Virtual machine system

A virtual machine system with dual-redundant pairs on multiple servers ensures redundancy and simplifies management by migrating and rebuilding virtual machines across servers, addressing the challenge of maintaining dual redundancy in virtualized systems.

JP2026055615APending Publication Date: 2026-03-31EAST JAPAN RAILWAY COMPANY +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In fields like railways, ensuring a dual redundant configuration is necessary for safety, but integrating multiple systems using server virtualization requires maintaining redundancy even when any server fails, which is challenging.

Method used

A virtual machine system using three or more servers, where virtual machines are configured in dual-redundant pairs, allowing migration and rebuilding on different servers in case of failure, ensuring redundancy and independent OS compatibility.

Benefits of technology

Maintains dual-redundant configuration while achieving server virtualization, reducing hardware lifecycle costs, and simplifying virtual machine management and setup.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026055615000001_ABST
    Figure 2026055615000001_ABST
Patent Text Reader

Abstract

Maintain a dual-redundancy configuration while implementing server virtualization across three or more servers. [Solution] The virtual machine system 10 uses three or more servers 12 and includes multiple virtual machines VMs built on the three or more servers 12. The multiple virtual machines VMs include a first virtual machine and a second virtual machine as a dual-redundant virtual machine pair. When one of the servers 12 on which the first virtual machine is built fails, the first virtual machine is migrated to a server 12 on which the other virtual machine is not built and rebuilt. This ensures dual-redundancy of the virtual machine pair, making it possible to maintain a dual-redundant configuration while realizing server 12 virtualization with three or more servers 12.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a virtual machine system for constructing a plurality of virtual machines on three or more servers.

Background Art

[0002] In recent years, server virtualization has been used for effective utilization of limited resources and downsizing of devices. By virtualizing a server, a plurality of virtual machines can be constructed on one server, and hardware resources such as a CPU and memory installed in the server are virtually divided and allocated to each virtual machine. Regarding such virtualization, for example, in the field of railways, there is a case where a virtualization infrastructure is adopted in an operation management system (see Non-Patent Document 1).

Prior Art Documents

Non-Patent Documents

[0003]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Here, in fields such as railways, in order to ensure safety, etc., it is necessary to configure some of the devices constituting the system in a dual redundant configuration. When considering integrating such multiple systems while using server virtualization, for example, due to system feasibility and hardware redundant configuration, etc., it is conceivable to construct the system with three or more servers. In this case, since it is necessary to maintain a dual redundant configuration even when any server fails, it was necessary to devise the arrangement of virtual machines. The present invention has been made in view of the above problems, and an object thereof is to maintain a dual redundant configuration while realizing server virtualization in three or more servers. [Means for solving the problem]

[0005] (Modes of the invention) The following embodiments of the invention are illustrative of the configuration of the present invention and are described in separate sections to facilitate understanding of the diverse configurations of the present invention. Each section does not limit the technical scope of the present invention. Therefore, while taking into consideration the best mode for carrying out the invention, the technical scope of the present invention may also include modifications, deletions, or additions of other components of each section.

[0006] (1) A virtual machine system using three or more servers, which includes a plurality of virtual machines built on the three or more servers, wherein the plurality of virtual machines include a first virtual machine and a second virtual machine as a dual-redundant virtual machine pair, and the first virtual machine and the second virtual machine are a virtual machine system in which, when the server on which one virtual machine is built fails, the first virtual machine is migrated to a server on which the other virtual machine is not built and rebuilt.

[0007] The virtual machine system described in this section uses three or more servers, and these servers are used in a virtualized manner. Therefore, multiple virtual machines are built on these three or more servers. The multiple virtual machines include a first virtual machine and a second virtual machine as a dual-redundant virtual machine pair, and there may be multiple such virtual machine pairs. In each virtual machine pair, if the server on which one virtual machine is built fails, the first virtual machine and the second virtual machine are reconfigured by migrating to a server on which the other virtual machine is not built.

[0008] In other words, if one of the three or more servers where the first virtual machine is built fails, the first virtual machine is migrated to and rebuilt on a server among the remaining servers where the second virtual machine is not built. Similarly, if one of the three or more servers where the second virtual machine is built fails, the second virtual machine is migrated to and rebuilt on a server among the remaining servers where the first virtual machine is not built. As a result, even if one of the three or more servers fails, either the first or second virtual machine built on the failed server will be migrated to a server where the other virtual machine is not built, thus ensuring dual-system redundancy for the virtual machine pair. Therefore, a dual-system redundant configuration is maintained while server virtualization is achieved across three or more servers.

