Virtual Security Appliance Isolation for Tamper Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions for computers are either expensive and power-intensive (security appliances) or vulnerable to manipulation and have large attack surfaces (client security software), failing to provide robust and reliable protection against malicious threats.

Innovation Solution

A virtual security appliance is created using virtualization technology to run in a separate environment from the user operating system, providing intrusion detection, firewall capabilities, and antivirus tools, while ensuring tamper-resistance and self-updating capabilities to prevent unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security appliances are used to provide robust protection, then security reliability is improved, but power consumption and hardware costs increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent creates a virtual copy of the security appliance that runs in a separate virtual machine environment. This virtual security appliance replicates the security functions of a physical appliance but consumes significantly less power and hardware resources, while maintaining the same security reliability through identical security protocols and mechanisms.

Inventive Principle:
Principle #26Copying

2Ease of manufacture

If client security software is used to reduce costs, then hardware costs decrease, but vulnerability to manipulation and attack surface increase

Engineering Contradiction:
Improvehardware costsVSAvoidtamper resistance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the security software from the user operating system by running it in a separate virtual machine with isolated execution environment. This segmentation prevents manipulation from the user OS while maintaining low hardware costs, as the security functions are software-based rather than requiring physical appliance hardware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual machine environment acts as an intermediary layer between the security software and the user operating system. This intermediary provides protection and isolation, preventing direct manipulation of security software while allowing controlled communication, thus improving tamper resistance without increasing hardware costs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If security software runs within the user operating system, then ease of use and management are improved, but susceptibility to being disabled and large attack surface increase

Engineering Contradiction:
Improveease of managementVSAvoidcontinuous protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent moves security software from the same dimensional space (user OS) to a different dimensional space (separate virtual machine). This dimensional separation allows security software to be managed easily through virtualization interfaces while simultaneously protecting it from being disabled by user OS processes, ensuring continuous protection.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9104861B1Virtual security appliance
Publication Date: 2015.08.11 GEN DIGITAL INC
  • US9104861B1 patent drawing
  • US9104861B1 patent drawing
  • US9104861B1 patent drawing

AI summary

Security from malicious attack is provided for a user environment running in a virtualized environment by a virtual security appliance (VSA) running outside of the user environment, but on the same computer system as the user environment. For example, a VSA running in a virtual machine can provide security for a user environment running in a second virtual machine. The separation of the VSA from the user environment enhances the robustness of the VSA against malicious attacks seeking to disable/bypass the protections of the VSA, while avoiding the costs and complexities of a physical security appliance.