Virtual Machine Placement in Communication Pathways for Resource Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks face challenges in protecting access to resources from unauthorized access and damage due to increased exposure to sophisticated hackers and malicious actors, especially as access becomes easier over large areas like the Internet and cloud networks.

Innovation Solution

The method involves fractionating computer applications into disparate components, assigning them to different communication pathways, and creating virtual machines to control access to requisite resources, with the ability to adjust the number of virtual machines based on threat levels, thereby providing a protective layer between the application and resource servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If computer resources are placed on a computer network to enable widespread access, then ease of operation and accessibility are improved, but security and protection from unauthorized access deteriorate

Engineering Contradiction:
Improveaccessibility to computer resourcesVSAvoidunauthorized access and damage to resources
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A virtual machine is introduced as an intermediary component between the computer application and the requisite resource on the network. The virtual machine controls access to the resource, acting as a mediator that prevents direct access while maintaining resource availability. This resolves the contradiction by enabling network accessibility while protecting resources through the intermediary virtual machine layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If virtual machines are installed within communication pathways to control access, then security and protection are improved, but device complexity increases

Engineering Contradiction:
Improveprotection from unauthorized accessVSAvoidsystem architecture complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system is segmented into distinct components: the computer application, the virtual machine, and the requisite resource. The virtual machine is fractionated and assigned to specific communication pathways, creating modular security layers. This segmentation allows protection functionality to be added without requiring complete system redesign, managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If the quantity of virtual machines is increased to adjust for higher threat levels, then security protection is improved, but use of energy and computational resources increases

Engineering Contradiction:
Improvesecurity defense capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system dynamically adjusts the quantity of virtual machines based on defined threat levels. When threat levels are low, fewer virtual machines are deployed, conserving computational resources. When threat levels increase, additional virtual machines are instantiated to enhance protection. This dynamic adaptation resolves the contradiction by making resource consumption variable rather than fixed, matching security investment to actual threat conditions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9553877B2Installing virtual machines within different communication pathways to access protected resources
Publication Date: 2017.01.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9553877B2 patent drawing
  • US9553877B2 patent drawing
  • US9553877B2 patent drawing

AI summary

One or more processors fractionate a computer application into disparate components, and assign two or more of the disparate components to different communication pathways, where the different communication pathways lead to requisite resources needed to execute the disparate components. The processor(s) create a virtual machine that controls access to a particular requisite resource by a particular disparate component, and install the virtual machine within at least one of the different communication pathways to control access to the particular requisite resource by the particular disparate component. The processor(s) transmit a resource retrieval instruction to retrieve the particular requisite resource via the virtual machine and at least one of the different communication pathways, and adjust a quantity of virtual machines between the computer application and the particular requisite resource according to a threat level for the particular disparate component.