Hypervisor Layer Network Security for Virtual Machine Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional virtual machine migration systems lack effective network security and routing control, requiring complex updates to switches and firewalls, and provide limited security, especially in large networks where virtual machines are only as secure as the weakest individual machine.

Innovation Solution

The solution involves enforcing network security and routing at the hypervisor layer, independent of guest operating systems, by copying and updating security and routing controls at the hypervisor level, allowing seamless migration of virtual machines between hardware devices without updating real switches or routers, and maintaining consistent IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security and routing controls are enforced at individual machine levels in conventional virtual machine migration systems, then each machine can maintain its own security policies, but the system becomes complex requiring updates to multiple switches and firewalls during migration

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges network security and routing control functions from multiple distributed locations (individual machines, switches, firewalls) into a centralized hypervisor layer. This consolidation simplifies the system architecture by eliminating the need to update multiple separate security devices during VM migration, while maintaining comprehensive security coverage through centralized policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The hypervisor acts as an intermediary layer between virtual machines and the physical network infrastructure. By enforcing security and routing controls at this intermediate layer, the system avoids the complexity of coordinating updates across multiple network devices while ensuring that security policies are consistently applied regardless of which physical host a VM resides on.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security controls are distributed across multiple switches and firewalls in conventional systems, then local security policies can be enforced, but migration requires complex coordination of updates across all these devices

Engineering Contradiction:
Improvelocal security policy enforcementVSAvoidmigration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent combines security control functions from multiple distributed switches and firewalls into a unified security enforcement mechanism at the hypervisor layer. This allows the system to maintain adaptable security policies for different VMs while eliminating the time-consuming coordination required to update multiple separate security devices during migration events.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If virtual machines can migrate freely between hardware devices, then system utilization and flexibility improve, but network security becomes vulnerable as VMs are only as secure as the weakest individual machine

Engineering Contradiction:
Improvesystem utilizationVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent copies security control capabilities from a centralized hypervisor layer to each virtual machine instance during migration. This ensures that security policies are consistently replicated and enforced across all hardware destinations, preventing the security vulnerability where VMs would be only as secure as their host machine. VMs maintain their security posture regardless of which physical host they migrate to.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8776059B2Moveable access control list (ACL) mechanisms for hypervisors and virtual machines and virtual port firewalls
Publication Date: 2014.07.08 DAEDALUS BLUE LLC
  • US8776059B2 patent drawing
  • US8776059B2 patent drawing
  • US8776059B2 patent drawing

AI summary

A computer implemented method of virtual machine migration with filtered network connectivity includes enforcing network security and routing at a hypervisor layer which is independent of guest operating systems via dynamic updating of routing controls initiated by a migration of said virtual machine from a first device to a second device.