Virtual Machine Encryption Key Management for Secure Host Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtual machine security measures are inadequate for protecting high business impact data, as they lack effective methods to prevent unauthorized access, copying, and misuse, especially with the increasing portability and storage capacity of portable storage media.

Innovation Solution

Implementing a system where each virtual machine is assigned a unique identifier and associated with encryption keys, which are used to encrypt its virtual hard drives, allowing only authorized physical hosts with the appropriate keys to access and operate the virtual machines, and enabling secure migration and access control through a management service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtual machines are made portable and accessible across multiple hosts, then ease of operation and adaptability improve, but security and protection against unauthorized access deteriorate

Engineering Contradiction:
Improvevirtual machine portabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encryption keys as an intermediary mechanism between the virtual machine files and the host system. These keys act as a mediator that controls access to the virtual machine, allowing legitimate portability while preventing unauthorized access. The keys are stored separately from the virtual machine files and are required to decrypt and execute the virtual machine, thus resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If encryption keys are distributed to multiple physical hosts, then adaptability and ease of operation improve, but security control becomes more complex

Engineering Contradiction:
Improvehost flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where each physical host automatically manages its own encryption keys through a key management service. The system automatically generates, stores, and retrieves keys as needed without requiring manual intervention. This automation reduces the perceived complexity for users while maintaining strong security controls, allowing multiple hosts to access virtual machines adaptively.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If conventional access control methods are used, then ease of operation is maintained, but protection against data theft and misuse is insufficient

Engineering Contradiction:
Improveaccess simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting virtual machine files with unique encryption keys before they are accessed or moved between hosts. This pre-encryption ensures that even if files are copied or transferred, they remain protected and unusable without the corresponding decryption key. The security measure is implemented in advance, maintaining ease of operation while significantly improving reliability of protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8977867B2Corralling virtual machines with encryption keys
Publication Date: 2015.03.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8977867B2 patent drawing
  • US8977867B2 patent drawing
  • US8977867B2 patent drawing

AI summary

A virtual machine comprises a unique identifier that is associated with one or more encryption keys. A management server encrypts the virtual machine's virtual hard disk(s) using the one or more associated encryption keys. The management server further provides the one or more encryption keys to a limited number of one or more servers in a system. Only those one or more servers that have been provided the one or more encryption keys can be used to load, access, and/or operate the virtual machine. The management server can thus differentiate which virtual machines can be operated on which servers by differentiating which servers can receive which encryption keys. In one implementation, a management server encrypts all virtual machines in the system, but encrypts virtual machines with sensitive data with a limited set of encryption keys, and further provides those encryption keys to a limited set of trusted servers.