Connectivity migration in virtual execution systems
By capturing and migrating the connectivity state of virtual machines in the virtual execution system, the problem of connection interruption during virtual machine updates is solved, achieving efficient and seamless connection migration, reducing resource consumption and impact on user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MICROSOFT TECHNOLOGY LICENSING LLC
- Filing Date
- 2020-04-22
- Publication Date
- 2026-05-26
AI Technical Summary
When applications running on virtual machines and/or guest operating systems are updated or patched, existing technologies require the connection to be stopped, forcing users to log in and authenticate again, which affects the user experience.
Seamless connectivity migration is achieved by capturing the connectivity state of the first virtual machine and migrating it to the second virtual machine, thereby re-establishing the state of applications and the operating system.
It reduces computing resources and bandwidth consumption, improves connection migration efficiency, and reduces user experience interruptions.
Smart Images

Figure CN113874838B_ABST
Abstract
Description
Background Technology
[0001] Applications and / or guest operating systems running on virtual machines may need to be updated or patched. For example, updates may need to be performed periodically to reflect the current version of the application and / or guest operating system. Alternatively, updates may be performed to correct issues identified in the application and / or guest operating system (e.g., security-related, discovered vulnerabilities, defects).
[0002] Stateful connections can be used to execute applications and / or guest operating systems. Stopping the execution of applications and / or guest operating systems on a virtual machine to perform updates / patches may terminate the connection. This can have significant negative impacts on users, such as requiring them to log in again and / or otherwise authenticate to re-establish the connection. Summary of the Invention
[0003] This document describes a system for migrating connectivity of a first virtual machine to a second virtual machine in a virtual execution system, comprising: a computer, including a processor and a memory storing computer-executable instructions thereon, which, when executed by the processor, cause the computer, at the second virtual machine, to: receive a captured state of a first instance of an application, a captured state of a first instance of a guest operating system, and captured connectivity states associated with multiple running connections between the first virtual machine and one or more client devices; establish connectivity of the multiple running connections between the second virtual machine and one or more client devices, at least in part based on the captured connectivity states; establish a state of a second instance of the guest operating system executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; establish a state of a second instance of an application executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; and synchronize the state of the second instance of the application with the state of the second instance of the operating system.
[0004] This summary provides a simplified overview of some concepts that will be further described in the detailed description below. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. Attached Figure Description
[0005] Figure 1 This is a functional block diagram illustrating a system for connectivity migration in a virtual execution system.
[0006] Figure 2 This is a functional block diagram illustrating a system for connectivity migration in a virtual execution system.
[0007] Figure 3 and Figure 4 This is a flowchart illustrating the connectivity migration method in a virtual execution system.
[0008] Figure 5 This is a flowchart illustrating a method for connectivity migration from a first virtual machine to a second virtual machine in a virtual execution system.
[0009] Figure 6 This is a flowchart illustrating a method for connectivity migration from a first virtual machine to a second virtual machine in a virtual execution system.
[0010] Figure 7 This is a functional block diagram illustrating an exemplary computing system. Detailed Implementation
[0011] The various techniques relating to connectivity migration of virtual applications and / or guest operating systems being executed are now described with reference to the accompanying drawings, wherein the same reference numerals are used throughout to refer to the same elements. In the following description, numerous specific details are set forth for illustrative purposes to provide a thorough understanding of one or more aspects. However, it will be apparent that these aspects can be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate the description of one or more aspects. Furthermore, it should be understood that functions described as being implemented by certain system components can be performed by multiple components. Similarly, for example, components can be configured to perform functions described as being performed by multiple components.
[0012] This topic discloses support for a variety of products and processes that are executed or configured to perform various actions related to the connectivity migration of an ongoing virtual application and / or guest operating system. Below are one or more exemplary systems and methods.
[0013] The aspects disclosed in this subject matter relate to the technical problem of migrating connectivity information of running virtual applications and / or guest operating systems. Technical features associated with solving this problem include: capturing the state of a first instance of an application running on a first virtual machine; capturing the state of a first instance of a guest operating system running on the first virtual machine; capturing connectivity states associated with multiple running connections between the first virtual machine and one or more client devices; providing the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and the captured connectivity states to a second virtual machine; establishing connectivity between the second virtual machine and one or more client devices based at least in part on the captured connectivity states; establishing the state of a second instance of the guest operating system running on the second virtual machine based at least in part on the captured state of the first instance of the guest operating system; establishing the state of a second instance of the application running on the second virtual machine based at least in part on the captured state of the first instance of the guest operating system; and synchronizing the state of the second instance of the application with the state of the second instance of the operating system. Therefore, these technical features exhibit the following technical effects: migrating connectivity information of running virtual applications and / or guest operating systems more efficiently and effectively while preserving existing connections, for example, reducing computer resource (e.g., processing time) and / or bandwidth consumption.
