Virtual Machine File Security via Cryptographic Share Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual machine computing environments lack effective methods for securing and restoring virtual machine files across multiple storage locations, particularly in distributed architectures and cloud computing environments, which can lead to data corruption or tampering during stop and start operations.

Innovation Solution

A cryptographic system that generates data parsing information to determine the placement and encryption of virtual machine files into multiple shares, allowing for secure storage and restoration by accessing a threshold number of shares, with the ability to decrypt and reassemble the data set using a cryptographic restoration application executed through a predetermined sequence of user inputs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If virtual machine files are stored in a single location for easy access, then ease of operation is improved, but reliability deteriorates due to risk of data corruption or tampering

Engineering Contradiction:
Improveease of accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The virtual machine file is divided into multiple shares (first share, second share, third share, fourth share) and stored in different storage locations. This segmentation allows the system to maintain ease of access while improving reliability, as the virtual machine can be restored from any threshold number of shares (e.g., 3 out of 4) without requiring access to a single centralized location.

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtual machine files are distributed across multiple storage locations for security, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A cryptographic system acts as an intermediary to manage the distribution and restoration of virtual machine files. This intermediary handles the complex tasks of generating shares, encrypting data, and coordinating restoration across multiple storage locations, thereby improving reliability while abstracting away the complexity from the user and simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to virtual machine files for security, then reliability is improved, but ease of operation deteriorates due to complex decryption processes

Engineering Contradiction:
Improvedata protectionVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cryptographic system is designed to automatically perform encryption and decryption operations without requiring user intervention. When a stop command is received, the system automatically encrypts the virtual machine file and distributes shares to storage locations. Similarly, when restoration is needed, the system automatically retrieves shares and decrypts them, maintaining ease of operation while ensuring data protection.

Inventive Principle:
Principle #25Self-service

4Reliability

If multiple shares are created for fault tolerance, then reliability is improved, but loss of time increases due to coordination overhead

Engineering Contradiction:
Improvefault toleranceVSAvoidcoordination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing the cryptographic infrastructure and share distribution mechanisms before faults occur. When a stop command is received, the encryption and share distribution process is already in place and can execute efficiently. This preliminary preparation reduces the time required for coordination during actual restoration operations, as the system only needs to retrieve and combine shares rather than establish the entire distribution framework from scratch.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9916456B2Systems and methods for securing and restoring virtual machines
Publication Date: 2018.03.13 SECURITY FIRST INNOVATIONS LLC
  • US9916456B2 patent drawing
  • US9916456B2 patent drawing
  • US9916456B2 patent drawing

AI summary

Systems and methods are provided for securing a virtual machine by causing a plurality of shares of virtual machine files to be separately stored in response to a stop command. Systems and methods are also provided for restoring a data set with a cryptographic restoration application in response to a series of user inputs received when no visual indicator of the cryptographic restoration algorithm is displayed, and for restoring a data set with data shares received from another computer device in response to detecting a communication link with the device.