[0009] Furthermore, in a virtualized server, the virtual machine's OS is independent of the physical hardware. Therefore, even if the hardware (server) is updated, the virtualization infrastructure software ensures compatibility of the existing OS with the new hardware. This eliminates the need for OS updates or software recreation associated with hardware updates, freeing the user from the hardware lifecycle. In addition, since each virtual machine is treated as a file, adding or moving virtual machines becomes easy through methods such as copying virtual machines or configuring virtual machines from templates, reducing the effort required during setup.

[0010] (2) In item (1) above, the first virtual machine and the second virtual machine are virtual machine systems in which the initial target server is set to a different server from the other. The virtual machine system described in this section is one in which the first and second virtual machines constituting a pair of virtual machines are initially configured on different servers among three or more servers, such as during system startup. This ensures redundancy of the virtual machine pair not only in the event of server failure but also during system startup.

[0011] (3) In the above paragraph (1), the plurality of virtual machines is a virtual machine system that is distributed and built on the three or more servers based on the use, purpose, or load of the three or more servers. The virtual machine system described in this section is one in which multiple virtual machines, including virtual machine pairs, are distributed across three or more servers based on their intended use, purpose, or load. Specifically, for example, multiple virtual machines are distributed across three or more servers during system startup to ensure an even load on each server, or in the event of a server failure or maintenance, the reconstruction destinations for multiple virtual machines on that server are distributed to the remaining servers. This equalizes the server load and maintains system availability and scalability.

[0012] (4) In item (1) above, the first virtual machine and the second virtual machine are virtual machine systems in which the server to be rebuilt is pre-configured. The virtual machine system described in this section has pre-configured servers for the reconstruction of the first and second virtual machines in a virtual machine pair in the event of a server failure. In other words, the reconstruction destination for the first and second virtual machines is pre-configured to be another server where the other virtual machine is not hosted, in the event of a server failure on the server where one virtual machine is hosted. This ensures more reliable redundancy of the virtual machine pair in the event of a server failure. Furthermore, if there are multiple such virtual machine pairs, the reconstruction destinations for the first and second virtual machines of each virtual machine pair are configured considering their use, purpose, or load, thereby ensuring equal server load distribution.

[0013] (5) A virtual machine system applicable to the railway operation management system described in items (1) to (4) above. The virtual machine system described in this section is applied to railway operation management systems, where each component of the operation management system is constructed using virtual machines. This allows for the smooth implementation of an operation management system, even one handling multiple railway lines, by dividing hardware resources such as CPUs and memory across three or more servers and distributing them to each virtual machine.

[0014] Conventional train operation management systems require multiple chassis, and the number of chassis increases proportionally when dealing with multiple railway lines. Furthermore, conventional train operation management systems require software updates every time the related hardware is updated, resulting in high costs associated with implementation and updates. For this reason, considering factors such as population decline and changes in transportation modes in local railway lines, streamlining equipment and reducing lifecycle costs have become urgent issues. Therefore, the virtual machine system described in this section, when applied to railway operation management systems as described above, can handle operations management systems that deal with multiple railway lines without problems, thereby achieving streamlining of equipment and reduction of lifecycle costs.

[0015] (6) In item (5) above, the operation management system includes a dual redundant PRC device that controls the route of trains based on the timetable of each station, and a dual redundant I / F device for data communication with operation management systems of different lines, wherein each of the PRC device and the I / F device is a virtual machine system implemented in the virtual machine pair. The virtual machine system described in this section applies to train operation management systems that include a PRC (Automatic Route Control) device and an I / F (Interface) device. The PRC device controls the route of trains based on the timetable of each station, and the I / F device is for data communication with train operation management systems of different railway lines.

