Virtual Machine Security via Community-of-Interest Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machines in cloud networks lack effective protection from other machines and devices with physical access, and data transmission is vulnerable to interception due to shared hardware resources, making conventional security solutions inadequate for isolating tenants' virtual machines.

Innovation Solution

Implementing cryptography to organize virtual machines into communities-of-interest (COI) for secure communication, using a virtual gateway to isolate and encrypt messages within enclaves, and enabling dynamic licensing for secure resource allocation and provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are frequently started and stopped based on demand to reduce costs, then resource utilization efficiency is improved, but security isolation between tenants deteriorates because virtual machines may execute on shared hardware with other tenants

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces cryptographic intermediaries (encryption keys, certificates, and security modules) as mediators between virtual machines and the hardware platform. These intermediaries provide security isolation without requiring dedicated physical hardware, allowing virtual machines to be dynamically allocated while maintaining security boundaries through cryptographic protection of communication channels and data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If conventional security solutions are used to isolate tenant hardware, then security isolation is improved, but adaptability to dynamic virtual machine allocation deteriorates because virtual machines cannot be frequently started and stopped

Engineering Contradiction:
Improvesecurity isolationVSAvoiddynamic allocation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security provisioning where cryptographic security contexts, encryption keys, and security associations are created, modified, and destroyed dynamically as virtual machines are allocated and deallocated. This allows the security infrastructure to adapt to changing virtual machine configurations without requiring static hardware assignments, enabling both strong security isolation and flexible resource allocation.

Inventive Principle:
Principle #15Dynamics

3Reliability

If cryptographic security is implemented to protect communication between virtual machines, then security is improved, but device complexity increases due to key management and encryption overhead

Engineering Contradiction:
Improvecommunication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal security mechanisms where a single cryptographic infrastructure serves multiple functions: establishing secure communication channels, authenticating virtual machines, protecting data at rest and in transit, and managing security contexts for multiple tenants. This multi-functional approach consolidates what would otherwise require separate security systems, reducing overall complexity while maintaining comprehensive security protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10248442B2Automated provisioning of virtual machines
Publication Date: 2019.04.02 UNISYS CORP
  • US10248442B2 patent drawing
  • US10248442B2 patent drawing
  • US10248442B2 patent drawing

AI summary

Virtual machines in a network may be isolated by encrypting transmissions between the virtual machines with keys possessed only by an intended recipient. Within a network, the virtual machines may be logically organized into a number of community-of-interest (COI) groups. Each COI may use an encryption key to secure communications within the COI, such that only other virtual machines in the COI may decrypt the message. Virtual machines may be automatically provisioned with configuration information, such as the encryption keys, when the virtual machine is started. The provisioning information may be created based on a template stored on a configuration server.