Virtual Machine Intermediary for Cloud Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based multitenancy environments face challenges in secure data storage due to inherent vulnerabilities in policy-based security, where a single administrator can access all data, and existing solutions like encryption are not scalable or portable, making them inefficient for cloud computing.

Innovation Solution

The implementation of a system where a virtual machine is interposed between the data and storage to provide cryptographic functions for secure data storage and retrieval, using a key manager for authentication and encryption key management, ensuring data security and scalability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If policy-based security is used to manage data access in multitenancy environments, then ease of operation is improved, but reliability deteriorates due to potential policy errors and administrator access vulnerabilities

Engineering Contradiction:
Improvedata access managementVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cryptographic intermediary layer between the storage area network and virtual machines. This intermediary performs cryptographic operations (encryption/decryption) without requiring policy-based access controls, thereby eliminating the security vulnerabilities associated with policy management while maintaining ease of data access. The intermediary acts as a trusted mediator that handles security operations independently of administrative policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted at the client and transmitted to cloud storage, then data security is improved, but productivity deteriorates because the data becomes completely unusable until decrypted

Engineering Contradiction:
Improvedata securityVSAvoiddata usability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the cryptographic operations from the data storage and retrieval processes. Instead of encrypting entire data sets before storage (which renders them unusable), the system performs selective cryptographic operations on specific data portions or metadata while leaving other data accessible in plaintext form. This segmentation allows data to remain usable in the cloud while maintaining security for specific sensitive portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cryptographic intermediary enables data to remain in usable form in cloud storage while providing selective security. The intermediary can decrypt data for processing, allow controlled access to specific portions, or perform cryptographic operations without requiring full decryption, thereby maintaining both security and productivity simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware security devices are installed for each tenant, then data security is improved, but device complexity and scalability worsen

Engineering Contradiction:
Improvedata securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces individual hardware security devices with a virtualized cryptographic intermediary that operates at the software/virtualization layer. This intermediary provides the same security functions as hardware devices but in a virtualized form that can serve multiple tenants through the storage area network, thereby eliminating the need for complex hardware installations while maintaining security and enabling scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of requiring physical hardware devices for each tenant, the system creates virtual copies of security functionality through the cryptographic intermediary. This virtualization allows security capabilities to be replicated and distributed across multiple tenants without requiring actual hardware multiplication, reducing complexity while maintaining security posture.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9021264B2Method and system for cloud based storage
Publication Date: 2015.04.28 EMC IP HLDG CO LLC
  • US9021264B2 patent drawing
  • US9021264B2 patent drawing
  • US9021264B2 patent drawing

AI summary

A method is disclosed wherein a first virtual machine is provided in execution. A storage area network for storing of data of the first virtual machine is also provided. A second virtual machine is executed for receiving first data from the first virtual machine for storage within the storage area network and for securing the first data to form secured first data and for storing the secured first data within the storage area network.