[0016] Furthermore, both the PRC device and the I / F device are configured in a dual-redundancy system, and are implemented in the first and second virtual machines of a virtual machine pair accordingly. That is, in a virtual machine pair constituting the PRC device, PRC device system 1 is configured by the first virtual machine, and PRC device system 2 is configured by the second virtual machine. Similarly, in a virtual machine pair constituting the I / F device, I / F device system 1 is configured by the first virtual machine, and I / F device system 2 is configured by the second virtual machine. This ensures dual-redundancy for the PRC device and I / F device in a virtual machine environment using three or more servers. [Effects of the Invention]

[0017] With this configuration, the present invention makes it possible to maintain a dual-redundant configuration while implementing server virtualization on three or more servers. [Brief explanation of the drawing]

[0018] [Figure 1] This block diagram shows an example of a hardware configuration and a virtualized server configuration used in a virtual machine system according to an embodiment of the present invention. [Figure 2]This is a configuration image diagram showing an example of the configuration of a virtual machine when the virtual machine system according to an embodiment of the present invention is applied to a railway operation management system. [Figure 3] This is a table showing the initial construction destination and reconstruction destination servers of each virtual machine in the configuration of FIG. 2. [Figure 4] This is a table showing setting examples of the initial construction destination and reconstruction destination servers of virtual machine pairs when the number of servers is 4 and 5.

Mode for Carrying Out the Invention

[0019] Hereinafter, embodiments of the present invention will be described based on the drawings. Here, throughout the drawings, the same parts or corresponding parts are denoted by the same reference numerals. Also, detailed descriptions of the same parts or corresponding parts as in the prior art will be omitted. FIG. 1 shows an example of the configuration of a virtual machine system 10 according to an embodiment of the present invention. The configuration of the virtual machine system 10 is not limited to the block diagram of FIG. 1. For example, depending on the system to be applied and the number of servers, some of the components shown in FIG. 1 may be deleted, changed, or appropriately added.

[0020] As shown in FIG. 1, the virtual machine system 10 according to an embodiment of the present invention includes three servers 12A, 12B, and 12C as three or more servers 12, namely, a first server 12A, a second server 12B, and a third server 12C. These three servers 12A, 12B, and 12C may be for ensuring triple redundancy as a system. Also, the three servers 12A, 12B, and 12C are connected to a storage server 30 by optical fibers, LAN, etc., and each server 12 serves as a node to form a cluster system. Each of the servers 12 includes a CPU 20, a memory 22, a ROM 24, and an input / output port 26 as hardware resources. Any server device having the above-described hardware resources and the like is used for the server 12.

[0021] The three servers 12A, 12B, and 12C described above are virtualized by the virtualization infrastructure software 34 installed on the storage server 30. That is, multiple virtual machines (VMs) are built on each of the three servers 12A, 12B, and 12C, as shown at the top of Figure 1. Each virtual machine (VM) is virtually divided and allocated the hardware resources of the server 12 on which it is built, such as the CPU 20, memory 22, ROM 24, and I / O ports 26. As a result, each of the multiple virtual machines (VMs) is individually equipped with an application 40 and an OS 42, and operates like an independent server. As will be described in more detail later, the virtual machine system 10 according to the embodiment of the present invention includes a first virtual machine 46 and a second virtual machine 48 (see Figures 2 to 4) as a dual-redundant virtual machine pair, among the multiple virtual machine VMs built on the three servers 12. The dashed arrows in Figure 1 illustrate the virtualization of each server 12.

[0022] The storage server 30, for example, is equipped with multiple HDDs (hard disk drives) and bundles them together to provide large-capacity storage, reading and writing data to the HDDs as needed. The storage server 30 stores the virtualization infrastructure software 34 mentioned above, including a hypervisor responsible for creating and running virtual machines (VMs), and cluster management software responsible for managing virtual machines (VMs) and clusters, as well as configuration data for each virtual machine (VM). As mentioned above, the storage server 30 is connected to the three servers 12A, 12B, and 12C to form a storage area network (SAN), and its isolation from server 12 enables large capacity and high availability. The data stored in the storage server 30 is shared by the three servers 12A, 12B, and 12C. Note that the storage server 30 may be composed of storage other than HDDs.

[0023] A virtual machine system 10 with the configuration described above will operate, for example, as follows (details omitted): First, when power is turned on, each of the three servers 12A, 12B, and 12C reads and runs the hypervisor stored in the storage server 30, and then runs the cluster management software. Next, the cluster management software reads the virtual machine VM information from the storage server 30 to each of the three servers 12A, 12B, and 12C according to the settings, and starts running each virtual machine VM. If any of the servers 12 become inoperable or unable to communicate due to a failure during operation, the hypervisor will, for example, use the HA (High Availability) function to rebuild the virtual machine VM according to the settings.

