Virtual Machine Access Control via Beacon Signal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of mobile virtualization and 'bring your own device' (BYOD) computing, there is a risk of security vulnerabilities as users may forget to log out of corporate virtual machines, allowing access to sensitive information when switching roles or locations, potentially exposing corporate data to malware.
Innovation Solution
A system that uses a beacon signal to manage and automatically switch virtual machines on a mobile device, ensuring that a virtual machine is only run when the device is within a predefined range of a broadcasting device, thereby limiting access to location-based virtual machines and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a virtual machine is kept running on a mobile device for convenient access to corporate applications, then ease of operation is improved, but security risk increases because the virtual machine may remain accessible even when the user is outside authorized locations
Solution Approach 1:
The system performs preliminary actions by detecting beacon signals from broadcasting devices before allowing virtual machine execution. The mobile device continuously monitors for beacon signals in the vicinity, and only initiates or maintains virtual machine operation when an authorized beacon is detected, preventing unauthorized access before it can occur
Solution Approach 2:
The system implements feedback by continuously monitoring beacon signal presence and using this information to dynamically control virtual machine operation. When a beacon signal is detected, the virtual machine is allowed to run; when the signal is lost or weakened below a threshold, the system automatically suspends or terminates the virtual machine, creating a closed-loop security mechanism
2Object-affected harmful factors
If a virtual machine is automatically terminated when leaving a location to maintain security, then security risk is reduced, but ease of operation deteriorates because the user must manually restart the virtual machine when returning
Solution Approach 1:
The system performs preliminary detection of beacon signals and prepares the virtual machine for execution in advance. When the mobile device enters a zone with an authorized beacon signal, the system has already detected the signal and can automatically initiate or resume the virtual machine without requiring user intervention, thus maintaining both security and convenience
3Object-affected harmful factors
If beacon signal monitoring is implemented to control virtual machine access, then security is improved, but device complexity increases due to additional monitoring and location-based control mechanisms
Solution Approach 1:
The system introduces beacon signals as an intermediary element between the mobile device and the virtual machine execution control. Instead of implementing complex direct monitoring and authentication mechanisms within the device, the solution uses external broadcasting devices that emit beacon signals, simplifying the mobile device's role to merely detecting these signals and responding accordingly
Data Source
AI summary
A system is provided and includes a broadcasting device configured to emit a beacon signal over a predefined range and a mobile computing device. The mobile computing device is configured to run a host operating system at any location. The mobile computing device is further configured to run a virtual machine associated with the beacon signal within the host operating system but only when the computing device is in range of the beacon signal of a predefined strength.


