Virtual Machine Data Protection for Unauthorized Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively protect computing devices from unauthorized access and ensure data recovery when devices are lost, stolen, or rendered inoperable, particularly in insecure environments, and lack efficient centralized management and backup solutions.
Innovation Solution
The implementation of a centrally-managed data protection system using a thin layer of virtual machine on computing devices for authentication and encryption, coupled with a hypervisor for centralized control and backup, enables secure data storage and recovery, and communication between devices and authentication servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored on mobile devices without proper protection, then accessibility and portability are improved, but security and protection from unauthorized access deteriorate
Solution Approach 1:
The system segments data into protected and unprotected portions, with only authorized users able to access the protected segment. The patent implements this by creating a secure container within the mobile device that separates sensitive data from general access areas, requiring authentication to retrieve the protected portion.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism between the user and the data. A secure authentication module acts as a mediator that verifies user credentials and controls access to protected data, preventing direct unauthorized access while maintaining legitimate accessibility.
2Reliability
If traditional backup methods are used, then data recovery capability is improved, but user convenience and automation deteriorate
Solution Approach 1:
The system implements self-service backup where the mobile device automatically performs backup operations without requiring user initiation. The patent describes an automated backup module that continuously monitors data changes and transfers protected data to secure remote storage without user intervention, while still allowing users to retrieve data when needed.
3Object-affected harmful factors
If encryption is applied to protect data, then security is improved, but processing speed and accessibility deteriorate
Solution Approach 1:
The patent implements preliminary encryption where data is encrypted before being stored on the mobile device, rather than encrypting on-demand during access. Authentication credentials are pre-configured in the device, allowing authorized users to access encrypted data quickly without real-time decryption overhead, thus maintaining both security and processing speed.
Data Source
AI summary
Methods and systems for performing an authenticated boot; performing a continuous data protection; performing automatic protection and optionally a consolidation; and performing other defenses and protection of a protected computing device (such as a computer system) are provided. The aspects include integrating security mechanisms (which may include a “call home” function, role and rule-based policies, validating technologies, encryption and decryption technologies, data compression technologies, protected and segmented boot technologies, and virtualization technologies. Booting and operating (either fully or in a restricted manner) are permitted only under a control of a specified role-set, rule-set, and/or a controlling supervisory process or server system(s). The methods and systems make advantageous use of hypervisors and other virtual machine monitors or managers.


