Virtualized Ecosystem Security Control via Embedded Blocks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualization technologies introduce security risks due to relaxed controls, portability of virtual machines, and dynamic resource allocation, making it challenging to ensure security and compliance in virtualized ecosystems.

Innovation Solution

A security control system that defines and analyzes object handling control information to derive object properties for logical resources in a virtualized ecosystem, enforcing controls through embedded control blocks and validating digital signatures to manage interactions and protect virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtualization technology is implemented to enable dynamic resource allocation and portability, then flexibility and adaptability are improved, but security control and reliability deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments security controls into embedded control blocks that are attached to individual virtual objects (virtual machines, disks, networks). Each control block contains specific security policies and rules that apply to that object, allowing granular security management across the virtualized environment without compromising overall system flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces control blocks as intermediary elements between the virtualization layer and security requirements. These control blocks act as mediators that enforce security policies on virtual objects without interfering with the dynamic resource allocation and portability benefits of virtualization. The control blocks translate high-level security requirements into enforceable rules.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If dynamic resource allocation is implemented for virtual machines, then productivity and adaptability are improved, but control precision and security monitoring worsen

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidcontrol precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by embedding control blocks with security policies before virtual objects are created or deployed. The control blocks are pre-configured with the necessary security rules and constraints, ensuring that control precision is maintained from the outset rather than attempting to impose controls on already-deployed dynamic resources.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent makes security controls dynamic by associating control blocks with virtual objects that can be dynamically created, moved, and destroyed. The control blocks automatically travel with their associated virtual objects, maintaining control precision regardless of the dynamic state changes. This allows security monitoring to keep pace with resource allocation dynamics.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If portability of virtual machines is enabled through encapsulation, then adaptability and ease of operation are improved, but security risks and vulnerability to harmful factors increase

Engineering Contradiction:
ImproveportabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies the nested doll principle by embedding control blocks within the encapsulated virtual machine images. The control blocks are nested inside the virtual object structure, ensuring that security controls are portable along with the virtual machine. When virtual machines are moved or copied, their embedded control blocks travel with them, maintaining security protections across portable operations.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent applies preliminary anti-action by pre-configuring control blocks with security policies that prevent harmful actions before they can occur. The control blocks contain rules that proactively block unauthorized access, prevent malicious modifications, and restrict dangerous operations on virtual objects, countering security risks before they manifest.

Inventive Principle:
Principle #9Preliminary anti-action

4Adaptability or versatility

If multiple logical resources are virtualized and managed separately, then adaptability and customization are improved, but device complexity and difficulty of management increase

Engineering Contradiction:
ImprovecustomizationVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized control block structure that can be applied to multiple types of virtual objects (virtual machines, disks, networks, storage). The same control block mechanism serves multiple security functions across different resource types, reducing management complexity while maintaining customization capabilities. The universal control block framework handles diverse resources through a common interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8832784B2Intelligent security control system for virtualized ecosystems
Publication Date: 2014.09.09 ENTRUST CORP
  • US8832784B2 patent drawing
  • US8832784B2 patent drawing
  • US8832784B2 patent drawing

AI summary

Resources of a virtualized ecosystem are intelligently secured by defining and analyzing object handling security control information for one or more logical resources in the virtualized ecosystem and deriving therefrom object properties for each of the logical resources involved in the execution of a virtual machine in any given context within the virtualized ecosystem.