Virtual Machine Secure Access via Management Appliance Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing secure access to virtual machine images in distributed computing systems is complex and prone to cyber attacks due to the need for additional authentication credentials when accessing virtual machines dispatched across multiple physical machines.

Innovation Solution

Establishing a trusted relationship between a management appliance and a virtual machine using public key cryptography, allowing authenticated users to access the virtual machine without further credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard security features such as login identification and passwords are used for accessing virtual machines, then security authentication is provided, but the access management becomes tedious and time consuming

Engineering Contradiction:
Improvesecurity authenticationVSAvoidaccess management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by establishing trust relationships between the management appliance and virtual machines before access is needed. The management appliance automatically authenticates to virtual machines using pre-configured credentials, eliminating the need for users to manually provide authentication credentials during access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management appliance automatically manages authentication credentials and performs self-service authentication to virtual machines. The system autonomously handles the authentication process without requiring user intervention, where the management appliance itself manages the credential distribution and verification processes.

Inventive Principle:
Principle #25Self-service

2Reliability

If security measures are adapted to the physical location of virtual machines across multiple physical machines, then security coverage is improved, but the complexity of security management increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management appliance serves as a universal authentication authority that can authenticate to multiple virtual machines across different physical hosts using a single integrated system. The appliance implements multi-functional security management including credential distribution, trust relationship establishment, and access control across the entire virtualized environment from a centralized location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The management appliance acts as an intermediary between administrators and virtual machines,以及between different physical hosts. It mediates authentication by holding and managing credentials centrally, then providing authenticated access to virtual machines without requiring administrators to directly manage credentials on each physical host or virtual machine.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If virtual machine images are dispatched across multiple physical machines, then resource utilization is improved, but the movement and management of virtual machines becomes more complicated

Engineering Contradiction:
Improveresource utilizationVSAvoidvirtual machine management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Virtual machines perform self-service authentication by automatically accepting credentials from the management appliance. When virtual machine images are dispatched or migrated across physical machines, they autonomously establish trusted relationships with the management appliance without requiring manual reconfiguration or administrator intervention, enabling seamless mobility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the management appliance continuously monitors and manages credential validity across the distributed environment. When virtual machines are dispatched or migrated, the appliance automatically updates trust relationships and maintains security policies, providing real-time feedback on authentication status and enabling dynamic adaptation to changing system configurations.

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security and convenience by eliminating the need for additional authentication, reducing the risk of cyber attacks and simplifying access management in distributed computing systems.

Implementation Method 1

Establishing a trusted relationship between a management appliance and a virtual machine using public key cryptography

Methodology Applied
Scientific EffectPublic key cryptography:

Data Source

PatentUS11307886B2Secure access to a virtual machine
Publication Date: 2022.04.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11307886B2 patent drawing
  • US11307886B2 patent drawing
  • US11307886B2 patent drawing

AI summary

A method for providing secure access to a virtual machine includes dispensing an image corresponding to a virtual machine from a management appliance to a distributed computing system such that the virtual machine is implemented by at least one of a plurality of interconnected physical computing devices in the distributed computing system; establishing a trusted relationship between the management appliance and the virtual machine; and providing a user with access to the virtual machine from the management appliance without further authentication credentials from the user.