Location-aware multi-factor authentication for virtual machine users
Disclosed systems and methods provide location-aware multi-factor authentication for VM users in combination with the prohibited users lists and disconnecting VMs based on user behavior or activity. Implementations may employ a hypervisor enabled by a lightweight, secure operating system (LSOS) as a foundational, enabling, and OS-agnostic technology for multiple uses cases. An LSOS authenticator module may generate IP location based authentication number for user authentication. An OEM Secure VM manager in Domain0 (Dom0) of a Xen cloud computing model may monitor user activity while Secure OEM Hypercall communication is employed for all communication from VM to LSOS. Embodiments may employ a LSOS VM prohibited users module and hypervisor action module to remove users and destroy VMs based on data received from Dom0, VM Manager and the user module in the VM.
1 . A method comprising:
responsive to a new user request to add a user as an authorized user of a virtual machine (VM) associated with a hypervisor running on an information handling system:
issuing, by the VM, a secure hypercall to establish a secure connection between the VM and an authenticator;
generating, by the authenticator, an authorization mapping for the user, wherein the authorization mapping is a 2-tuple data structure including:
an authorization number determined by the authenticator and;
location information indicative of an originating location of the new user request; and
storing the authorization mapping to a replay protected memory block (RPMB) within a secure boot partition of a nonvolatile memory (NVM) device of the information handling system; and
performing VM security operations including:
authenticating a VM login associated with the user against the authorization number and the location information corresponding to the user and responsive to detecting a mismatch, adding the user to a prohibited user list for the VM;
monitoring VM activity of the user and responsive to detecting the VM activity satisfying an activity trigger, adding the user to a prohibited user list corresponding to the VM; and
blocking VM access to users included in the prohibited users list.
2 . The method of claim 1 , wherein the location information comprises an IP address corresponding to the new user request.
3 . The method of claim 1 , further comprising storing the authorization mapping to a user database within the a user module of the VM.
4 . The method of claim 1 , wherein monitoring VM activity comprises monitoring VM activity with a VM manager in secure communication with the hypervisor and configured to monitor activity of all users of the VM.
5 . The method of claim 1 , wherein the hypervisor comprise a Xen hypervisor.
6 . The method of claim 5 , wherein the VM manager executes in a domain 0(Dom0) of the Xen hypervisor.
7 . The method of claim 5 , wherein the hypervisor is enabled by a secure, lightweight operating system (OS) including:
a kernel and base rootfs retrieved from the NVM device; and
an external rootfs retrieved from a cloud software development platform.
8 . The method of claim 7 , wherein the authenticator runs in the lightweight OS.
9 . The method of claim 1 , wherein satisfying the activity trigger includes any one or more of:
multiple requests from a single VM; and
network traffic exceeding a maximum permitted traffic volume.
10 . The method of claim 1 , wherein the VM security operations include terminating the VM upon detecting activity satisfying the activity trigger for multiple users of the VM.
11 . An information handling system, comprising:
a central processing unit (CPU);
a memory, including processor executable instructions that, when executed by the CPU, cause the system to perform operations including:
responsive to a new user request to add a user as an authorized user of a virtual machine (VM) associated with a hypervisor running on an information handling system:
issuing, by the VM, a secure hypercall to establish a secure connection between the VM and an authenticator;
generating, by the authenticator, an authorization mapping for the user, wherein the authorization mapping is a 2-tuple data structure including:
an authorization number determined by the authenticator and;
location information indicative of an originating location of the new user request; and
storing the authorization mapping to a replay protected memory block (RPMB) within a secure boot partition of a nonvolatile memory (NVM) device of the information handling system; and
performing VM security operations including:
authenticating a VM login associated with the user against the authorization number and the location information corresponding to the user and responsive to detecting a mismatch, adding the user to a prohibited user list for the VM;
monitoring VM activity of the user and responsive to detecting the VM activity satisfying an activity trigger, adding the user to a prohibited user list corresponding to the VM; and
blocking VM access to users included in the prohibited users list.
12 . The information handling system of claim 11 , wherein the location information comprises an IP address corresponding to the new user request.
13 . The information handling system of claim 11 , further comprising storing the authorization mapping to a user database within the a user module of the VM.
14 . The information handling system of claim 11 , wherein monitoring VM activity comprises monitoring VM activity with a VM manager in secure communication with the hypervisor and configured to monitor activity of all users of the VM.
15 . The information handling system of claim 11 , wherein the hypervisor comprise a Xen hypervisor.
16 . The information handling system of claim 15 , wherein the VM manager executes in a domain 0(Dom0) of the Xen hypervisor.
17 . The information handling system of claim 15 , wherein the hypervisor is enabled by a secure, lightweight operating system (OS) including:
a kernel and base rootfs retrieved from the NVM device; and
an external rootfs retrieved from a cloud software development platform.
18 . The information handling system of claim 17 , wherein the authenticator runs in the lightweight OS.
19 . The information handling system of claim 11 , wherein satisfying the activity trigger includes any one or more of:
multiple requests from a single VM; and
network traffic exceeding a maximum permitted traffic volume.
20 . The information handling system of claim 11 , wherein the VM security operations include terminating the VM upon detecting activity satisfying the activity trigger for multiple users of the VM.