[0024] Here, we will explain the reconstruction of the virtual machine VM when server 12 fails. In the virtual machine system 10 according to an embodiment of the present invention, if any of the three servers 12A, 12B, and 12C fail, the virtualization infrastructure software 34 (hypervisor) reconstructs the virtual machine VM that was running on the failed server 12 and runs it on another server 12 that is not experiencing a failure (failover). At this time, if the failed server 12 contains one of the virtual machines in a redundant dual-system configuration, namely the first virtual machine 46 and the second virtual machine 48, the virtualization infrastructure software 34 reconstructs one of the first virtual machine 46 and the second virtual machine 48 on a server 12 that is not experiencing a failure, where the other virtual machine is not configured. This reconstruction of the virtual machine VM will be explained in more detail using Figure 2, which will be referenced next.

[0025] Figure 2 illustrates a configuration in which the virtual machine system 10 according to an embodiment of the present invention is applied to a railway operation management system 60. Here, the operation management system 60 will be briefly described. The operation management system 60 integrates operation management systems that handle three railway lines, Line A, Line B, and Line C, and the operation management system for each railway line includes, for example, the following components. • Timetable management system: A device for creating a database of timetables. • Driver's Control Desk: A device that changes the timetable data in the event of an accident or other incident. • Control console: A device used to switch train station signals, etc., from "green" to "red". • Display console: A device that displays the location of trains on the entire railway line. • PRC device (62): A device that automatically sets the route based on the timetable of each station. • System monitoring console: A device that monitors system failures and displays their details. • I / F device (64): A device that exchanges necessary information between different train operation management systems on different railway lines. • Data storage device: A device for storing data. Of these components, at least the PRC device 62 and the I / F device 64 are configured in a redundant, dual-system configuration.

[0026] In the configuration shown in Figure 2, 26 virtual machines (VMs) VM1 to VM26 are distributed across three servers 12A, 12B, and 12C, and each virtual machine (VM) is assigned a component of the operation management system for each line section as described above. The "Virtual Machine" column in the table in Figure 3 shows the correspondence between virtual machines VM1 to VM26 and the components of the operation management system. Specifically, virtual machines VM1 and VM2 are assigned "Line A_I / F Device_1 System" and "Line A_I / F Device_2 System," which represent the redundant I / F device 64 for Line A. Similarly, virtual machines VM3 and VM4 are assigned "Line B_I / F Device_1 System" and "Line B_I / F Device_2 System," which represent the redundant I / F device 64 for Line B. Virtual machines VM5 and VM6 are assigned "Line C_I / F Device_1 System" and "Line C_I / F Device_2 System," which represent the redundant I / F device 64 for Line C.

[0027] Furthermore, virtual machines VM7 and VM8 are assigned "Line A_PRC_Device_1 System" and "Line A_PRC_Device_2 System," which represent the redundant Line A PRC device 62. Similarly, virtual machines VM11 and VM12 are assigned "Line B_PRC_Device_1 System" and "Line B_PRC_Device_2 System," which represent the redundant Line B PRC device 62, and virtual machines VM16 and VM17 are assigned "Line C_PRC_Device_1 System" and "Line C_PRC_Device_2 System," which represent the redundant Line C PRC device 62. In this case, each pair of virtual machines VM1 and VM2, VM3 and VM4, VM5 and VM6, VM7 and VM8, VM11 and VM12, and VM16 and VM17, to which the redundant Line A devices are assigned, corresponds to the first virtual machine 46 and the second virtual machine 48, which are a redundant Virtual Machine pair.

