Virtual Machine Image Deployment Enforcement via Pre-Instantiation Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual machine image deployment systems allow instantiation before security controls are initiated, leading to potential unauthorized instantiation and theft of virtual machine images.

Innovation Solution

A method that verifies the virtualization environment before allowing instantiation of a virtual machine image, using a validation module to communicate with an enforcement module to ensure the environment's authenticity and compliance with deployment policies, preventing unauthorized instantiation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machine images are fully instantiated before security controls are initiated, then deployment speed and productivity are improved, but security reliability deteriorates as images can be extracted and instantiated in unverified locations

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing environment verification before virtual machine image instantiation. The validation module checks whether the virtualization environment is verified and compliant with deployment policies prior to allowing the virtual machine image to be instantiated, preventing unauthorized deployment while maintaining efficient deployment processes

Inventive Principle:
Principle #10Preliminary action

2Reliability

If environment verification is performed before instantiation, then security reliability is improved, but deployment time increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies self-service by implementing autonomous verification where the validation module automatically checks environment verification status and deployment policy compliance without requiring manual intervention. The system self-determines whether to allow instantiation based on verification results, reducing operational overhead while maintaining security

Inventive Principle:
Principle #25Self-service

3Ease of operation

If security controls are initiated after virtual machine instantiation, then ease of operation is improved, but harmful factors increase as images can be extracted and used in unauthorized environments

Engineering Contradiction:
Improveease of deploymentVSAvoidunauthorized usage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preventing unauthorized deployment before it can occur. The validation module proactively verifies the virtualization environment and checks compliance with deployment policies prior to allowing instantiation, blocking harmful actions before they can affect the virtual machine images

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS8826275B2System and method for self-aware virtual machine image deployment enforcement
Publication Date: 2014.09.02 CA TECH INC
  • US8826275B2 patent drawing
  • US8826275B2 patent drawing
  • US8826275B2 patent drawing

AI summary

According to one embodiment of the present disclosure, a method includes receiving a request to instantiate a virtual machine image in a virtualization environment. The method also includes sending a request for verification of the virtualization environment. The method further includes receiving information from the enforcement module in response to the request for verification of the virtualization environment. The method further includes determining whether the virtualization environment is verified based on the information received.