Encrypted Guest Migration via Dirty Page Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant cloud environments, migrating encrypted guests is inefficient due to security concerns and high latency, as hypervisors lack access to encryption keys, leading to unnecessary data transfer of unmodified memory pages and prolonged downtime.
Innovation Solution
Track and transfer only the memory pages modified during the boot process of an encrypted guest, allowing the destination host to instantiate the guest without access to encryption keys, thereby reducing data transfer and latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all memory pages are transferred during guest migration, then data integrity is ensured, but network bandwidth usage increases and transfer time extends
Solution Approach 1:
The patent segments the memory transfer process by dividing memory pages into two categories: dirty pages (modified during boot) and clean pages (unmodified). Only dirty pages are transferred over the network, while clean pages are reconstructed locally at the destination host. This segmentation reduces network bandwidth consumption while ensuring data integrity for the pages that actually contain guest state information.
Solution Approach 2:
The patent performs preliminary tracking of dirty pages during the guest boot process on the source host. By identifying which pages will be modified before migration, the system prepares a precise list of pages that need transfer. This preliminary action prevents unnecessary transfer of clean pages and ensures that all necessary dirty pages are captured for accurate guest state reconstruction.
2Productivity
If encryption keys are made accessible to hypervisors for migration, then migration speed improves, but security is compromised
Solution Approach 1:
The patent introduces a trusted execution environment (TEE) as an intermediary that securely holds and manages encryption keys during the migration process. The TEE acts as a mediator between the hypervisor and the encrypted memory, allowing the hypervisor to perform migration operations without directly accessing the encryption keys. This maintains security while enabling efficient migration through hardware-accelerated encryption operations within the TEE.
Solution Approach 2:
The patent implements local quality by providing different access permissions to different components: the hypervisor gets full access to unencrypted memory for migration operations, while the encryption keys remain securely stored in the TEE with restricted access. This localized security approach allows each component to operate with the minimum necessary privileges, improving overall system security without hindering migration productivity.
3Reliability
If entire memory space is transferred including unmodified pages, then migration completeness is ensured, but latency increases
Solution Approach 1:
The patent applies partial action by transferring only the necessary subset of memory pages (dirty pages) rather than the entire memory space. The system accurately identifies and transfers only those pages that contain modified guest state information, while clean pages are reconstructed at the destination. This partial transfer approach maintains migration completeness for essential data while significantly reducing migration latency by eliminating unnecessary data transfer.
4Measurement precision
If tracked pages are transferred only after boot completion, then accuracy of dirty page identification improves, but guest downtime increases
Solution Approach 1:
The patent implements continuous tracking of dirty pages throughout the guest boot process rather than performing a single post-boot scan. The tracking mechanism operates continuously from the start of the boot process, accumulating information about which pages are modified. This continuous action allows the system to identify all dirty pages with high accuracy while minimizing the pause time needed for tracking, as the tracking occurs concurrently with the boot process rather than requiring a separate post-boot scanning phase.
Data Source
AI summary
Efficient instantiation of encrypted guests is disclosed. In an example, a first host with a first hypervisor is separated from a second host with a second hypervisor by a network. The first hypervisor executes to allocate a requested amount of memory associated with a first guest on the first host. Pages of the requested amount of memory written to by a boot process of the first guest are tracked. The second hypervisor is requested to allocate the requested amount of memory on the second host. All tracked pages written to by the boot process are transferred to the second host. In response to transferring all of the tracked pages, a transfer completion confirmation is sent to the second hypervisor and a second guest that is a migrated copy of the first guest is instantiated on the second host with the transferred pages from the first guest.