[0028] Furthermore, virtual machines VM9, VM10, and VM26 are assigned "Line A Command_1," "Line A Command_2," and "Line A Command_3," respectively, which represent the equipment of the Line A command system. These command system devices include timetable management devices, operation control consoles, control consoles, and display consoles, and are allocated to one of "Line A Command_1," "Line A Command_2," or "Line A Command_3" depending on their quantity and load. The virtual machines VM corresponding to the timetable management devices, operation control consoles, control consoles, and display consoles correspond to their thin client terminals. Similarly, virtual machines VM13, VM14, and VM15 are assigned "Line B Command_1," "Line B Command_2," and "Line B Command_3," respectively, which represent the equipment of the Line B command system, and virtual machines VM18, VM19, and VM20 are assigned "Line C Command_1," "Line C Command_2," and "Line C Command_3," respectively, which represent the equipment of the Line C command system. The command system equipment for lines B and C is allocated in the same way as for line A.

[0029] Furthermore, virtual machine VM22 is assigned "Line A_DataStorage Device," which indicates the data storage device for Line A. Similarly, virtual machine VM23 is assigned "Line B_DataStorage Device," which indicates the data storage device for Line B, and virtual machine VM24 is assigned "Line C_DataStorage Device," which indicates the data storage device for Line C. In addition, virtual machine VM21 is assigned "SQL Server" as the common database for Lines A, B, and C. Also, virtual machine VM25 is assigned "Virtualization Infrastructure Management" for managing the virtualization infrastructure software 34. Note that the system monitoring consoles for each line section are implemented on separate, independent devices, not on the virtual machine system 10.

[0030] In Figures 2 and 3, among the virtual machines VM1 to VM26, the first virtual machine 46 and the second virtual machine 48, which are a redundant virtual machine pair in a dual-system configuration, have their initial host server 12 (such as when the system is powered on) and their reconstruction host server 12 (such as when the host server 12 fails) pre-configured. This configuration is achieved, for example, by applying affinity rules of the DRS (Distributed Resource Scheduler) function to server 12. In Figure 3, the initial host server 12 for each virtual machine VM corresponding to the first virtual machine 46 and the second virtual machine 48 is indicated by "●", and the reconstruction host server 12 is indicated by "▲".

[0031] For example, virtual machine VM1 is initially built on the third server 12C and rebuilt on the second server 12B. In contrast, virtual machine VM2, which forms a dual-redundant configuration with virtual machine VM1, is initially built on the first server 12A and rebuilt on the second server 12B. Similarly, virtual machine VM11 is initially built on the first server 12A and rebuilt on the third server 12C, and virtual machine VM12, which forms a dual-redundant configuration with virtual machine VM11, is initially built on the second server 12B and rebuilt on the third server 12C. In other words, the two virtual machines VMs corresponding to the first virtual machine 46 and the second virtual machine 48 in the dual-redundant configuration have their initial build destinations set to different servers 12. Furthermore, as described above, the two virtual machines VMs corresponding to the first virtual machine 46 and the second virtual machine 48 are configured such that if the server 12 on which one virtual machine VM is built fails, the other virtual machine VM will be rebuilt on one of the remaining servers 12 that are not faulty, but on which the other virtual machine VM is not built.

[0032] Furthermore, among the virtual machines VM1 to VM26 shown in Figures 2 and 3, the virtual machines VMs other than the redundant virtual machine pairs in the dual-system configuration have a pre-configured initial server 12 for when the system is powered on, and the initial server 12 for which the virtual machines are configured is indicated by "●" in Figure 3. This configuration is also achieved, for example, by applying affinity rules of the DRS function. For example, the initial configuration destination for virtual machine VM9 is the third server 12C, and the initial configuration destination for virtual machine VM20 is the first server 12A. When the server 12 that these virtual machines were operating on fails, they are rebuilt on one of the remaining non-failed servers 12, for example, by the HA function. At this time, the server 12 to which the virtual machines are rebuilt is determined, for example, by the DRS function, so that the load on each server 12 is distributed.

[0033] Figure 2 shows the initial state in which virtual machines VM1 to VM26 are built on server 12, the initial build location, such as when the system is powered on. As shown in Figure 2, virtual machines VM1 to VM26 are built distributed across three servers 12A, 12B, and 12C based on, for example, the load of the components of the assigned operation management system 60, or in other words, based on the use, purpose, or load of the three servers 12A, 12B, and 12C. Figure 2 also illustrates a virtual switch 52 built through the virtualization of server 12, which plays the role of a network between the virtual machines VM within each server 12 and external devices. Each server 12 is equipped with multiple NICs (Network Interface Cards), and although a detailed explanation is omitted, the allocation of NICs for each communication and teaming of multiple NICs are performed via the virtual switch 52.