[0014] Furthermore, the term "or" is intended to mean inclusive "or" rather than exclusive "or". That is, unless otherwise specified or clearly understood from the context, the phrase "X adopts A or B" is intended to mean any natural inclusive arrangement. Specifically, the phrase "X adopts A or B" is satisfied in any of the following cases: X adopts A; X adopts B; or X adopts both A and B. Additionally, the articles "a" and "an" as used in this application and the appended claims should generally be interpreted as meaning "one or more" unless otherwise specified or clearly understood from the context to refer to the singular form.
[0015] As used herein, the terms “component” and “system,” and their various forms (e.g., component, system, subsystem, etc.), are intended to refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution. For example, a component can be, but is not limited to, a process running on a processor, a processor, an object, an instance, an executable file, a thread of execution, a program, and / or a computer. For illustration, an application running on a computer and the computer itself can both be components. One or more components may reside within a process and / or a thread of execution, and components may be localized on one computer and / or distributed across two or more computers. Furthermore, as used herein, the term “exemplary” is intended to mean as an illustration or example of something and is not intended to indicate preference.
[0016] Terminating the execution of applications and / or guest operating systems on a virtual machine to perform application and / or guest operating system updates / patches may terminate stateful connections. This can have significant negative impacts on users, such as requiring them to log in again and / or otherwise authenticate to re-establish a connection.
[0017] This document describes a system and method for migrating connectivity from a first virtual machine (VM) to a second VM within a virtual execution system (e.g., live migration of virtual applications, guest operating systems, and / or running connections). Connectivity migration can be performed to facilitate updates and / or patching of virtual applications and / or guest operating systems running on the first VM. In response to a migration request, the application and / or guest operating system is responsible for capturing the state (if any) required to rebuild the application and / or guest operating system on the second VM. This captured state can be provided to the application or guest operating system on the second VM to rebuild the application and / or guest operating system.
[0018] The first virtual machine also captures information about connectivity status associated with the virtual application and / or guest operating system (e.g., established running / real-time connections). The captured connectivity status is then provided to the second virtual machine to seamlessly re-establish streaming connections for the application and / or guest operating system on the second virtual machine.
[0019] For purposes of explanation and not limitation, the systems and methods described herein are discussed in the context of virtual machine migration. However, in some embodiments, the systems and methods described herein can be used to migrate native systems.
[0020] refer to Figure 1 The diagram illustrates a system for connectivity migration from a first virtual machine to a second virtual machine within a virtual execution system 100. System 100 can perform connectivity migrations to allow updates and / or patches to application 104 and / or guest operating system 108 that are running on the first virtual machine 112.
[0021] For example, several scenarios may require connectivity migration (e.g., Transmission Control Protocol (TCP) information) from one virtual machine to another. This includes Network Virtual Applications (NVAs) operating in active-passive or n-active modes, where an NVA expects to migrate connections to another instance when one instance fails. Similarly, SQL Data Warehouses (SQL-DWs) can have long-lived TCP connections for long-running queries, and TCP connections can be migrated from one instance to another, for example, when a VM needs to be updated (e.g., guest operating system updates and / or rollout of updated applications) and / or fails. System 100 facilitates the migration of running / real-time connections (e.g., TCP / IP) at the infrastructure level.
[0022] In some embodiments, the migration request may be generated by application 104. For example, application 104 may need to be updated to a new version. In some embodiments, the migration request may be generated by guest operating system 108. For example, guest operating system 108 may need to be patched. In some embodiments, the migration request may be generated by first virtual machine 112 (e.g., host operating system). For example, first virtual machine 112 may want to update application 104 and / or guest operating system 108.
[0023] In response to a migration request, application 104 and / or guest operating system 108 may be responsible for capturing the states (if any) required to rebuild application 104 (e.g., SQL session state) and / or guest operating system 108 on the second virtual machine 124 as application 116 and guest operating system 120, respectively. In this manner, the captured states can be provided to application 120 and / or guest operating system 124 on the second virtual machine 124 to rebuild application 104 and / or guest operating system 108 (of the first virtual machine 112) on the second virtual machine 124. The first virtual machine 112 and the second virtual machine 124 may communicatively connect to one or more client devices 126 using network 128 (e.g., the Internet).
[0024] In some embodiments, application 116 and application 104 are instances of the same version of the application. In some embodiments, application 116 and application 104 are instances of different versions of the application. In some embodiments, guest operating system 120 and guest operating system 108 are instances of the same version of the guest operating system. In some embodiments, guest operating system 120 and guest operating system 108 are instances of different versions of the guest operating system.
[0025] The first virtual machine 112 may further include a connectivity component 130 that manages the connectivity of the first virtual machine 112, including application 104 and / or guest operating system 108. In some embodiments, the connectivity component 130 employs a hierarchical model, as described below. The connectivity state capture component 132 of the first virtual machine 112 further captures the connectivity state associated with application 104 and / or guest operating system 108. The captured connectivity state is then provided to the connectivity state recovery component 136 of the second virtual machine 124 to seamlessly re-establish streaming connections for the application and / or guest operating system on the second virtual machine 116 via the connectivity component 140.
