Virtual Machine Partition Isolation by Compliance Category
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization technologies do not adequately address the security needs of virtual machines, particularly in safety-critical environments such as aviation systems, where failures can lead to severe consequences.
Innovation Solution
A host circuit with a processor and memory is used to create a virtual environment with partitions, each containing a virtual machine, where software modules are isolated and executed based on compliance with operational rules, adjusting partition connections according to compliance categories to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If traditional virtualization techniques are used to create virtual machines, then resource optimization and scalability are improved, but security of the virtual machines deteriorates
Solution Approach 1:
The system divides the virtual machine environment into multiple isolated partitions, each with controlled access to software modules. This segmentation allows resource sharing while maintaining security boundaries, resolving the contradiction between resource optimization and security.
Solution Approach 2:
The patent introduces a partition management system that acts as an intermediary between software modules and virtual machines. This intermediary controls and monitors software module execution, enabling resource optimization while enforcing security policies and preventing unauthorized access.
2Reliability
If software modules are isolated to specific partitions based on compliance categories, then security is improved, but device complexity increases
Solution Approach 1:
The partition connection structure is made dynamic and adjustable based on compliance categories. The system automatically configures partition connections according to software module compliance levels, reducing manual configuration complexity while maintaining security through adaptive isolation policies.
Solution Approach 2:
The system changes the parameter of partition connectivity based on compliance categories. By dynamically adjusting connection parameters rather than fixed structures, the system simplifies management while enforcing security through parameter-based access control.
Data Source
AI summary
An apparatus and method for increasing security of a virtual machine are disclosed. The apparatus includes a host circuit having at least a processor and a memory, wherein the at least a processor is configured to receive at least a software module, create a virtual environment, which includes creating a plurality of partitions including a virtual machine (VM), determine a compliance category of the at least a software module as a function of an adherence of the at least a software module to at least one operational rule, isolate the at least a software module to the VM of a software module partition of the plurality of partitions, which includes adjusting partition connections between the software module partition and other partitions of the plurality of partitions within the virtual environment as a function of the compliance category and execute the at least a software module within the virtual environment.


