Virtual Machine Image Provisioning for Secure Remote Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for remotely accessing enterprise computer networks via virtual machines are inefficient due to the time-consuming and costly process of creating user-specific virtual machine image files, which exposes the network to potential malicious software and requires extensive IT resource management.

Innovation Solution

A method for provisioning a customized virtual machine image that includes an operating system and configuration data, allowing for automated setup and authentication, enabling secure and efficient remote access while minimizing user interaction and IT resource consumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user-specific virtual machine image files are created and distributed, then remote users can access the enterprise network, but the process becomes time-consuming and expensive

Engineering Contradiction:
Improveremote network access capabilityVSAvoidprovisioning time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-configuring a master virtual machine image with all necessary enterprise network connections, authentication mechanisms, and security policies before distribution. This master image serves as a template that automatically provisions user-specific configurations when deployed to remote workstations, eliminating the time-consuming manual customization process while maintaining adaptability for different users.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If user-specific virtual machine image files are created and distributed, then remote users can access the enterprise network, but IT resource management becomes extensive and costly

Engineering Contradiction:
Improveremote network access capabilityVSAvoidIT resource management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a single master virtual machine image that contains all necessary configurations, authentication mechanisms, and enterprise network connections. This universal image can be distributed to multiple remote users who each receive their own customized instance, eliminating the need for IT to manually manage and customize separate images for each user, thereby reducing IT resource management complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If remote users connect via VPN, then they can access the enterprise network, but the network becomes exposed to malicious software

Engineering Contradiction:
Improveremote network connectivityVSAvoidmalicious software exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies the intermediary principle by introducing a virtual machine as a mediator layer between the remote user's host computer and the enterprise network. The virtual machine runs in an isolated environment with controlled network access, allowing users to securely connect to the enterprise network while preventing malicious software on the host computer from directly accessing or compromising the enterprise network resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If virtual machines are used for remote access, then network security is improved, but the provisioning process becomes complex and resource-intensive

Engineering Contradiction:
Improvenetwork securityVSAvoidprovisioning process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements copying by creating a master virtual machine image that serves as a reusable template. This master image can be copied and distributed to multiple remote users, with each copy automatically receiving the necessary user-specific configurations. This approach maintains the security benefits of virtual machines while dramatically simplifying the provisioning process by eliminating manual setup for each user.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9392078B2Remote network access via virtual machine
Publication Date: 2016.07.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9392078B2 patent drawing
  • US9392078B2 patent drawing
  • US9392078B2 patent drawing

AI summary

A virtual machine project manager creates a generic, i.e., not user-specific, virtual machine image file. Copies of this image file may be distributed to one or more users, each of whom may then use an automated procedure to generate a user-specific virtual machine image file and, thus, a user-specific virtual machine on his/her remote host computer. The generic virtual machine image file may be distributed on computer-readable media, such as a DVD disks, or the file may be stored on a server and downloaded (such as via the Internet) by the users. Each user also receives or downloads a token, which contains a small amount of user-specific information that is used by the automated procedure to provision the generic virtual machine image file for the particular user. A virtual machine accesses a security token connected to a host computer to automatically authenticate or re-authenticate a user, such as when a virtual private network connection is restarted. Substantially identical session identifiers are used by a host computer and a virtual machine, or by two or more virtual machines and, when communicating with an integrated access server. A file server stores virtual machine images that are accessed by a plurality of host computers.