[0026] In some embodiments, application 104, guest operating system 108, and connectivity state capture component 132 receive migration requests substantially simultaneously. In this manner, the state of application 104, the state of guest operating system 108, and the connectivity state can be captured substantially simultaneously. In some embodiments, the state of application 104, the state of guest operating system 108, and / or the connectivity state can be captured substantially in parallel. In some embodiments, the state of application 104, the state of guest operating system 108, and / or the connectivity state can be captured sequentially. In some embodiments, once a migration request has been received and / or a determination has been made that the migration can be safely performed, application 116, guest operating system 120, and / or connectivity component 130 perform non-migration processing.
[0027] In some embodiments, a migration request is first provided to application 104 and / or guest operating system 108. For example, the transaction executed by application 104 and / or guest operating system 108 may be completed and / or placed in an expected state (e.g., suspended, failed) to allow application 104 and / or guest operating system 108 to be seamlessly migrated to the second virtual machine 116 (e.g., without significantly disrupting the execution of application 104 as experienced by the user). Once application 104 and / or guest operating system 108 determines that the migration can be safely performed (e.g., application 104 and / or guest operating system 108 is in a stable state), a migration request is provided to the first virtual machine 112, and application 104 and / or guest operating system 108 captures the state (if any).
[0028] In some embodiments, the connectivity of the first virtual machine 112 can be viewed as a hierarchical model:
[0029]
[0030] Table 1
[0031] In some embodiments, application 104 and / or guest operating system 108 are responsible for capturing the states (if any) associated with layers 5, 6, and / or 7 of the hierarchical model in Table 1. Connectivity state capture component 132 may capture the connectivity states associated with layers 2, 3, and / or 4 of the hierarchical model in Table 1.
[0032] In some embodiments, regarding the transport layer (Layer 4), connectivity status includes information about firewall status, Transport Security Layer (TLS), encryption and / or decryption keys, and certificate information associated with the connectivity of application 104. In some embodiments, regarding the network layer (Layer 3), connectivity information may include the Internet Protocol (IP) address of the first virtual machine 112.
[0033] In some embodiments, connectivity component 130 utilizes TCP to track information about the connection to the first virtual machine 112. At least some of this information may be stored in a transmission control block (TCB), a data structure that maintains information about endpoints (IP and port numbers) (e.g., socket handles, connection status, runtime data about packets being exchanged) and / or information about buffers used for sending and receiving data. The TCB may further manage send and receive sequence numbers.
[0034] In response to a migration request, the connectivity state capture component 132 may save the state associated with the running connection, including connection establishment status and / or sequence number. In some embodiments, the connectivity state capture component 132 may save some or all of the information stored in the TCB. In some embodiments, the connectivity state capture component 132 may also store the IP address of the first virtual machine for use in migrating that IP address to a second virtual machine (e.g., in the absence of a load balancer).
[0035] In some embodiments, the states captured by application 104, guest operating system 108, and / or connectivity state capture component 132 are provided separately to the second virtual machine 124. In some embodiments, the states captured by application 104, guest operating system 108, and / or connectivity state capture component 132 are serialized into predefined data structures and provided to the second virtual machine 124 (e.g., securely).
[0036] The second virtual machine 124 uses the state captured by the application 104, guest operating system 108 and / or connectivity state capture component 132 of the first virtual machine 112 to re-establish the application and / or guest operating system as the application 116, guest operating system 120 and / or connectivity component 140 on the second virtual machine 124, respectively.
[0037] In some embodiments, the application 116, guest operating system 120, and / or connectivity component 140 of the second virtual machine 124 are executing before the capture state is received. Thereafter, the capture state is distributed to the application 116, guest operating system 120, and / or connectivity component 140 (e.g., sequentially or substantially in parallel) to rebuild the application.
[0038] The connectivity state recovery component 136 of the second virtual machine 124 can utilize the state captured by the connectivity state capture component 132 to re-establish connections on the second virtual machine 124 (e.g., all running connections are migrated from the first virtual machine 112 to the second virtual machine 124). In some embodiments, connections can be re-established in parallel, i.e., layers 2, 3, and 4 are re-established substantially simultaneously. In some embodiments, connections can be re-established sequentially, first layer 2, then layer 3, and then layer 4. Therefore, firewall rules and / or state associated with a specific connection can be migrated from the first virtual machine 112 to the second virtual machine 124.
[0039] In some embodiments, the connectivity state recovery component 136 can write to or overwrite the TCB of the connectivity component 140 on the second virtual machine 124. In this way, the socket handle used by application 104 can continue to be used by application 116.