[0034] Herein, the virtual machine system 10 according to the embodiment of the present invention is not limited to the embodiment described above, and various modifications can be made by those skilled in the art within the technical concept of the present invention. For example, the virtual machine system 10 is not limited to application to the railway operation management system 60, but can be applied to any system in various fields, including redundant dual-system configurations. Also, the number of servers 12 is not limited to three, but can be any number of three or more, such as four or five. Figure 4 shows examples of the initial and reconstruction server 12 settings for four pairs of virtual machines in the cases of four and five servers 12. Similar to Figure 3, the initial server 12 is indicated by "●" and the reconstruction server 12 is indicated by "▲".

[0035] Looking at Figure 4(a), which corresponds to the first to fourth servers 12, we see that, similar to the case with three servers 12, the first virtual machine 46 and the second virtual machine 48, which form a pair, are configured to have different initial host servers 12. Furthermore, if the server 12 on which one of the paired first virtual machine 46 and second virtual machine 48 was running fails, the reconstruction destination is set to another server 12 on which the other virtual machine VM is not running. This configuration is the same for Figure 4(b), which corresponds to the first to fifth servers 12. In addition, three or more servers 12 may be configured in a triple-redundancy or higher-redundancy configuration; for example, four servers 12 may be configured in a quadruple-redundancy configuration, and five servers 12 may be configured in a quintuple-redundancy configuration.

[0036] Now, according to the embodiment of the present invention having the above configuration, the following effects can be obtained. That is, the virtual machine system 10 according to the embodiment of the present invention uses three or more servers 12, as shown in Figure 1, and these servers 12 are used in a virtualized manner. For this reason, multiple virtual machines VMs are built on these three or more servers 12. The multiple virtual machine VMs include a first virtual machine 46 and a second virtual machine 48 (see Figures 2 to 4) as a dual-redundant virtual machine pair, and multiple such virtual machine pairs are included. Furthermore, in each virtual machine pair, if the server 12 on which one virtual machine VM is built fails, one virtual machine VM is transferred to the other server 12 on which the other virtual machine VM is not built and rebuilt (see Figures 3 and 4).

[0037] In other words, if one of the three or more servers 12 where the first virtual machine 46 is built fails, the first virtual machine 46 is migrated to and rebuilt on one of the remaining servers 12 where the second virtual machine 48 is not built. Similarly, if one of the three or more servers 12 where the second virtual machine 48 is built fails, the second virtual machine 48 is migrated to and rebuilt on one of the remaining servers 12 where the first virtual machine 46 is not built. As a result, even if one of the three or more servers 12 fails, either the first virtual machine 46 or the second virtual machine 48 built on the failed server 12 can be migrated to a server 12 where the other virtual machine 46 or the second virtual machine 48 is not built, thus ensuring dual-system redundancy of the virtual machine pair. Therefore, it is possible to maintain a dual-system redundant configuration while implementing server 12 virtualization with three or more servers 12.

[0038] Furthermore, in a virtualized server 12, the OS 42 of the virtual machine VM is independent of the physical hardware. Therefore, even if the hardware (server 12) is updated, the virtualization infrastructure software 34 can ensure compatibility of the existing OS with the new hardware. This eliminates the need to update the OS 42 or recreate the software when hardware is updated, freeing the system from the hardware lifecycle. In addition, since each virtual machine VM is treated as a file, it is easy to add or move virtual machine VMs by copying them or configuring them from templates, reducing the effort required during setup.

[0039] Furthermore, in the virtual machine system 10 according to the embodiment of the present invention, as can be seen in Figures 3 and 4, the first server 12 to which the first virtual machine 46 and the second virtual machine 48 constituting the virtual machine pair are initially built when the system starts up is set to different servers 12 from among three or more servers 12. This ensures redundancy of the virtual machine pair not only in the event of a server 12 failure, but also when the system starts up.

[0040] Furthermore, in the embodiment of the present invention, the virtual machine system 10 is configured such that multiple virtual machine VMs, including virtual machine pairs, are distributed and built across three or more servers 12 based on their intended use, purpose, or load. That is, for example, multiple virtual machine VMs are distributed and built across three or more servers 12 at system startup, etc., so that the load on each server 12 is evenly distributed (see Figures 2 to 4), or in the event of a server 12 failure or maintenance, the reconstruction destinations of multiple virtual machine VMs built on that server 12 are distributed across the remaining servers 12 (see Figures 3 and 4). This makes it possible to equalize the load on the servers 12 and maintain the availability and scalability of the system.

