Virtual Machine Intermediary for Cloud Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based multitenancy environments face challenges in secure data storage due to inherent vulnerabilities in policy-based security, where a single administrator can access all data, and existing solutions like encryption are not scalable or portable, making them inefficient for cloud computing.
Innovation Solution
The implementation of a system where a virtual machine is interposed between the data and storage to provide cryptographic functions for secure data storage and retrieval, using a key manager for authentication and encryption key management, ensuring data security and scalability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If policy-based security is used to manage data access in multitenancy environments, then ease of operation is improved, but reliability deteriorates due to potential policy errors and administrator access vulnerabilities
Solution Approach 1:
The patent introduces a cryptographic intermediary layer between the storage area network and virtual machines. This intermediary performs cryptographic operations (encryption/decryption) without requiring policy-based access controls, thereby eliminating the security vulnerabilities associated with policy management while maintaining ease of data access. The intermediary acts as a trusted mediator that handles security operations independently of administrative policies.
2Reliability
If data is encrypted at the client and transmitted to cloud storage, then data security is improved, but productivity deteriorates because the data becomes completely unusable until decrypted
Solution Approach 1:
The patent segments the cryptographic operations from the data storage and retrieval processes. Instead of encrypting entire data sets before storage (which renders them unusable), the system performs selective cryptographic operations on specific data portions or metadata while leaving other data accessible in plaintext form. This segmentation allows data to remain usable in the cloud while maintaining security for specific sensitive portions.
Solution Approach 2:
The cryptographic intermediary enables data to remain in usable form in cloud storage while providing selective security. The intermediary can decrypt data for processing, allow controlled access to specific portions, or perform cryptographic operations without requiring full decryption, thereby maintaining both security and productivity simultaneously.
3Reliability
If hardware security devices are installed for each tenant, then data security is improved, but device complexity and scalability worsen
Solution Approach 1:
The patent replaces individual hardware security devices with a virtualized cryptographic intermediary that operates at the software/virtualization layer. This intermediary provides the same security functions as hardware devices but in a virtualized form that can serve multiple tenants through the storage area network, thereby eliminating the need for complex hardware installations while maintaining security and enabling scalability.
Solution Approach 2:
Instead of requiring physical hardware devices for each tenant, the system creates virtual copies of security functionality through the cryptographic intermediary. This virtualization allows security capabilities to be replicated and distributed across multiple tenants without requiring actual hardware multiplication, reducing complexity while maintaining security posture.
Data Source
AI summary
A method is disclosed wherein a first virtual machine is provided in execution. A storage area network for storing of data of the first virtual machine is also provided. A second virtual machine is executed for receiving first data from the first virtual machine for storage within the storage area network and for securing the first data to form secured first data and for storing the secured first data within the storage area network.


