Virtual Media Device for Secure VM Credential Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for communicating credential information to virtual machines (VMs) either require significant management overhead or compromise security, making it difficult to access and communicate with applications running in VM environments effectively.

Innovation Solution

A virtual media device is used to communicate information from outside a VM to applications within, employing a media image that is mounted and managed by an agent running in the VM, allowing secure and efficient transfer of messages and commands without exposing credential information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credential information is communicated to the VM using existing methods, then the application can access the guest OS and communicate with applications, but management overhead increases or security is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a virtual media device as an intermediary component between the host system and the VM guest OS. This virtual media device enables communication and credential verification without requiring direct exposure of credential information to the VM, thereby maintaining security while reducing management overhead. The virtual media device acts as a secure mediator that facilitates the necessary interactions without compromising the credential information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If credential information is exposed to communicate with VM applications, then communication is enabled, but security is compromised

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The virtual media device serves as a secure intermediary that enables communication with VM applications without exposing credential information. It mediates the authentication process by presenting credentials in a controlled manner, allowing the application to communicate with the VM while the actual credential information remains protected from exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses a virtual media device that can present a copy or representation of the credential information without exposing the actual credentials. The virtual media device creates a secure copy that can be used for authentication and communication purposes while the original credential information remains safeguarded and inaccessible to the VM environment.

Inventive Principle:
Principle #26Copying

3Ease of operation

If management overhead is reduced, then ease of operation improves, but the ability to securely manage credential information may be compromised

Engineering Contradiction:
Improvemanagement overheadVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The virtual media device implements self-service capabilities by automatically managing the credential information presentation and verification process. Once configured, the system can autonomously handle authentication and communication without requiring extensive manual management, thereby reducing management overhead while maintaining security through automated controlled access mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10467034B1Performing application specific actions without in-guest credential information
Publication Date: 2019.11.05 EMC IP HLDG CO LLC
  • US10467034B1 patent drawing
  • US10467034B1 patent drawing
  • US10467034B1 patent drawing

AI summary

Disclosed are systems and methods for using a virtual media device to communicate messages to one or more applications running in a virtual machine (VM) without the need to expose credential information. Based on a media image having been mounted on a virtual media device of the VM, a notification may be generated to enable an agent in the VM to access the media image. The media image may include a message for one or more applications running in the VM. The agent may be configured to retrieve the message and to communicate the message to the one or more applications to enable the one or more applications to perform operations based on the message. The agent may be configured to eject the virtual media device based on completion of the operations.