Virtualization Control Layer Security Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualization platforms face significant security risks due to relaxed controls and increased flexibility, which can lead to unauthorized access, resource manipulation, and malicious attacks, necessitating stringent security measures to protect sensitive data and infrastructure.

Innovation Solution

A control layer is introduced that proxies virtualization management commands, authenticates users, and enforces access control policies, ensuring only authorized commands are executed, and provides centralized monitoring and logging to detect potential threats and maintain compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtualization platforms are managed remotely through software with relaxed controls, then ease of operation and adaptability are improved, but security risks and vulnerability to unauthorized access increase

Engineering Contradiction:
Improveremote management capabilityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a control layer as an intermediary component positioned between management clients and virtualization platforms. This control layer acts as a security mediator that authenticates users, authorizes commands, and proxies management operations, thereby maintaining remote management capabilities while blocking unauthorized access and malicious commands before they reach the virtualization platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the virtualization management architecture into distinct functional layers: management clients, a control layer for security enforcement, and virtualization platforms. This segmentation isolates the security control functions from the operational virtualization functions, allowing remote management to continue while security policies are enforced independently at the control layer boundary.

Inventive Principle:
Principle #1Segmentation

2Productivity

If virtualization platforms allow flexible resource allocation and dynamic management, then productivity and adaptability improve, but control over resource access and manipulation deteriorates

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidcontrol over resource access
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The control layer performs preliminary authentication and authorization actions before allowing management operations to proceed. Users must be authenticated and their commands authorized by the control layer before the virtualization platforms execute resource allocation or manipulation operations, ensuring control is established in advance while maintaining operational flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The control layer implements feedback mechanisms by monitoring management operations, logging commands and their outcomes, and providing audit trails. This feedback loop enables continuous verification of resource access control while allowing dynamic resource allocation to proceed, as the control layer can detect and respond to unauthorized operations in real-time.

Inventive Principle:
Principle #23Feedback

3Reliability

If centralized management and monitoring are implemented, then security control and compliance improve, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidmanagement architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control layer is designed as a universal security component that handles multiple functions: authentication, authorization, command proxying, logging, and compliance monitoring. By consolidating these diverse security functions into a single multi-functional control layer, the patent reduces overall system complexity compared to implementing separate security mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2332285B1Methods and systems for securely managing virtualization platform
Publication Date: 2018.11.07 HYTRUST
  • EP2332285B1 patent drawingFigure 1
  • EP2332285B1 patent drawingFigure 2
  • EP2332285B1 patent drawingFigure 3~4

AI summary

Virtualization platforms and management clients therefor are communicatively coupled to one another via a control layer logically disposed therebetween. The control layer is configured to proxy virtualization management commands from the management clients to the virtualization platforms, but only after successful authentication of users (which may include automated agents and processes) issuing those commands and privileges of those users as defined by access control information accessible to the control layer. The control layer may be instantiated as an application running on a physical appliance logically interposed between the virtualization platforms and management clients, or a software package running on dedicated hardware logically interposed between the virtualization platforms and management clients, or as an application encapsulated in a virtual machine running on a compatible virtualization platform logically interposed between the virtualization platforms and management clients.