METHOD FOR CONTROLLING A DISTRIBUTED COMPUTING SYSTEM AND ASSOCIATED DEVICES

DE602021047696T2Active Publication Date: 2026-02-11BYO NETWORKS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602021047696
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-05-20
Filing Date
2021-05-18
Publication Date
2026-02-11
Estimated Expiration
2041-05-18

AI Technical Summary

Technical Problem

Existing virtual machine migration across different network infrastructures is limited by the need for rebuilding interactions, resulting in poor portability and security concerns in distributed computer systems.

Method used

A control process for a distributed computer system that involves creating a secondary network environment with isolated access rights, allowing network elements to be transferred and activated with lower access rights, ensuring the user maintains control without granting full access to the cloud operator.

Benefits of technology

Enhances virtual machine portability and security by allowing user-controlled access while preventing cloud operator access to sensitive network elements, thus maintaining system integrity.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method for controlling a distributed computer system. The present invention also relates to a virtual machine and a distributed computer system involved in the control method.

[0002] The present invention relates to the field of cloud computing or distributed computing, which refers to access to computing services (servers, storage, networking, software) via the Internet (the "cloud") through an operator providing a specific network infrastructure.

[0003] In the case of a public network (also referred to as a "public cloud") or a mixed public and private network, an end user (e.g., a company) uses the operator's infrastructure to run virtual machines.

[0004] In computing, a virtual machine (often abbreviated as VM) is an illusion of a computer system created by emulation software or instantiated on a hypervisor. The emulation software simulates the presence of hardware and software resources such as memory, the processor, the hard drive, and even the operating system and drivers, allowing programs to run under the same conditions as the simulated machine.

[0005] More specifically, such a network infrastructure allows the virtual machine user to access programs, data, or services that the virtual machines produce.

[0006] The network infrastructure is also responsible for the initial configuration of virtual machines during their first instantiation phase. Such instantiation involves, on the one hand, executing programs provided by the operator to adapt the virtual machine to the infrastructure, and on the other hand, configuring the infrastructure's network to allow the creation of the virtual machine.

[0007] Therefore, migrating a virtual machine from one operator's infrastructure to another operator's infrastructure requires rebuilding all the interactions the virtual machine has with the first operator's infrastructure before transferring it to the second operator's. This necessitates the involvement of both the virtual machine's user and two operators, resulting in limited virtual machine portability.

[0008] It is known from US patent 2018 / 0074839 A1 that systems, processes, and computer media are used to configure a network. Several virtual devices are created. Each of these devices is associated with a corresponding virtual container. The virtual devices are then connected to a physical device, which is itself associated with a host container, to enable communication between the virtual devices and the physical device through a network namespace.

[0009] It is also known from the document entitled "Introducing Linux Network Namespaces - Scott's Weblog", September 4, 2013, pages 1 to 6, retrieved from the Internet URL:https: / / blog.scottlowe.org / 2013 / 09 / 04 / introducing-linux-network-namespaces / , the use of network namespaces.

[0010] There is therefore a need for a control process for a distributed computer system that allows for better portability of a virtual machine while maintaining a good level of security for all the elements that are part of the distributed computer system.

[0011] To this end, the present description proposes a method for controlling a distributed computer system, the method being according to claim 1.

[0012] According to particular embodiments, the control method includes one or more of the features of claims 2 to 5 where technically possible.

[0013] This description also describes a virtual machine suitable for implementing a method of controlling a distributed computer system, the virtual machine being according to claim 6.

[0014] This description also applies to a distributed computer system comprising at least one virtual machine as previously described.

[0015] Other features and advantages of the invention will become apparent from the following description of embodiments of the invention, given by way of example only and with reference to the drawings which are: figure 1 a schematic representation of a distributed computer system, figure 2 a schematic representation of part of such a distributed computer system, and figure 3 , a flowchart of an example of the implementation of a distributed computer system control process of the figure 1 .

[0016] A distributed computer system 8 is schematically illustrated on the figure 1 .

[0017] The distributed computing system 8 is an infrastructure 9 controlled by an operator in connection with terminals 10 (computers in this case). Such an operator is often called a cloud operator, referring to the English term "cloud," sometimes translated as "cloud computing." To avoid confusion in the remainder of this description, the term "cloud operator" will be used to refer to the operator.

[0018] It should be noted that by "control" is meant control of at least some of the elements of the distributed computer system 8 (either on the terminal side or on the infrastructure side 9).

