Virtual Machine File Security via Cryptographic Share Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual machine computing environments lack effective methods for securing and restoring virtual machine files across multiple storage locations, particularly in distributed architectures and cloud computing environments, which can lead to data corruption or tampering during stop and start operations.
Innovation Solution
A cryptographic system that generates data parsing information to determine the placement and encryption of virtual machine files into multiple shares, allowing for secure storage and restoration by accessing a threshold number of shares, with the ability to decrypt and reassemble the data set using a cryptographic restoration application executed through a predetermined sequence of user inputs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If virtual machine files are stored in a single location for easy access, then ease of operation is improved, but reliability deteriorates due to risk of data corruption or tampering
Solution Approach 1:
The virtual machine file is divided into multiple shares (first share, second share, third share, fourth share) and stored in different storage locations. This segmentation allows the system to maintain ease of access while improving reliability, as the virtual machine can be restored from any threshold number of shares (e.g., 3 out of 4) without requiring access to a single centralized location.
2Reliability
If virtual machine files are distributed across multiple storage locations for security, then reliability is improved, but device complexity increases
Solution Approach 1:
A cryptographic system acts as an intermediary to manage the distribution and restoration of virtual machine files. This intermediary handles the complex tasks of generating shares, encrypting data, and coordinating restoration across multiple storage locations, thereby improving reliability while abstracting away the complexity from the user and simplifying the overall system architecture.
3Reliability
If encryption is applied to virtual machine files for security, then reliability is improved, but ease of operation deteriorates due to complex decryption processes
Solution Approach 1:
The cryptographic system is designed to automatically perform encryption and decryption operations without requiring user intervention. When a stop command is received, the system automatically encrypts the virtual machine file and distributes shares to storage locations. Similarly, when restoration is needed, the system automatically retrieves shares and decrypts them, maintaining ease of operation while ensuring data protection.
4Reliability
If multiple shares are created for fault tolerance, then reliability is improved, but loss of time increases due to coordination overhead
Solution Approach 1:
The system performs preliminary actions by pre-establishing the cryptographic infrastructure and share distribution mechanisms before faults occur. When a stop command is received, the encryption and share distribution process is already in place and can execute efficiently. This preliminary preparation reduces the time required for coordination during actual restoration operations, as the system only needs to retrieve and combine shares rather than establish the entire distribution framework from scratch.
Data Source
AI summary
Systems and methods are provided for securing a virtual machine by causing a plurality of shares of virtual machine files to be separately stored in response to a stop command. Systems and methods are also provided for restoring a data set with a cryptographic restoration application in response to a series of user inputs received when no visual indicator of the cryptographic restoration algorithm is displayed, and for restoring a data set with data shares received from another computer device in response to detecting a communication link with the device.


