Virtual Relay Device for Secure Cloud Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machines in cloud networks lack effective security measures, as they share hardware with other tenants and can be accessed by remote devices through shared networks, leading to potential data interception and unauthorized access.

Innovation Solution

Implementing a virtual device relay system that uses communities-of-interest to encrypt and isolate communications between virtual machines, allowing remote devices to access specific hosts on a shared network only through assigned virtual device relays, ensuring secure connections and data forwarding based on shared community membership.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines execute on shared hardware in a cloud network, then resource utilization is improved and cost is reduced, but security is worsened because transmissions may be intercepted by other tenants

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the shared network into multiple isolated virtual networks, each dedicated to a specific tenant. This segmentation allows multiple tenants to share the same physical infrastructure while maintaining complete isolation between their virtual networks, thus preserving security while enabling resource utilization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtual network as an intermediary layer between tenants and the shared physical network infrastructure. This virtual network acts as a mediator that enables secure communication for each tenant without exposing their transmissions to other tenants, even though they share the same physical hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a remote device connects to the shared network through a VPN tunnel, then access to virtual machines is improved, but security is worsened because the remote device may access virtual machines owned by other tenants

Engineering Contradiction:
Improveaccess to virtual machinesVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the network access by creating dedicated virtual networks for each tenant. When a remote device connects, it is assigned to a specific virtual network corresponding to its authorized tenant, preventing it from accessing virtual machines in other tenants' virtual networks even though it has VPN access to the shared infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by providing different network access characteristics to different tenants. Each tenant receives a virtual network with specific access permissions and isolation properties tailored to their needs, rather than providing uniform access to all virtual machines on the shared network.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12124563B2Virtual relay device for providing a secure connection to a remote device
Publication Date: 2024.10.22 UNISYS CORP
  • US12124563B2 patent drawing
  • US12124563B2 patent drawing
  • US12124563B2 patent drawing

AI summary

Virtual machines in a network may be isolated by encrypting transmissions between the virtual machines with keys possessed only by an intended recipient. Within a network, the virtual machines may be logically organized into a number of community-of-interest (COI) groups. Each COI may use an encryption key to secure communications within the COI, such that only other virtual machines in the COI may decrypt the message. Remote devices may gain access to virtual machines in a network through a virtual device relay. The virtual device relay receives data from the remote device, such as a tablet or cellular phone, and forwards the data to one of the virtual machines, when the virtual device relay shares a COI with the destination virtual machine.