[0019] In the example described, control of the distributed computer system 8 corresponds to a maximum access right to the infrastructure 9, which is only assigned to the cloud operator.

[0020] The term "maximum" here refers to the extent of the assigned control.

[0021] Infrastructure control, for example, is achieved through a set of software called an orchestrator or VIM. The acronym VIM stands for "Virtual Infrastructure Manager," which literally means virtual infrastructure controller.

[0022] More specifically, the distributed computer system 8 includes, on the terminal side, computers 10 suitable for emulating a virtual machine MV and, on the infrastructure side 9, a set of network elements 11.

[0023] A computer 10 is illustrated more specifically on the figure 2 with a computer program product 12. The interaction of the computer program product 12 with the computer 10 allows the implementation of a virtual machine MV which is itself suitable for implementing the control of the distributed computer system 8. The control process is thus a process implemented by computer.

[0024] More generally, computer 10 is an electronic calculator designed to manipulate and / or transform data represented as electronic or physical quantities in registers of the calculator and / or memories into other similar data corresponding to physical data in memories, registers or other types of display, transmission or storage devices.

[0025] It should be noted that, in this description, the expression "specific to" means interchangeably "suited for", "adapted to" or "configured for".

[0026] The computer 10 includes a processor 14 comprising a data processing unit 16, memory 18, and a data storage drive 20. In the example shown, the computer 10 includes a keyboard 22 and a display unit 24.

[0027] The computer program product 12 includes a readable information medium.

[0028] A readable information medium is a medium that can be read by the computer 10, usually by the reader 20. The readable information medium is a medium suitable for storing electronic instructions and capable of being coupled to a bus of a computer system.

[0029] As an example, the readable information medium is a floppy disk, an optical disc, a CD-ROM, a magneto-optical disc, a ROM memory, a RAM memory, an EPROM memory, an EEPROM memory, a magnetic card or an optical card.

[0030] By extension to virtualized environments, any software that identically reproduces the behaviors of the previously listed readable information media is also a readable information medium.

[0031] On any of the aforementioned readable information media is stored a computer program comprising program instructions.

[0032] The computer program can be loaded onto the data processing unit 16 and is adapted to train the creation of the virtual machine MV.

[0033] The virtual machine (VM) is designed to provide a computer interface to a user. In the example provided, the user of the virtual machine is not the operator.

[0034] Thus, in a secure operation, the user does not have maximum access rights to the infrastructure (on the contrary, only assigned to the cloud operator) but has maximum access rights for the MV virtual machine (for which the cloud operator should not have maximum access rights).

[0035] In addition to the services provided to the user, the MV virtual machine is suitable for implementing a distributed computer system control process 8.

[0036] The network element set 11 groups together network elements.

[0037] By definition, a network element is a component that is part of a network.

[0038] According to the example shown, the network element set 11 includes a switch 26, a router 28, a firewall 30 and a network interface 32, for example a port.

[0039] In the general case, the distributed computer system 8 has more network elements, said network elements being an element chosen from the list consisting of a switch, a router or a firewall.

[0040] In addition, depending on the case, each of the aforementioned elements (switch 26, router 28, firewall 30 and network interface 32) is either physical or virtual in nature.

[0041] The set of network elements 11 forms a first environment E1 of the virtual machine MV.

[0042] Such a first E1 environment of the MV virtual machine can be seen as the MV virtual machine's boot network environment.

[0043] The operation of the MV virtual machine is now described with reference to an example of the implementation of a distributed computer system control method 8.

[0044] According to the example described, the control process is implemented during a startup of the virtual machine MV.

[0045] For example, the control process is implemented during the instantiation of the MV virtual machine.

[0046] As an illustration, the control process is implemented after the MV virtual machine boot process but before the MV virtual machine initialization.

[0047] Alternatively, the control process is implemented during the initialization of the MV virtual machine.

[0048] Furthermore, with respect to the environment elements, the control process is implemented after the start of the MV virtual machine's file management system but before the start process of the elements of the first E1 environment of the MV virtual machine.

[0049] Such a control method can therefore be seen as a computer process.

[0050] A process is a program being executed by a computer.

[0051] The control process includes a first instantiation step E50, a transfer step E52, an activation step E54, a second instantiation step E56 and a start-up step E58.

[0052] During the first instantiation step E50, a second environment E2 is instantiated.

[0053] The second environment E2 consists of a set of virtual network elements.

[0054] The first instantiation step E50 aims to obtain a second environment E2 isolated from the first environment E1.

[0055] The second environment E2 is therefore different from the first environment E1.