[0040] In some embodiments, information about the socket handle of the TCB of connectivity component 140 can be provided to application 116. Therefore, the socket handle used by application 116 can be updated to reflect the current value.
[0041] In some embodiments, connectivity component 140 may store information about the mapping of socket handles in the TCB of connectivity component 130 to socket handles in the TCB of connectivity component 140. Therefore, application 116 may continue to use the socket handles utilized by application 104, wherein connectivity component 140 translates the socket handles before communication is performed using the socket handles.
[0042] In some embodiments, the elapsed time for the capture state, transmission state, and recovery state is less than a predefined TCP / IP timeout period (e.g., nine seconds). In this way, once the migration is performed, packets received (and not processed) by the first virtual machine 112 will be retransmitted and processed by the second virtual machine 124. Therefore, although the client may experience packet loss and delay, the retries will recover from the loss with minimal impact on the client (e.g., without losing the connection).
[0043] refer to Figure 2A system for connectivity migration in a virtual execution system 200 is illustrated. System 200 includes a first virtual machine 112 and a second virtual machine 124, as described above. System 200 also includes a load balancer component 204 that acts as an intermediary between a client device 126 and the virtual first virtual machine 112.
[0044] Load balancer component 204 allows multiple virtual machines to be associated with a single virtual network. Network messages addressed to a virtual network address are received by load balancer component 204, which determines which of the multiple virtual machines will handle the network message. Load balancer 204 then forwards the network message to the specific virtual machine.
[0045] During connectivity migration, load balancer component 204 receives a connectivity migration request from first virtual machine 112. In some embodiments, application 104 and / or guest operating system 108 may invoke an application programming interface (API) on load balancer component 204. In response to the receipt of the migration request, load balancer component 204 temporarily stops forwarding network messages that would otherwise be forwarded to first virtual machine 112.
[0046] In some embodiments, the IP address of the first virtual machine 112 is not migrated to the second virtual machine 124. Instead, the load balancer component 204 may update the mapping performed by the load balancer component 204 to redirect traffic specified to the IP address of the first virtual machine 112 to the IP address of the second virtual machine 124.
[0047] Once the status captured by application 104, guest operating system 108 and / or connectivity status capture component 132 is provided to the second virtual machine 124, the load balancer component 204 can be updated to restart forwarding network messages to the first virtual machine 112 to the second virtual machine 124 (e.g., because the second virtual machine 124 has been reassigned the IP address previously assigned to the first virtual machine 112).
[0048] In some embodiments, the ability to request connection migration can be configured by an administrator associated with application 104 running on the first virtual machine 112.
[0049] Figures 3-6 An exemplary method relating to connectivity migration in a virtual execution system is illustrated. Although the method is shown and described as a series of actions executed sequentially, it should be understood and appreciated that the method is not limited by the order of the sequence. For example, some actions may be performed in a different order than those described herein. Furthermore, one action may be performed concurrently with another. Moreover, in some cases, implementing the method described herein may not require all actions.
[0050] Furthermore, the actions described herein can be computer-executable instructions, which can be implemented by one or more processors and / or stored on one or more computer-readable media. Computer-executable instructions can include routines, subroutines, programs, threads of execution, etc. Moreover, the results of the actions of the method can be stored in a computer-readable medium, displayed on a display device, etc.
[0051] refer to Figure 3 and Figure 4 The illustration depicts a method for connectivity migration in a virtual execution system 300. In some embodiments, method 300 is executed by system 100 and / or system 200. In some embodiments, method 300 is executed in response to receiving a connectivity migration request.
[0052] At 304, the load balancer (e.g., load balancer component 204) stops forwarding network messages to the first virtual machine. At 308, the state of the first instance of the application running on the first virtual machine is captured. At 312, the state of the first instance of the guest operating system running on the first virtual machine is captured. At 316, the connectivity state associated with multiple running connections between the first virtual machine and one or more client devices is captured. At 320, the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and / or the captured connectivity state are provided to the second virtual machine.
[0053] At 324, based at least in part on the captured connectivity state, a plurality of running connections are established between the second virtual machine and one or more client devices. At 328, based at least in part on the captured state of the first instance of the guest operating system, the state of the second instance of the guest operating system running on the second virtual machine is established. At 332, based at least in part on the captured state of the first instance of the guest operating system, the state of the second instance of the application running on the second virtual machine is established. At 336, the load balancer resumes forwarding network messages destined for the first virtual machine to the second virtual machine.
[0054] Turning Figure 5 A method for connectivity migration from a first virtual machine to a second virtual machine in a virtual execution system 500 is illustrated. In some embodiments, method 400 is executed by the first virtual machine 112.
[0055] At 510, the state of the first instance of the application running on the first virtual machine is captured. At 520, the state of the first instance of the guest operating system running on the first virtual machine is captured. At 530, the connectivity state associated with multiple running connections between the first virtual machine and one or more client devices is captured. At 540, the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and / or the captured connectivity state are provided to the second virtual machine.
