Virtual Machine Security via Community-of-Interest Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual machines in cloud networks lack effective protection from other machines and devices with physical access, and data transmission is vulnerable to interception due to shared hardware resources, making conventional security solutions inadequate for isolating tenants' virtual machines.
Innovation Solution
Implementing cryptography to organize virtual machines into communities-of-interest (COI) for secure communication, using a virtual gateway to isolate and encrypt messages within enclaves, and enabling dynamic licensing for secure resource allocation and provisioning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual machines are frequently started and stopped based on demand to reduce costs, then resource utilization efficiency is improved, but security isolation between tenants deteriorates because virtual machines may execute on shared hardware with other tenants
Solution Approach 1:
The patent introduces cryptographic intermediaries (encryption keys, certificates, and security modules) as mediators between virtual machines and the hardware platform. These intermediaries provide security isolation without requiring dedicated physical hardware, allowing virtual machines to be dynamically allocated while maintaining security boundaries through cryptographic protection of communication channels and data.
2Reliability
If conventional security solutions are used to isolate tenant hardware, then security isolation is improved, but adaptability to dynamic virtual machine allocation deteriorates because virtual machines cannot be frequently started and stopped
Solution Approach 1:
The patent implements dynamic security provisioning where cryptographic security contexts, encryption keys, and security associations are created, modified, and destroyed dynamically as virtual machines are allocated and deallocated. This allows the security infrastructure to adapt to changing virtual machine configurations without requiring static hardware assignments, enabling both strong security isolation and flexible resource allocation.
3Reliability
If cryptographic security is implemented to protect communication between virtual machines, then security is improved, but device complexity increases due to key management and encryption overhead
Solution Approach 1:
The patent implements universal security mechanisms where a single cryptographic infrastructure serves multiple functions: establishing secure communication channels, authenticating virtual machines, protecting data at rest and in transit, and managing security contexts for multiple tenants. This multi-functional approach consolidates what would otherwise require separate security systems, reducing overall complexity while maintaining comprehensive security protection.
Data Source
AI summary
Virtual machines in a network may be isolated by encrypting transmissions between the virtual machines with keys possessed only by an intended recipient. Within a network, the virtual machines may be logically organized into a number of community-of-interest (COI) groups. Each COI may use an encryption key to secure communications within the COI, such that only other virtual machines in the COI may decrypt the message. Virtual machines may be automatically provisioned with configuration information, such as the encryption keys, when the virtual machine is started. The provisioning information may be created based on a template stored on a configuration server.