[0056] Virtual network elements are not visible from the first environment E1 and it is not possible to access these elements.

[0057] According to the illustrated example, the second environment E2 is controllable by an access right strictly lower than the maximum access right for the virtual machine MV.

[0058] The Cloud operator's access rights on this second E2 environment are the highest level rights on this environment and are necessary for instantiating the network elements of the E2 environment of the MV virtual machine.

[0059] The access right is then the access right that has been granted to the MV virtual machine by the cloud operator.

[0060] Such a second E2 environment is often instantiated in the form of a network namespace, which refers to the English term "net namespace". In computer science, the term namespace designates an abstract space designed to accommodate elements whose scope or accessibility is limited to a specific group of actors identified by the namespace.

[0061] According to the illustrated example, the first instantiation step E50 of the second environment E2 is implemented by using a container.

[0062] In computer science, a container is a data structure, class, or abstract data type whose instances represent collections of other objects. In other words, containers are used to store objects in an organized form that follows specific access rules.

[0063] When a container is run, a dedicated network environment is created for the container's execution space. By design, such a network environment is isolated from the primary environment E1. The container's network environment is, therefore, an example of a secondary environment E2.

[0064] It should be noted that any other technology allowing the isolation of network environments within the same virtual machine can be used during the first E50 instantiation step.

[0065] During the E52 transfer step, at least one network element from the first environment E1 is transferred to the second environment E2.

[0066] Preferably, as is the case in the present example, each network element from the first environment E1 is transferred to the second environment E2.

[0067] In one particular embodiment, all network elements provided by the Cloud operator are 32-bit network interfaces.

[0068] To ensure clarity, the following developments assume that the transfer takes place for all network elements, with the transposition to the case of transferring fewer network elements being immediate.

[0069] The network elements provided by the cloud operator therefore become invisible to the first E1 environment.

[0070] A practical example of implementing a transfer to a second E2 environment is now detailed.

[0071] For example, in the Linux environment, all network functionalities are implemented in environments called "net namespace", often abbreviated as "netns".

[0072] When a virtual machine is initialized, all of these network functionalities are implemented in the "netns" environment associated with the init process. By definition, the init process has the highest level of privileges and can perform all actions on the machine (including launching the initialization processes for network elements and the virtual machine). In the following, we will refer to the netns environment associated with the init process as "default".

[0073] In the case of a container, a netns environment is created to implement the network function(s) of this "netns" environment. This netns environment is associated with all the container's processes (actually with the container's init process).

[0074] For the rest of this document, the netns environment associated with the container is referred to as "container".

[0075] In the case of an eth0 network interface initially created in the "default" netns, the transfer step is implemented by logically transferring the interface to the "container" netns. The following command: `ip link set dev eth0 netns container` executed with the highest-level privileges in an environment with access rights to the default netns, will allow the interface transfer.

[0076] Once this command is executed, the eth0 interface is no longer visible in the "default" netns. The eth0 interface becomes visible and usable in the "container" netns to which it has been transferred.

[0077] The eth0 interface from the first environment has been successfully transferred to a second environment.

[0078] During the E54 activation step, at least one transferred network element is activated.

[0079] For example, during the E54 activation step, each network element transferred to the second environment E2 is started (or restarted). In other words, in the second environment E2, each network element transferred from the first environment E1 is started.

[0080] In the particular embodiment where all network elements are 32 network interfaces, the 32 network interfaces are enabled in the second environment E2.

[0081] Advantageously, such an E54 activation step is not implemented with higher level access rights on the MV virtual machine but with lower level access rights.

[0082] It is then possible to implement the cloud operator processes that would have taken place in the first E1 environment during a startup without the highest level access rights of the MV virtual machine by implementing this control process.

[0083] Self-configuration devices or specific executables are examples of such cloud operator processors.

[0084] These cloud operator processes can therefore only act on the second environment E2. The first environment E1 remains isolated from the potentially dangerous implementation of these processes.

[0085] Alternatively or in addition, information retrieval processes can be implemented to improve the implementation of subsequent steps in the control process.

[0086] Among the information retrieval processes, one can notably cite those for retrieving IP addresses and routing rules exchanged by processes using the DHCP protocol. Automatic configuration tools such as "cloud-init" allow for the configuration of virtual machines (VMs) at startup, while mass configuration tools, such as those based on network execution, facilitate data exchange or configuration software. Examples of such software include Ansible®, Puppet®, and SaltStack®.

