IP Library Granted Patent US 10,423,774
Granted Patent B1
US 10,423,774 · App. 15/682,943 · Granted Sep 24, 2019

System and method for establishing secure communication channels between virtual machines

Inventors: Anton Zelenov (Moscow, RU); Nikolay Dobrovolskiy (Moscow, RU); Serguei M. Beloussov (Costa Del Sol, SG)
Assignee: PARALLELS INTERNATIONAL GMBH
G06F21/445H04L63/0442H04L63/126H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,423,774
App. No.
15/682,943
Granted
Sep 24, 2019
Kind
B1
Abstract

Disclosed are systems and methods for establishing secure communication between virtual machines, and, more particularly, to a system and method for establishing secure communication channels between two or more homogenous virtual machines. An exemplary method includes generating, by a first virtual machine, an encryption key compatible with a symmetric encryption algorithm and storing the encryption key in a memory of the first virtual machine; generating a second virtual machine by performing a virtual machine forking operation on the first virtual machine, wherein a memory of the generated second virtual machine contains the encryption key; receiving, by one of the at least two virtual machines, a communication transmitted by another of the at least two virtual machines, wherein the communication comprises data encrypted using the encryption key; and decrypting the data, by the recipient virtual machine, using the encryption key.

Claims (64)

1. A method for establishing a secure communication channel between at least two virtual machines, comprising:

generating, by a first virtual machine, an encryption key compatible with a symmetric encryption algorithm and storing the encryption key in a memory of the first virtual machine;

generating a second virtual machine by performing a virtual machine forking operation on the first virtual machine, wherein a memory of the generated second virtual machine contains the encryption key, and wherein the virtual machine forking operation comprises:

generating, by the first virtual machine, a unique identifier associated with the first virtual machine;

communicating, by the first virtual machine, a request to a virtual machine manager to generate the second virtual machine by cloning the first virtual machine; and

assigning, by the virtual machine manager, parent or clone status to the at least two virtual machines;

receiving, by one of the at least two virtual machines, a communication transmitted by another of the at least two virtual machines, wherein the communication comprises data encrypted using the encryption key; and

decrypting the data, by the recipient virtual machine, using the encryption key.

2. The method of claim 1 , wherein the encryption key is a random string.

3. The method of claim 1 , wherein the second virtual machine is a linked clone or a full clone of the first virtual machine.

4. The method of claim 3 , wherein the request to the virtual machine manager further includes the unique identifier associated with the first virtual machine.

5. The method of claim 3 , wherein the virtual machine manager is configured to record the internet protocol (IP) address of the first virtual machine when it receives the request to generate the second virtual machine, and to assign parent status to the virtual machine that has the same IP address as the recorded IP address.

6. The method of claim 3 , further comprising:

pausing the first virtual machine prior to the cloning operation; and

unpausing both virtual machines after the cloning operation is complete.

7. The method of claim 3 , wherein the virtual machine manager and the first virtual machine are configured to communicate over a network.

8. The method of claim 3 , wherein the first virtual machine is configured to communicate with the virtual machine manager using at least one of the following:

a) a virtual COM port using a pipe with a predefined name based on the unique identifier;

b) a virtual USB device; or

c) an API configured to allow communication between the virtual machine and the virtual machine manager.

9. The method of claim 1 , wherein the virtual machine forking operation further comprises:

manager to generate the second virtual machine by cloning the first virtual machine;

determining, by one of the at least two virtual machines, whether it is a parent or a clone.

10. The method of claim 1 , wherein the virtual machine manager is a hypervisor.

11. The method of claim 1 , further comprising:

generating, by the first virtual machine, one or more additional encryption keys prior to the virtual forking operation; and

decrypting the data, by the recipient virtual machine, requires at least one of the additional encryption keys.