[0056] Next, refer to Figure 6 The illustration depicts a method for connectivity migration from a first virtual machine to a second virtual machine in a virtual execution system 600. In some embodiments, method 400 is executed by the second virtual machine 124.
[0057] At 610, the second virtual machine receives the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and / or the captured connectivity state of the first virtual machine. At 620, based at least in part on the captured connectivity state, a plurality of running connections are established between the second virtual machine and one or more client devices. At 630, based at least in part on the captured state of the first instance of the guest operating system, the state of a second instance of the guest operating system executing on the second virtual machine is established. At 640, based at least in part on the captured state of the first instance of the guest operating system, the state of a second instance of the application executing on the second virtual machine is established.
[0058] At 650, the state of the second instance of the application is synchronized with the state of the second instance of the guest operating system. In some embodiments, information about the socket handle of the TCB of the second virtual machine can be provided to the second instance of the application. Therefore, the socket handle used by the second instance of the application can be updated to reflect the current value.
[0059] In some embodiments, the second virtual machine may store information about the mapping of socket handles in the TCB of the first virtual machine to socket handles in the TCB of the second virtual machine. Therefore, the second instance of the application can continue to use the socket handles utilized by the first instance of the application, wherein the second virtual machine translates the socket handles before communicating using them.
[0060] This document describes a system for migrating from a first virtual machine to a second virtual machine in a virtual execution system, comprising: a computer, including a processor and a memory storing computer-executable instructions thereon, which, when executed by the processor, cause the computer, at the second virtual machine, to: receive a captured state of a first instance of an application, a captured state of a first instance of a guest operating system, and captured connectivity states associated with a plurality of running connections between the first virtual machine and one or more client devices; establish connectivity of the plurality of running connections between the second virtual machine and one or more client devices, at least in part based on the captured connectivity states; establish a state of a second instance of the guest operating system executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; establish a state of a second instance of an application executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; and synchronize the state of the second instance of the application with the state of the second instance of the operating system.
[0061] The system may include a memory on which additional computer-executable instructions are stored, which, when executed by a processor, cause the computer to: at a first virtual machine: capture the state of a first instance of an application running on the first virtual machine; capture the state of a first instance of a guest operating system running on the first virtual machine; capture connectivity states associated with multiple running connections between the first virtual machine and one or more client devices; and provide a second virtual machine with the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and the captured connectivity states.
[0062] The system may also include: capturing connectivity state including: storing information about firewall state associated with connectivity to a first instance of the application, and storing information about transport security layer associated with connectivity to the first instance of the application.
[0063] The system may further include: capturing connectivity state including storing information about at least one of an encryption key or decryption key associated with the connectivity of a first instance of the application. The system may further include: capturing connectivity state including storing information about the Internet Protocol (IP) address of the first virtual machine. The system may further include: wherein capturing connectivity state includes storing information about a transport control block associated with the running connection of the first virtual machine.
[0064] The system may further include: a transmission control block maintaining information about endpoints, the state of running connections, data about packets being exchanged, and information about buffers used for sending and receiving data. The system may further include: the capture state of a first instance of the application, the capture state of a first instance of the guest operating system, and the captured connectivity state are serialized into a predefined data structure. The system may further include: a second instance of the guest operating system and a second instance of the application are executing on a second virtual machine before the capture state of the first instance of the application, the capture state of the first instance of the guest operating system, and the captured connectivity state are provided.
[0065] The system may include a memory storing additional computer-executable instructions, which, when executed by a processor, cause the computer to: respond to a connectivity migration request by stopping the forwarding of network messages to the first virtual machine via a load balancer; and, after the state of a second instance of an application running on the second virtual machine is established, resume forwarding network messages to the first virtual machine to the second virtual machine. The system may also include a version of the application that is different from the second instance of the application.
[0066] This document describes a method for migrating from a first virtual machine to a second virtual machine in a virtual execution system, comprising: at the second virtual machine: receiving a captured state of a first instance of an application, a captured state of a first instance of a guest operating system, and a captured connectivity state associated with multiple runtime connections between the first virtual machine and one or more client devices; establishing connectivity between the multiple runtime connections between the second virtual machine and one or more client devices, at least in part based on the captured connectivity states; establishing a state of a second instance of the guest operating system executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; establishing a state of a second instance of the application executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; and synchronizing the state of the second instance of the application with the state of the second instance of the operating system.
[0067] The method may further include: capturing the state of a first instance of an application running on a first virtual machine; capturing the state of a first instance of a guest operating system running on the first virtual machine; capturing connectivity states associated with multiple running connections between the first virtual machine and one or more client devices; and providing the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and the captured connectivity states to a second virtual machine.
