Virtual Machine Policy State Protection via Cryptographic Hash Chaining

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized systems, ensuring that virtual machines migrate to compatible security policies across different physical platforms is challenging due to limited hardware resources and the need for third-party intervention to verify compatible security policies.

Innovation Solution

The method involves creating and chaining different representations of a security policy, including a source policy, a mapping policy, and a binary policy, using cryptographic hashes to ensure compatibility without third-party intervention, allowing systems to autonomously verify and enforce compatible security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machines are migrated between physical platforms to utilize hardware resources, then resource utilization and system flexibility improve, but security policy compatibility and system reliability deteriorate

Engineering Contradiction:
Improvevirtual machine migration capabilityVSAvoidsecurity policy compatibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary extraction and verification of security policy state information before virtual machine migration. The source physical platform extracts the policy state information from the source virtual machine and verifies compatibility with the target platform beforehand, preventing incompatible migrations and ensuring security policy reliability throughout the migration process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism where the source physical platform acts as a mediator to extract, verify, and validate security policy state information. This intermediary process ensures that only compatible policy states are transferred during migration, resolving the contradiction between migration flexibility and policy compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If third-party intervention is used to verify security policy compatibility, then system reliability improves, but operational complexity and verification time increase

Engineering Contradiction:
Improvesecurity policy verification accuracyVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service verification where the source physical platform autonomously extracts and verifies security policy state information without requiring third-party intervention. The source platform uses its own verification mechanisms to validate policy compatibility, simplifying the system architecture while maintaining high verification accuracy and reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the essential security policy state information from the virtual machine configuration and separates it from the migration process. By extracting only the critical policy state data and verifying it independently, the system achieves reliable verification without the complexity of third-party intervention, focusing only on the essential security attributes

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7856653B2Method and apparatus to protect policy state information during the life-time of virtual machines
Publication Date: 2010.12.21 WRP IP MANAGEMENT LLC
  • US7856653B2 patent drawing
  • US7856653B2 patent drawing
  • US7856653B2 patent drawing

AI summary

A scheme for protecting policy state information during the lifetime of a virtual machine is presented. In order to protect and preserve the policy state information of the virtual machine, a process creates a source policy, a mapping policy, and a binary policy. These policies are all different representations of a security policy. The different policy representations are chained together via cryptographic hashes.