12. A system for establishing a secure communication channel between at least two virtual machines, comprising:

a first virtual machine having a hardware processor configured to:

generate an encryption key compatible with a symmetric encryption algorithm and store the encryption key in a memory of the first virtual machine;

a virtual machine manager configured to:

generate a second virtual machine by performing a virtual machine forking operation on the first virtual machine, wherein a memory of the generated second virtual machine contains the encryption key, and wherein the virtual machine forking operation comprises:

generating, by the first virtual machine, a unique identifier associated with the first virtual machine;

communicating, by the first virtual machine, a request to the virtual machine manager to generate the second virtual machine by cloning the first virtual machine; and

assigning, by the virtual machine manager, parent or clone status to the at least two virtual machines;

wherein the hardware processor of the first or second virtual machine is configured to:

receive a communication transmitted by another of the at least two virtual machines, wherein the communication comprises data encrypted using the encryption key; and

decrypt the data, by the recipient virtual machine, using the encryption key.

13. The system of claim 12 , wherein the encryption key is a random string.

14. The system of claim 12 , wherein the second virtual machine is a linked clone or a full clone of the first virtual machine.

15. The system of claim 12 , wherein the virtual machine forking operation further comprises:

determining, by one of the at least two virtual machines, whether it is a parent or a clone.

16. The system of claim 15 , wherein the request to the virtual machine manager further includes the unique identifier associated with the first virtual machine.

17. The system of claim 12 , wherein the virtual machine manager is configured to record the internet protocol (IP) address of the first virtual machine when it receives the request to generate the second virtual machine, and to assign parent status to the virtual machine that has the same IP address as the recorded IP address.

18. The system of claim 12 , wherein the virtual machine manager is further configured to:

pause the first virtual machine prior to the cloning operation; and

unpause both virtual machines after the cloning operation is complete.

19. The system of claim 12 , wherein the virtual machine manager and the first virtual machine are configured to communicate over a network.

20. The system of claim 12 , wherein the first virtual machine is configured to communicate with the virtual machine manager using at least one of the following:

a) a virtual COM port using a pipe with a predefined name based on the unique identifier;

b) a virtual USB device; or

c) an API configured to allow communication between the virtual machine and the virtual machine manager.

21. The system of claim 12 , wherein the virtual machine manager is a hypervisor.

22. The system of claim 12 , wherein the processor of the first virtual machine is configured to:

generate one or more additional encryption keys prior to the virtual forking operation; and

wherein the processor of the first or second virtual machine is further configured to decrypt the data using at least one of the additional encryption keys.

23. A non-transitory computer readable medium comprising computer executable instructions for establishing a secure communication channel between at least two virtual machines, comprising instructions for:

generating, by a first virtual machine, an encryption key compatible with a symmetric encryption algorithm and storing the encryption key in a memory of the first virtual machine;

generating a second virtual machine by performing a virtual machine forking operation on the first virtual machine, wherein a memory of the generated second virtual machine contains the encryption key, and wherein the virtual machine forking operation comprises:

generating, by the first virtual machine, a unique identifier associated with the first virtual machine;

communicating, by the first virtual machine, a request to a virtual machine manager to generate the second virtual machine by cloning the first virtual machine; and

assigning, by the virtual machine manager, parent or clone status to the at least two virtual machines;

receiving, by one of the at least two virtual machines, a communication transmitted by another of the at least two virtual machines, wherein the communication comprises data encrypted using the encryption key; and

decrypting the data, by the recipient virtual machine, using the encryption key.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jul 18, 2019
From: UBS AG, STAMFORD BRANCH, AS ADMINISTRATIVE AND COLLATERAL AGENT
To: COREL CORPORATION; CLEARSLIDE, INC.; PARALLELS INTERNATIONAL GMBH
Reel/Frame 049787/0073 →
RELEASE OF SECURITY INTEREST RECORDED AT : REEL 047973 FRAME 0797 Recorded Jul 17, 2019
From: UBS AG, STAMFORD BRANCH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 049773/0590 →
SECURITY INTEREST Recorded Dec 21, 2018
From: PARALLELS INTERNATIONAL GMBH
To: UBS AG, STAMFORD BRANCH
Reel/Frame 047973/0797 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2017
From: ZELENOV, ANTON; DOBROVOLSKIY, NIKOLAY; BELOUSSOV, SERGUEI
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 043355/0420 →
Cited By (5)
US 12,452,219 US 12,547,543 US 12,580,892 US 12,688,315 US 12,719,843