[0087] According to another example, key exchange processes are used to instantiate an encrypted tunnel, as well as processes to instantiate this tunnel, enabling the encryption of all flows visible to the Cloud operator.

[0088] Each of the aforementioned processes is, according to another embodiment, implemented by a container that does not have higher-level access rights on the MV virtual machine.

[0089] During the second instantiation step E56, at least one link between the first environment E1 and at least one network element of the second environment E2 is instantiated.

[0090] Such a second E56 instantiation step can therefore be considered as a connection step.

[0091] Such a connection allows the MV virtual machine to be linked to a part of the distributed computing system 8 via processes controllable only by an entity with access rights strictly lower than the highest level of access rights on the MV virtual machine. Thus, in the example described, the connection is not controlled by the cloud operator.

[0092] For example, the MV virtual machine generates a virtual link in the first environment E1, a link which is intended to be connected to the network elements of the second environment E2.

[0093] The generated link has two ends, one of which is then transferred to the second environment E2 to be connected to the network elements of the second environment E2, and the other to an interface instantiated by the virtual machine MV with the highest privileges and belonging to the first environment E1. All network equipment in the E1 environment is then accessible only with the highest-level privileges of the virtual machine MV. This means that all network equipment in the E1 environment is inaccessible to the software implemented by the distributed system 8 running in the second environment E2.

[0094] Such a link thus plays the role of an interface between the distributed computer system 8 and the virtual machine MV.

[0095] During the E58 startup step, at least the instantiated link is started.

[0096] In addition, all network elements of the first E1 environment are started by the MV virtual machine with the highest level access rights on the MV virtual machine.

[0097] As an example, the E58 startup step includes the configuration of network functions implemented in the second environment E2 and then the startup of the software enabling the implementation of the network functions necessary for the operation of the real or virtual network equipment of the second environment E2.

[0098] The E58 startup step also includes the activation of both ends of at least one link connecting the first environment E1 to the second environment E2, the configuration of the network functions implemented in the first environment E1, and the starting of the software enabling the implementation of the network functions necessary for the operation of the network functions of the virtual machine MV.

[0099] The control process thus ensures that, regardless of the information transmitted during the start-up of the MV virtual machine, and in particular during the initialization of the network elements provided by the cloud operator, the user who has the highest level access rights on the MV virtual machine retains control of the rights and data without ever providing the highest level right access to the cloud operator.

[0100] The control process thus makes it possible to overcome constraints related to the cloud operator, guaranteeing a certain independence to the user of the virtual machine VM from the infrastructure 9.

[0101] Thus, the control process allows for better portability of a virtual machine (VM) while maintaining a good level of security for all elements that are part of the distributed computer system 8.

[0102] Other embodiments are conceivable for the control process just described, these embodiments being able to be combined with the control process when these embodiments are technically compatible with such a process.

[0103] Thus, during the E58 startup step, network elements other than the transferred network elements can also be instantiated. The software required to instantiate these network elements is executed with privileges lower than the maximum access rights to the virtual machine VM.

[0104] Such network elements are often suited to implement more complex network functions. These more complex network functions can include, among other things, the implementation of encrypted tunnels providing services identical to a network interface.32

[0105] In a particular embodiment, the implementation of one or more virtual switches in the second environment E2, the implementation of one or more virtual routers, and the implementation of routing table generation software, particularly those based on automatic routing protocols such as BGP or OSPF. BGP stands for Border Gateway Protocol, and OSPF stands for Open Shortest Path First.

[0106] According to another embodiment or in addition, the E58 start-up step includes the instantiation of network elements enabling the realization of these complex functions and in particular the instantiation of all network equipment, tunnels, interfaces enabling the realization of the complex functions requested in the second environment E2, as well as the instantiation of the links between all this network equipment in the second environment E2.

[0107] According to one embodiment for startup step E58, at least one network bridge is used. A network bridge performs a Layer 2 switching function according to the OSI model. The OSI model (an acronym referring to the English name "Open Systems Interconnection") is a network communication standard for all computer systems.

[0108] In each of the proposed cases, the instantiation of the network equipment necessary to perform these complex functions is not implemented with higher level access rights on the MV virtual machine but with lower level access rights.

[0109] In one particular embodiment, a container with lower-level access rights is used.

[0110] According to another embodiment of the E58 startup step, at least one router is used. A router performs a Layer 3 switching function according to the OSI model.

[0111] According to yet another embodiment, when additional information has been obtained during the E54 activation step, the connection is preferably made using the router and software providing dedicated functions.

