Virtualized Zone Hierarchy for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computer systems, existing access control mechanisms face challenges in maintaining fine-grained access control while utilizing virtualization features, often requiring compromises that limit either virtualization features or access control granularity.

Innovation Solution

The system implements a method and architecture that allows for the coexistence of primary and secondary zones within a global zone, enabling enhanced security features and granular access control by using unique labels and IP addresses to isolate and manage non-global zones, with the global zone controlling access and interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If traditional access control mechanisms are used in virtualized systems, then implementation simplicity is maintained, but access control granularity is limited

Engineering Contradiction:
Improveaccess control granularityVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The system segments the virtualized environment into multiple zones (primary zones and secondary zones) with distinct access control policies. Each zone can have its own label and IP address configuration, allowing fine-grained access control at the zone level while maintaining overall system manageability through hierarchical organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of zone hierarchy by implementing secondary zones within primary zones. This multi-level zone structure adds granularity to access control without fundamentally redesigning the entire system, allowing administrators to control access at multiple levels (global, primary, and secondary zone levels).

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If virtualization features are fully utilized, then resource efficiency is improved, but access control granularity is limited

Engineering Contradiction:
Improveresource efficiencyVSAvoidaccess control granularity
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system divides virtualized resources into isolated zones that can be independently managed. Primary zones and secondary zones provide segmented access control boundaries, allowing full utilization of virtualization features for resource efficiency while maintaining granular access control through zone-specific policies and labels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The zone label acts as an intermediary mechanism between virtualization resources and access control policies. By assigning labels to zones and using these labels for access decisions, the system enables both full virtualization capabilities and fine-grained access control without direct coupling between resource management and security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If primary zones with unique IP addresses are implemented, then access control granularity is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control granularityVSAvoidconfiguration complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent resolves IP address conflicts by introducing a new dimension of network addressing through secondary zones. Secondary zones can share the primary zone's IP address while providing additional access control granularity, thereby increasing precision without proportionally increasing configuration complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The nested zone structure allows secondary zones to be contained within primary zones, inheriting certain properties while maintaining independent access control. This nesting reduces configuration complexity by allowing secondary zones to leverage the primary zone's network identity while adding granular control where needed.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8819681B2Method and system for implementing primary and secondary zones in a virtualized environment
Publication Date: 2014.08.26 ORACLE INT CORP
  • US8819681B2 patent drawing
  • US8819681B2 patent drawing
  • US8819681B2 patent drawing

AI summary

A system including a processor and a host operating system (OS) executing on the processor. The Host OS including a global zone, a first primary non-global (NG) zone associated with a first label and a first internet protocol (IP) address, where the first primary NG zone is accessible by a desktop layer of the system. The Host OS further including a second primary NG zone associated with a second label and the first IP address, wherein the second primary NG zone is accessible by the desktop layer of system. The global zone is configured to receive a first request to create a secondary NG zone with the first label, and in response to the first request, create the secondary NG zone associated with the first label and a second IP address, where the secondary NG zone is not accessible by the desktop layer of the system.