[0068] The method may further include: capturing connectivity state by storing information about firewall state associated with connectivity to a first instance of the application, and storing information about transport security layers associated with connectivity to the first instance of the application. The method may further include: capturing connectivity state by storing information about at least one of an encryption key or a decryption key associated with connectivity to the first instance of the application. The method may further include: capturing connectivity state by storing information about the Internet Protocol (IP) address of the first virtual machine. The method may further include: capturing connectivity state by storing information about transport control blocks associated with the running connection of the first virtual machine.
[0069] This document describes a computer storage medium storing computer-readable instructions that, when executed, cause a computing device to: receive a captured state of a first instance of an application, a captured state of a first instance of a guest operating system, and a captured connectivity state associated with a plurality of running connections between a first virtual machine and one or more client devices; establish connectivity of the plurality of running connections between a second virtual machine and one or more client devices, at least in part based on the captured connectivity states; establish a state of a second instance of a guest operating system executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; establish a state of a second instance of an application executing on the second virtual machine, at least in part based on the captured state of the first instance of the guest operating system; and synchronize the state of the second instance of the application with the state of the second instance of the operating system.
[0070] The computer storage medium may store additional computer-readable instructions, which, when executed, cause the computing device to: capture connectivity state by storing information about firewall status associated with connectivity to the first instance of the application, information about transport security layers associated with connectivity to the first instance of the application, and information about at least one of encryption or decryption keys associated with connectivity to the first instance of the application. The computer storage medium may also store additional computer-readable instructions, which, when executed, cause the computing device to: capture connectivity state by storing information about transport control blocks associated with the running connection to the first virtual machine, wherein the transport control blocks maintain information about endpoints, the state of the running connection, data of packets being exchanged, and information about buffers used for sending and receiving data.
[0071] refer to Figure 7The illustration depicts an example general-purpose computer or computing device 702 (e.g., mobile phone, desktop computer, laptop computer, tablet computer, watch, server, handheld device, programmable consumer or industrial electronic equipment, set-top box, gaming system, computing node, etc.). For example, computing device 702 could be used in systems for detecting malware by monitoring the execution of configuration process 100 and / or by monitoring the execution of configuration process 200.
[0072] Computer 702 includes one or more processors 720, memory 730, system bus 740, one or more mass storage devices 750, and one or more interface components 770. The system bus 740 is communicatively coupled to at least the aforementioned system components. However, it should be understood that, in its simplest form, computer 702 may include one or more processors 720 coupled to memory 730, which execute various computer-executable actions, instructions, and / or components stored in memory 730. For example, instructions may be instructions for implementing functions described as being implemented by the aforementioned one or more components, or instructions for implementing one or more of the aforementioned methods.
[0073] One or more processors 720 may be implemented using a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. The general-purpose processor may be a microprocessor, but alternatively, the processor may be any processor, controller, microcontroller, or state machine. One or more processors 720 may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, a multi-core processor, one or more microprocessors combined with a DSP core, or any other such configuration. In one embodiment, one or more processors may be a graphics processor.
[0074] Computer 702 may include or otherwise interact with various computer-readable media to support the control of computer 702 to implement one or more aspects of the claimed subject matter. Computer-readable media may be any available media that can be accessed by computer 702, and includes volatile and non-volatile media as well as removable and non-removable media. Computer-readable media may include two distinct and mutually exclusive types: computer storage media and communication media.
[0075] Computer storage media includes volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes storage devices such as memory devices (e.g., random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), etc.), magnetic storage devices (e.g., hard disks, floppy disks, magnetic cartridges, magnetic tapes, etc.), optical disks (e.g., optical discs (CD), DVDs, etc.), and solid-state devices (e.g., solid-state drives (SSD), flash drives, etc., cards, sticks, key drives, etc.), or any other similar media that, in contrast to transmission or communication, store information desired by computer 702. Therefore, computer storage media exclude modulated data signals and content described relative to communication media.
[0076] Communication media implement computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and include any information transmission medium. The term "modulated data signal" refers to a signal whose characteristics, one or more of which are set or altered in a manner capable of encoding information in the signal. By way of example and not limitation, communication media include wired media such as wired networks or direct wired connections, and wireless media such as acoustic, RF, infrared, and other wireless media.
[0077] Memory 730 and mass storage device 750 are examples of computer-readable storage media. Depending on the exact configuration and type of the computing device, memory 730 may be volatile (e.g., RAM), non-volatile (e.g., ROM, flash memory, etc.), or some combination of both. As an example, the basic input / output system (BIOS) (which includes basic routines such as transferring information between elements within computer 702 during startup) may be stored in non-volatile memory, while volatile memory may be used as external cache memory to support the processing of one or more processors 720, etc.
[0078] Mass storage device 750 includes removable / non-removable, volatile / non-volatile computer storage media for storing large amounts of data relative to memory 730. For example, mass storage device 750 includes, but is not limited to, one or more devices such as disk or optical disk drives, floppy disk drives, flash memory, solid-state drives, or memory sticks.
