Cloud VM Recovery Without Failed Machine Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud computing environments, such as Amazon Web Services (AWS), require specific drivers to be injected into virtual machines (VMs) for proper operation, which can be challenging during disaster recovery scenarios where immediate access to the failed device's credentials is not available.
Innovation Solution
A data storage management system that recovers backup data and system states from failed machines, custom-configures recovery VMs in the cloud, and injects necessary drivers without requiring the failed machine's credentials, using an enhanced bare-metal restore process and a temporary, password-protected user ID.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If individualized credentials of failed computing devices are used to inject drivers into recovery VMs, then the VMs can be configured to operate correctly in the cloud environment, but the recovery process becomes slow and prone to operator error due to manual credential entry
Solution Approach 1:
The system performs self-service by automatically retrieving credentials from the backup image and injecting drivers without requiring manual operator intervention. The storage manager autonomously completes the entire driver injection process, eliminating both the slowness of manual entry and the potential for human error.
Solution Approach 2:
The credentials are preserved in the backup image during the initial backup process, preparing them in advance for future recovery operations. This preliminary action ensures that when recovery is needed, the credentials are already available and do not need to be manually re-entered, significantly speeding up the recovery process.
2Reliability
If manual credential entry is required for each recovery VM, then security can be maintained through individualized access control, but the process becomes time-consuming and cannot scale to large numbers of failed devices
Solution Approach 1:
The system autonomously retrieves and applies credentials from the backup image without manual intervention, maintaining security through automated credential management while eliminating the time loss associated with manual entry. The process scales efficiently to large numbers of devices because it requires no human operator time.
Solution Approach 2:
The system dramatically accelerates the credential application process by using automated scripts that can inject drivers into multiple VMs simultaneously or in rapid succession, reducing recovery time from hours or days to minutes while maintaining the same security standards.
3Productivity
If credentials are immediately available during disaster recovery, then rapid restoration of computing devices is possible, but security risks increase due to potential exposure of sensitive authentication information
Solution Approach 1:
The system extracts only the specific credentials needed for driver injection from the backup image, rather than exposing or handling all authentication information. This targeted extraction minimizes the security risk by limiting credential exposure to only what is necessary for the recovery operation.
Solution Approach 2:
The temporary credentials used during the automated driver injection process are discarded immediately after use and not stored or reused. This approach allows rapid restoration while minimizing security risks, as the credentials exist only transiently in memory during the automated process and are then permanently deleted.
4Productivity
If automated driver injection without credentials is implemented, then recovery scalability is improved, but the system complexity increases due to the need for enhanced bare-metal restore processes
Solution Approach 1:
The system merges the credential retrieval, driver injection, and VM configuration steps into a single automated workflow. This consolidation improves scalability by eliminating manual intervention points, while the integrated nature of the process actually reduces operational complexity despite the enhanced technical capabilities required.
Solution Approach 2:
The storage manager acts as an intermediary that bridges the backup image, the cloud environment, and the driver injection process. This intermediary handles all the complex automated operations, shielding the user from the underlying complexity while enabling scalable recovery across large numbers of devices.
Data Source
AI summary
The disclosed approach works without the individualized credentials of failed machines when setting up recovery VMs in a cloud computing environment. Each recovery VMs is customized to properly correspond to the system state of its failed counterpart. An illustrative data storage management system recovers backup data and system states collected from the counterpart computing devices, custom-configures recovery VMs in the cloud computing environment, and injects the desired drivers into each recovery VM during an enhanced bare-metal restore process. The enhanced bare-metal restore process works without the failed computer's credentials. The system also restores the backed up data to recovery volumes attached to the recovery VMs. The present approach is both scalable and secure. When the enhanced bare-metal restore process completes, each cloud-based recovery VM presents a user interface that, for the first time after the computing device has failed, asks for the individualized credentials of the failed machine.


