated environment for executing untrusted code, analogous to performing chemical reactions in a controlled atmosphere. This isolated environment allows users to freely install and test code without the harmful effects (malware) affecting the host system, thereby enabling productivity while maintaining security.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Reliability

If virtual machine isolation is implemented for testing untrusted code, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual machine platform provides multi-functionality by serving as both a security isolation mechanism and a code testing environment. Rather than implementing separate systems for security and testing, the virtual machine performs both functions simultaneously, reducing overall system complexity while maintaining security improvements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11983263B2Virtual machines to install untrusted executable codes
Publication Date: 2024.05.14 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US11983263B2 patent drawing
  • US11983263B2 patent drawing
  • US11983263B2 patent drawing

AI summary

In some examples, an electronic device includes a processor to allow installation of an untrusted executable code to a virtual machine, monitor the installation and execution of the untrusted executable code, and, responsive to a determination that an executed amount of the untrusted executable code is less than a threshold amount, prompt a user to continue the execution of the untrusted executable code.