VM Onboarding via Centralized Policy Server Quarantine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current unified communication solutions lack mechanisms to prevent additional virtual machines (VMs) from being installed post-deployment and ensure that installed VMs meet security posture requirements, potentially compromising system security and performance.

Innovation Solution

A method and system using a centralized policy server to onboard VMs securely, involving baseline creation, posture assessment, and activation, where newly added VMs are initially quarantined, assessed for compliance with security posture policies, and only activated if meeting the required standards, with the option to terminate non-compliant VMs and limit VM numbers based on licensing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If no mechanism is implemented to control additional VM installations, then system flexibility and ease of operation are improved, but system security and performance reliability deteriorate

Engineering Contradiction:
Improveease of adding VMsVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a baseline configuration of authorized VMs during system setup. This baseline serves as a pre-defined security boundary that automatically evaluates any subsequently added VMs against it, ensuring security requirements are met before the VMs are allowed to operate in the production environment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A quarantine environment acts as an intermediary between the external world and the production environment. Newly added VMs are first placed in this isolated quarantine zone where they can be evaluated against security policies without directly impacting the main system, serving as a buffer that protects system reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a quarantine mechanism is implemented for new VMs, then system security is improved, but device complexity and operational time increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is segmented into distinct operational environments: a production environment for authorized VMs and a quarantine environment for newly added VMs. This segmentation isolates potential security risks in the quarantine zone while maintaining a clean production environment, managing complexity through clear spatial separation of functions.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If posture assessment is performed on all new VMs, then measurement precision of security compliance is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvesecurity posture assessment accuracyVSAvoidVM onboarding time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The posture assessment agent operates autonomously on the newly added VM, performing self-assessment of its own security compliance status. This self-service approach eliminates the need for manual security audits and reduces the time and complexity associated with external assessment processes.

Inventive Principle:
Principle #25Self-service

4Productivity

If licensing limits are enforced on VM数量, then productivity control and cost management are improved, but system adaptability and ease of expansion deteriorate

Engineering Contradiction:
ImproveVM quantity controlVSAvoidsystem scalability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts its capacity based on licensing parameters. The baseline configuration and VM quotas are not fixed but can be modified according to license keys, allowing the system to adapt its productivity limits and scalability characteristics based on the organizational needs and licensing agreements.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10511483B2Securely onboarding virtual machines using a centralized policy server
Publication Date: 2019.12.17 EXTREME NETWORKS INC
  • US10511483B2 patent drawing
  • US10511483B2 patent drawing
  • US10511483B2 patent drawing

AI summary

In some implementations, a method can include determining a virtual machine (VM) inventory baseline of a system, including identifying VMs in a baseline configuration and generating a VM fingerprint for each VM in the inventory baseline, and detecting a user onboarded VM and moving the user onboarded VM to a quarantine operating area for a period of time. The operational posture of the user onboarded VM can be compared to an operational posture policy of the system. When the operational posture of the user onboarded VM meets the operational posture policy of the system, the user onboarded VM is moved from the quarantine area to an operational area, and, when the operational posture of the user onboarded system does not meet the operational policy posture of the system and the period of time has expired, the user onboarded VM is terminated.