Encrypted Guest Migration via Dirty Page Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant cloud environments, migrating encrypted guests is inefficient due to security concerns and high latency, as hypervisors lack access to encryption keys, leading to unnecessary data transfer of unmodified memory pages and prolonged downtime.

Innovation Solution

Track and transfer only the memory pages modified during the boot process of an encrypted guest, allowing the destination host to instantiate the guest without access to encryption keys, thereby reducing data transfer and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all memory pages are transferred during guest migration, then data integrity is ensured, but network bandwidth usage increases and transfer time extends

Engineering Contradiction:
Improvedata integrityVSAvoidnetwork bandwidth usage
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the memory transfer process by dividing memory pages into two categories: dirty pages (modified during boot) and clean pages (unmodified). Only dirty pages are transferred over the network, while clean pages are reconstructed locally at the destination host. This segmentation reduces network bandwidth consumption while ensuring data integrity for the pages that actually contain guest state information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary tracking of dirty pages during the guest boot process on the source host. By identifying which pages will be modified before migration, the system prepares a precise list of pages that need transfer. This preliminary action prevents unnecessary transfer of clean pages and ensures that all necessary dirty pages are captured for accurate guest state reconstruction.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If encryption keys are made accessible to hypervisors for migration, then migration speed improves, but security is compromised

Engineering Contradiction:
Improvemigration speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary that securely holds and manages encryption keys during the migration process. The TEE acts as a mediator between the hypervisor and the encrypted memory, allowing the hypervisor to perform migration operations without directly accessing the encryption keys. This maintains security while enabling efficient migration through hardware-accelerated encryption operations within the TEE.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements local quality by providing different access permissions to different components: the hypervisor gets full access to unencrypted memory for migration operations, while the encryption keys remain securely stored in the TEE with restricted access. This localized security approach allows each component to operate with the minimum necessary privileges, improving overall system security without hindering migration productivity.

Inventive Principle:
Principle #3Local quality

3Reliability

If entire memory space is transferred including unmodified pages, then migration completeness is ensured, but latency increases

Engineering Contradiction:
Improvemigration completenessVSAvoidmigration latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by transferring only the necessary subset of memory pages (dirty pages) rather than the entire memory space. The system accurately identifies and transfers only those pages that contain modified guest state information, while clean pages are reconstructed at the destination. This partial transfer approach maintains migration completeness for essential data while significantly reducing migration latency by eliminating unnecessary data transfer.

Inventive Principle:
Principle #16Partial or excessive action

4Measurement precision

If tracked pages are transferred only after boot completion, then accuracy of dirty page identification improves, but guest downtime increases

Engineering Contradiction:
Improvedirty page identification accuracyVSAvoidguest downtime
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements continuous tracking of dirty pages throughout the guest boot process rather than performing a single post-boot scan. The tracking mechanism operates continuously from the start of the boot process, accumulating information about which pages are modified. This continuous action allows the system to identify all dirty pages with high accuracy while minimizing the pause time needed for tracking, as the tracking occurs concurrently with the boot process rather than requiring a separate post-boot scanning phase.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10866814B2Efficient instantiation of encrypted guests
Publication Date: 2020.12.15 RED HAT INC
  • US10866814B2 patent drawing
  • US10866814B2 patent drawing
  • US10866814B2 patent drawing

AI summary

Efficient instantiation of encrypted guests is disclosed. In an example, a first host with a first hypervisor is separated from a second host with a second hypervisor by a network. The first hypervisor executes to allocate a requested amount of memory associated with a first guest on the first host. Pages of the requested amount of memory written to by a boot process of the first guest are tracked. The second hypervisor is requested to allocate the requested amount of memory on the second host. All tracked pages written to by the boot process are transferred to the second host. In response to transferring all of the tracked pages, a transfer completion confirmation is sent to the second hypervisor and a second guest that is a migrated copy of the first guest is instantiated on the second host with the transferred pages from the first guest.