Virtualized Zone Hierarchy for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computer systems, existing access control mechanisms face challenges in maintaining fine-grained access control while utilizing virtualization features, often requiring compromises that limit either virtualization features or access control granularity.
Innovation Solution
The system implements a method and architecture that allows for the coexistence of primary and secondary zones within a global zone, enabling enhanced security features and granular access control by using unique labels and IP addresses to isolate and manage non-global zones, with the global zone controlling access and interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If traditional access control mechanisms are used in virtualized systems, then implementation simplicity is maintained, but access control granularity is limited
Solution Approach 1:
The system segments the virtualized environment into multiple zones (primary zones and secondary zones) with distinct access control policies. Each zone can have its own label and IP address configuration, allowing fine-grained access control at the zone level while maintaining overall system manageability through hierarchical organization.
Solution Approach 2:
The patent introduces a new dimension of zone hierarchy by implementing secondary zones within primary zones. This multi-level zone structure adds granularity to access control without fundamentally redesigning the entire system, allowing administrators to control access at multiple levels (global, primary, and secondary zone levels).
2Productivity
If virtualization features are fully utilized, then resource efficiency is improved, but access control granularity is limited
Solution Approach 1:
The system divides virtualized resources into isolated zones that can be independently managed. Primary zones and secondary zones provide segmented access control boundaries, allowing full utilization of virtualization features for resource efficiency while maintaining granular access control through zone-specific policies and labels.
Solution Approach 2:
The zone label acts as an intermediary mechanism between virtualization resources and access control policies. By assigning labels to zones and using these labels for access decisions, the system enables both full virtualization capabilities and fine-grained access control without direct coupling between resource management and security policies.
3Manufacturing precision
If primary zones with unique IP addresses are implemented, then access control granularity is improved, but system complexity increases
Solution Approach 1:
The patent resolves IP address conflicts by introducing a new dimension of network addressing through secondary zones. Secondary zones can share the primary zone's IP address while providing additional access control granularity, thereby increasing precision without proportionally increasing configuration complexity.
Solution Approach 2:
The nested zone structure allows secondary zones to be contained within primary zones, inheriting certain properties while maintaining independent access control. This nesting reduces configuration complexity by allowing secondary zones to leverage the primary zone's network identity while adding granular control where needed.
Data Source
AI summary
A system including a processor and a host operating system (OS) executing on the processor. The Host OS including a global zone, a first primary non-global (NG) zone associated with a first label and a first internet protocol (IP) address, where the first primary NG zone is accessible by a desktop layer of the system. The Host OS further including a second primary NG zone associated with a second label and the first IP address, wherein the second primary NG zone is accessible by the desktop layer of system. The global zone is configured to receive a first request to create a secondary NG zone with the first label, and in response to the first request, create the secondary NG zone associated with the first label and a second IP address, where the secondary NG zone is not accessible by the desktop layer of the system.