[0079] The memory 730 and mass storage device 750 may include or store an operating system 760, one or more applications 762, one or more program modules 764, and data 766. The operating system 760 is used to control and allocate the resources of the computer 702. Applications 762 include one or both system and application software, and can utilize the operating system 760's management of resources through program modules 764 and data 766 stored in the memory 730 and / or one or more mass storage devices 750 to perform one or more actions. Therefore, applications 762 can transform the general-purpose computer 702 into a special-purpose machine according to the logic provided therein.
[0080] All or part of the claimed subject matter may be implemented using standard programming and / or engineering techniques to produce software, firmware, hardware, or any combination thereof to control a computer to perform the disclosed functions. By way of example and not limitation, system 100 or a portion thereof may be or form part of application 762 and includes one or more modules 764 and data 766 stored in memory and / or one or more mass storage devices 750, the functions of which may be implemented when executed by one or more processors 720.
[0081] In some embodiments, one or more processors 720 may correspond to a system-on-a-chip (SOC) or similar architecture, including or in other words integrating hardware and software on a single integrated circuit substrate. Here, one or more processors 720 may include one or more processors and at least memory similar to one or more processors 720 and memory 730. Conventional processors include a minimal amount of hardware and software and rely extensively on external hardware and software. In contrast, SOC implementations of processors are more powerful because they embed hardware and software that enable the implementation of specific functions with minimal or no reliance on external hardware and software. For example, system 100 and / or associated functions can be embedded within the hardware of an SOC architecture.
[0082] Computer 702 also includes one or more interface components 770 communicatively coupled to system bus 740 and supporting interaction with computer 702. As an example, interface component 770 may be a port (e.g., serial, parallel, PCMCIA, USB, FireWire, etc.) or an interface card (e.g., audio, video, etc.). In one example implementation, interface component 770 may be implemented as a user input / output interface to enable a user to input commands and information into computer 702, such as through one or more gestures or voice input, through one or more input devices (e.g., pointing devices, such as a mouse, trackball, stylus, touchpad, keyboard, microphone, joystick, gamepad, satellite dish, scanner, camera, other computer, etc.). In another example implementation, interface component 770 may be implemented as an output peripheral interface to provide output to a display (e.g., LCD, LED, plasma, etc.), speaker, printer, and / or other computer, etc. Furthermore, interface component 770 may be implemented as a network interface to enable communication with other computing devices (not shown), such as via wired or wireless communication links.
[0083] The above description includes examples of various aspects of the claimed subject matter. Of course, for the purpose of describing the claimed subject matter, it is impossible to describe every conceivable combination of components or methods; however, those skilled in the art will recognize that many other combinations and arrangements of the disclosed subject matter are possible. Therefore, the disclosed subject matter is intended to encompass all such changes, modifications, and variations that fall within the spirit and scope of the appended claims. Furthermore, the use of the term "comprising" in the detailed description or claims is intended to be inclusive in a manner similar to the term "including," as interpreted when "comprising" is used as a transitional word in the claims.
Claims
1. A system for migrating from a first virtual machine to a second virtual machine in a virtual execution system, comprising: A processor and a memory thereon storing computer-executable instructions, which, when executed by the processor, cause the system to: The connectivity between the second virtual machine and the one or more client devices is established based at least in part on the captured connectivity state of the multiple running connections between the first virtual machine and one or more client devices, wherein the captured connectivity state is obtained by at least one of the following: an application running on the first virtual machine, a guest operating system running on the first virtual machine, or a connectivity state capture component of the first virtual machine; The state of the second instance of the guest operating system executing on the second virtual machine is established based at least in part on the captured state of the first instance of the guest operating system executing on the first virtual machine; The state of the second instance of the application running on the second virtual machine is established based at least in part on the captured state of the first instance of the application running on the first virtual machine; The second virtual machine stores information about the mapping of socket handles in the transport control block of the first virtual machine to socket handles in the transport control block of the second virtual machine, and maps the socket handles of the first instance of the application to the second instance of the application. as well as Synchronize the state of the second instance of the application with the state of the second instance of the client operating system.
2. The system of claim 1, wherein the memory stores computer-executable instructions thereon, which, when executed by the processor, cause the system to: Capture the state of the first instance of the application running on the first virtual machine; Capture the state of the first instance of the guest operating system executing on the first virtual machine; Capture connectivity status associated with the plurality of runtime connections between the first virtual machine and the one or more client devices; as well as The second virtual machine is provided with the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and the captured connectivity state.
3. The system of claim 2, wherein, Capturing connectivity status includes storing information about firewall status associated with connectivity to the first instance of the application, and storing information about transport security layers associated with connectivity to the first instance of the application.
4. The system according to claim 2, wherein, Capturing connectivity status includes storing information about at least one of an encryption key or a decryption key associated with the connectivity of the first instance of the application.
5. The system according to claim 2, wherein, Capturing connectivity status includes storing information about the Internet Protocol (IP) address of the first virtual machine.
