Virtual Storage Appliance Image Lockbox Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual storage appliance (VSA) installation images are vulnerable to unauthorized access and manipulation due to their ease of opening and manipulation, posing risks of intellectual property theft and malware spoofing.

Innovation Solution

The VSA image is maintained in two states: a 'Pre-install' state for initial deployment and a 'Runtime' state, with sensitive contents encrypted in a 'lockbox' accessible only when the system is in the Pre-install state, using stable system values (SSVs) that change upon transitioning to Runtime, rendering the lockbox inaccessible.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the VSA installation image is distributed as an archive image (OVA format), then the deployment and installation process is simplified and standardized, but the image becomes easy to open and manipulate, increasing the risk of unauthorized access and intellectual property theft

Engineering Contradiction:
Improvedeployment processVSAvoidunauthorized access
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting the installation image contents and lockbox before distribution. The encryption is performed in advance during image creation, so that when the image is deployed and manipulated during installation, the sensitive contents remain protected. This resolves the contradiction by maintaining ease of deployment while preventing unauthorized access through pre-applied encryption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by transitioning the system from a pre-installation state (where encryption keys can be accessed) to a post-installation state (where keys are no longer accessible). The encryption status and key accessibility parameters change based on the installation state, allowing easy deployment during pre-installation while preventing unauthorized access during and after installation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the installation image contains sensitive cryptographic secrets and intellectual property, then the VSA can provide secure and functional operations, but the image becomes a target for spoofing and malware injection by bad actors

Engineering Contradiction:
Improvecryptographic securityVSAvoidspoofing risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-encrypting sensitive cryptographic secrets and intellectual property within the installation image before distribution. The encryption is set up in advance with state-dependent key accessibility, so that even if bad actors attempt to spoof or manipulate the image during deployment, the sensitive contents remain protected and cannot be extracted or misused.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by implementing encryption and state-dependent key accessibility as a preventive measure before any potential spoofing or malware injection can occur. The encryption structure is built in advance to actively prevent unauthorized access, counteracting potential harmful actions before they can take effect.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If the lockbox encryption key is accessible during installation, then the VSA can be properly deployed and configured, but the key becomes vulnerable to extraction and unauthorized use

Engineering Contradiction:
Improveinstallation processVSAvoidkey extraction risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses parameter changes by making the encryption key accessibility dependent on the system state parameter. During pre-installation, the key is accessible for proper deployment. After installation completes, the system state changes and the key becomes inaccessible. This dynamic parameter change allows easy operation during installation while preventing key extraction and unauthorized use after installation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies dynamics by making the encryption key accessibility dynamic rather than static. The key can be accessed during pre-installation but becomes locked after installation completes. This dynamic behavior allows the system to provide ease of operation when needed while automatically preventing key extraction risks after deployment.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9990190B1Secured virtual storage appliance installation image
Publication Date: 2018.06.05 EMC IP HLDG CO LLC
  • US9990190B1 patent drawing
  • US9990190B1 patent drawing
  • US9990190B1 patent drawing

AI summary

An installation image of a virtual storage appliance (VSA) is protected by initiating VSA installation from an archive image establishing a pre-installation operating state. The archive image includes an installation image with a lockbox storing a first key for accessing the installation image. The lockbox is encrypted using a second key derived from a stable system value (SSV), such as data for device partitioning, obtainable from an execution environment in the pre-installation operating state. During installation, the SSV is obtained and used in decrypting the lockbox to retrieve the first key and use the installation image to install the VSA. The VSA is installed in a manner establishing a post-installation operating in which the SSV is no longer obtainable from the execution environment, e.g., due to changing the device partition information. An SSV obtained from the partition information post-installation does not yield the key for decrypting the lockbox, protecting the installed image.