Virtual Machine Security via Third-Party Trusted Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing platforms face security challenges due to inadequate user identity authentication, limited malware prevention, and data leakage control, particularly in scenarios involving multiple tenants and 64-bit operating systems, leading to relatively low security and inefficient information sharing.

Innovation Solution

A management control method and system for virtual machines that utilize a security control platform to authenticate user requests through a third-party trusted platform, ensuring only authorized users can enable and manage virtual machines by decrypting and decapsulating them using encryption keys, and performing integrity checks to prevent unauthorized access and data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security assurance technology (identity authentication, malware prevention, data leakage prevention) is used in cloud computing platforms, then basic security functions are provided, but security reliability is insufficient due to privilege threats from administrators, false negatives in malware detection, and limited operating system support

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third-party trusted platform as an intermediary between users and the cloud computing platform. This trusted platform performs identity authentication and issues digital certificates, separating the authentication function from the cloud platform administrator. The trusted platform acts as a neutral mediator that users trust more than the cloud administrator, thereby improving security reliability without requiring the cloud platform to become more complex itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cloud computing platform administrators have full privileges to manage virtual machines, then system management flexibility is improved, but security threats from administrator privileges increase

Engineering Contradiction:
Improvesystem management flexibilityVSAvoidsecurity threats from administrator privileges
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication and authorization functions from the cloud computing platform administrator. Instead of relying on administrator privileges for security, the system divides responsibilities: the trusted platform handles identity authentication and certificate issuance, while the cloud platform handles resource management. This segmentation reduces the security risks associated with concentrated administrator privileges while maintaining operational flexibility.

Inventive Principle:
Principle #1Segmentation

3Productivity

If data is shared between virtual machines to improve information sharing efficiency, then productivity is improved, but data leakage risks increase

Engineering Contradiction:
Improveinformation sharing efficiencyVSAvoiddata leakage risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The trusted platform serves as an intermediary that manages data sharing between virtual machines through digital certificates and encrypted channels. When data needs to be shared, the trusted platform verifies the identities of both parties using digital certificates and establishes secure encrypted communication channels. This allows productive data sharing while preventing unauthorized access and data leakage, as the trusted platform mediates all data exchange operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9698988B2Management control method, apparatus, and system for virtual machine
Publication Date: 2017.07.04 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US9698988B2 patent drawing
  • US9698988B2 patent drawing
  • US9698988B2 patent drawing

AI summary

A security control platform receives a virtual machine starting request message that is from user equipment and forwarded by a management platform, where the virtual machine starting request message includes an identifier of a virtual machine that needs to be enabled and user information; invokes a third-party trusted platform to determine that the virtual machine starting request message is initiated by the user equipment according to an instruction of an authorized user; and performs authentication on the user information, and based on successful authentication, invokes the third-party trusted platform to decapsulate the virtual machine that needs to be enabled. It is ensured that other user equipment (including the management platform) cannot obtain a key of the third-party trusted platform, which enhances security of management control on the virtual machine, and thereby enhances security of a cloud computing platform.