[0112] A dedicated function is, for example, an IP address configuration service using DHCP. The acronym DHCP refers to the English name "Dynamic Host Configuration Protocol," which literally means dynamic host configuration protocol and designates a network protocol whose role is to ensure the automatic configuration of the IP parameters of a station or machine, in particular by automatically assigning it an IP address and a subnet mask.

[0113] Alternatively, a dedicated function is a name resolution service or a virtual machine (VM) configuration server.

[0114] Preferably, software providing dedicated functions is not implemented with higher-level access rights on the MV virtual machine, but with lower-level access rights.

[0115] Furthermore, it should be noted that other embodiments are obtained by implementing the aforementioned steps in a different way from the control process that has been described as an example.

[0116] Thus, the E54 activation step is by nature independent of the previous steps and is therefore not in a constrained sequence with regard to the other steps of the process.

[0117] The E54 activation step finds a particular advantage in being implemented after the E52 transfer step insofar as this ensures that the software required to implement the link with the distributed system is all executed with rights strictly lower than the maximum right of the MV.

[0118] The E54 activation step also finds a particular advantage in being implemented before the E58 startup step because the E54 activation step can produce the information needed for the E58 startup step.

[0119] The activation step E54 is not dependent on the implementation of the second instantiation step E56, which can occur before or after the implementation of the activation step E54.

[0120] According to another example, the second instantiation step E56 can be implemented at any time after the creation of the second environment E2 of the first instantiation step E50 and only allows the expected functions to be performed once the startup step E58 is completed.

Claims

1. A method of controlling a distributed computer system (8), the distributed computer system (8) comprising at least one virtual machine (VM) and a set of network elements (11), the set of network elements (11) forming a first environment (E1) of the virtual machine (VM), the control method being implemented by the virtual machine (VM) and comprising, during an initiation of the virtual machine (VM), the steps of: - instantiating a second environment (E2) formed by a set of virtual network elements, the second environment (E2) being different from the first environment (E1), - transferring at least one network element from the first environment (E1) to the second environment (E2), - activating the at least one transferred network element, - instantiating at least one link between the first environment (E1) and each network element of the second environment (E2), the step of instantiating being carried out by: - generating a link intended for being connected to the network elements of the second environment (E2), the link comprising two ends, - transferring one end of the link to the second environment (E2) in order to be connected to the network elements of the second environment (E2), - transferring the other end of the link to an interface belonging to the first environment (E1), the interface being instantiated by the virtual machine (VM) with the highest-level of right of access to the virtual machine (VM), the steps of activating and of instantiating of the at least one link being carried out with a level of right of access strictly inferior to the highest-level of right of access to the virtual machine (VM), and - initiating the at least one instantiated link.

2. The control method according to claim 1, wherein each network element is selected from the list consisting of a switch, a router and a firewall.

3. The control method according to claim 1 or 2, wherein the step of instantiating at least one link comprises using a network bridge or router.

4. The control method according to any one of claims 1 to 3, wherein the step of instantiating a second environment (E2) is performed using a container.

5. The control method according to any one of claims 1 to 4, wherein the control of the distributed computer system (8) corresponds to a maximum right of access, the second environment (E2) being controllable by a right of access strictly lower than the maximum right of access.

6. A virtual machine (VM) suitable for implementing a method of controlling a distributed computer system (8), the distributed computer system (8) comprising at least the virtual machine (VM) and a set of network elements, the set of network elements forming a first environment (E1) of the virtual machine (VM), the virtual machine (VM) being suitable for, during an initiation of the virtual machine (VM): - instantiating a second environment (E2) formed by a set of virtual network elements, the second environment being different from the first environment (E1), - transferring at least one network element from the first environment (E1) to the second environment (E2), - activating the at least one transferred network element, - instantiating the at least one link between the first environment (E1) and each network element of the second environment (E2), the virtual machine (VM) being adapted to instantiate the at least one link by: - generating a link intended for being connected to the network elements of the second environment (E2), the link comprising two ends, - transferring one end of the link to the second environment (E2) in order to be connected to the network elements of the second environment (E2), - transferring the other end of the link to an interface belonging to the first environment (E1), the interface being instantiated by the virtual machine (VM) with the highest-level of right of access to the virtual machine (VM), the activating and the instantiating of the at least one link being carried out with a level of right of access strictly inferior to the highest-level of right of access to the virtual machine (VM), and - initiating the at least one instantiated link.

7. A distributed computer system (8) comprising at least one virtual machine (VM) according to claim 6.