[0041] Furthermore, in the virtual machine system 10 according to the embodiment of the present invention, as shown in Figures 3 and 4, the server 12 to which the first virtual machine 46 and the second virtual machine 48 constituting a virtual machine pair will be rebuilt in the event of a server 12 failure is pre-configured. That is, the first virtual machine 46 and the second virtual machine 48 will be rebuilt in the event of a failure of the server 12 on which one virtual machine VM is built, by pre-configuring the rebuilding destination to another server 12 on which the other virtual machine VM is not built. This ensures more reliable redundancy of the dual virtual machine pair in the event of a server 12 failure. In addition, if there are multiple such virtual machine pairs, the rebuilding destination for the first virtual machine 46 and the second virtual machine 48 of each virtual machine pair can be configured considering the application, purpose, or load, thereby ensuring equal load distribution on the server 12.

[0042] In addition, as shown in Figure 2, the virtual machine system 10 according to an embodiment of the present invention can be applied to a railway operation management system 60, allowing each device constituting the operation management system 60 to be constructed using virtual machines (VMs). This enables the operation management system 60, for example, which handles multiple railway lines, to be implemented on three or more servers 12 without problems by dividing hardware resources such as CPUs 20 and memory 22 installed on three or more servers 12 and distributing them to each virtual machine (VM). Therefore, it is possible to handle operation management systems 60 that handle multiple railway lines without problems, enabling equipment streamlining and reduction of lifecycle costs.

[0043] Furthermore, as shown in Figures 2 and 3, the virtual machine system 10 according to the embodiment of the present invention includes a PRC (Automatic Route Control) device 62 and an I / F (Interface) device 64 in the target operation management system 60. The PRC device 62 controls the route of trains based on the timetable of each station, and the I / F device 64 is for data communication with operation management systems of different railway lines. Each of the PRC device 62 and the I / F device 64 is configured as a dual-system redundant configuration and is implemented in the first virtual machine 46 and the second virtual machine 48 of the virtual machine pair accordingly. That is, in the virtual machine pair constituting the PRC device 62, one system of the PRC device 62 is configured by the first virtual machine 46, and the second system of the PRC device 62 is configured by the second virtual machine 48. Similarly, in the virtual machine pair constituting the I / F device 64, one system of the I / F device 64 is configured by the first virtual machine 46, and the second system of the I / F device 64 is configured by the second virtual machine 48. This makes it possible to ensure dual redundancy of the PRC device 62 and I / F device 64 in a virtual machine environment using three or more servers 12. [Explanation of Symbols]

[0044] 10: Virtual machine system, 12 (12A~12C): Server, VM (VM1~VM26): Virtual machine, 46: First virtual machine, 48: Second virtual machine, 60: Operation management system, 62: PRC device, 64: I / F device

Claims

1. A virtual machine system using three or more servers, This includes multiple virtual machines built on the three or more servers mentioned above, The plurality of virtual machines include a first virtual machine and a second virtual machine as a dual-redundant virtual machine pair. A virtual machine system characterized in that, when the server on which one virtual machine is built fails, the first virtual machine is transferred to a server on which the other virtual machine is not built and rebuilt.

2. The virtual machine system according to claim 1, characterized in that the first virtual machine and the second virtual machine are initially configured on different servers.

3. The virtual machine system according to claim 1, characterized in that the plurality of virtual machines are constructed distributed across the three or more servers based on the use, purpose, or load of the three or more servers.

4. The virtual machine system according to claim 1, characterized in that the first virtual machine and the second virtual machine have a pre-configured server for reconstruction.

5. A virtual machine system according to any one of claims 1 to 4, characterized in that it is applied to a railway operation management system.

6. The aforementioned train operation management system includes a dual-redundant PRC device that controls the train route based on the timetable of each station, and a dual-redundant I / F device for data communication with train operation management systems of different lines. The virtual machine system according to claim 5, characterized in that each of the PRC device and the I / F device is implemented in the virtual machine pair.