6. The system according to claim 2, wherein, Capturing connectivity status includes storing information about transport control blocks associated with the running connection of the first virtual machine.
7. The system according to claim 6, wherein, The transmission control block maintains: information about the endpoints, the status of the running connection, data about the packets being exchanged, and information about the buffers used for sending and receiving data.
8. The system according to claim 1, wherein, The capture state of the first instance of the application, the capture state of the first instance of the guest operating system, and the captured connectivity state are serialized into a predefined data structure.
9. The system according to claim 1, wherein, Before the capture state of the first instance of the application, the capture state of the first instance of the guest operating system, and the captured connectivity state are provided, the second instance of the guest operating system and the second instance of the application are executing on the second virtual machine.
10. The system of claim 1, wherein the memory stores computer-executable instructions thereon, which, when executed by the processor, cause the system to: Suspend the forwarding of network messages from the load balancer component to the first virtual machine; and After the state of the second instance of the application running on the second virtual machine has been established, the load balancer component forwards network messages directed to the first virtual machine to the second virtual machine.
11. The system according to claim 1, wherein, The first instance of the application is a different version of the application compared to the second instance of the application.
12. A method for migrating from a first virtual machine to a second virtual machine in a virtual execution system, comprising: The connectivity between the second virtual machine and the one or more client devices is established based at least in part on the captured connectivity state of the multiple running connections between the first virtual machine and one or more client devices, wherein the captured connectivity state is obtained by at least one of the following: an application running on the first virtual machine, a guest operating system running on the first virtual machine, or a connectivity state capture component of the first virtual machine; The state of the second instance of the guest operating system executing on the second virtual machine is established based at least in part on the captured state of the first instance of the guest operating system executing on the first virtual machine; The state of the second instance of the application running on the second virtual machine is established based at least in part on the captured state of the first instance of the application running on the first virtual machine; The second virtual machine stores information about the mapping of socket handles in the transport control block of the first virtual machine to socket handles in the transport control block of the second virtual machine, so as to map the socket handles of the first instance of the application to the second instance of the application. as well as Synchronize the state of the second instance of the application with the state of the second instance of the client operating system.
13. The method of claim 12, further comprising: Capture the state of the first instance of the application running on the first virtual machine; Capture the state of the first instance of the guest operating system running on the first virtual machine; Capture connectivity status associated with the plurality of runtime connections between the first virtual machine and the one or more client devices; as well as The second virtual machine is provided with the captured state of the first instance of the application, the captured state of the first instance of the guest operating system, and the captured connectivity state.
14. The method according to claim 13, wherein, Capturing connectivity status includes storing information about firewall status associated with connectivity to the first instance of the application, and storing information about transport security layers associated with connectivity to the first instance of the application.
15. The method according to claim 13, wherein, Capturing connectivity status includes storing information about at least one of an encryption key or a decryption key associated with the connectivity of the first instance of the application.
16. The method according to claim 13, wherein, Capturing connectivity status includes storing information about the Internet Protocol (IP) address of the first virtual machine.
17. The method according to claim 13, wherein, Capturing connectivity status includes storing information about transport control blocks associated with the running connection of the first virtual machine.
18. A non-volatile computer storage medium storing computer-readable instructions, which, when executed, cause a computing device to: The connectivity between a second virtual machine and the one or more client devices is established based at least in part on the captured connectivity state of a plurality of running connections between a first virtual machine and one or more client devices, wherein the captured connectivity state is obtained by at least one of the following: an application running on the first virtual machine, a guest operating system running on the first virtual machine, or a connectivity state capture component of the first virtual machine; The state of the second instance of the guest operating system executing on the second virtual machine is established based at least in part on the captured state of the first instance of the guest operating system executing on the first virtual machine; The state of the second instance of the application running on the second virtual machine is established based at least in part on the captured state of the first instance of the application running on the first virtual machine; The second virtual machine stores information about the mapping of socket handles in the transport control block of the first virtual machine to socket handles in the transport control block of the second virtual machine, and maps the socket handles of the first instance of the application to the second instance of the application. as well as Synchronize the state of the second instance of the application with the state of the second instance of the client operating system.
19. The non-volatile computer storage medium of claim 18, further storing additional computer-readable instructions, which, when executed, cause the computing device to capture connectivity state by: storing information about firewall state associated with connectivity to the first instance of the application, storing information about transport security layers associated with connectivity to the first instance of the application, and storing information about at least one of encryption or decryption keys associated with connectivity to the first instance of the application.
20. The non-volatile computer storage medium of claim 18, storing additional computer-readable instructions that, when executed, cause the computing device to: capture a connectivity state by storing information about a transmission control block associated with the running connection of the first virtual machine, and the transmission control block maintaining: information about endpoints, the state of the running connection, data about packets being exchanged, and information about buffers used for sending and receiving data.