Live Legacy VM to Confidential VM Conversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for converting legacy virtual machines to confidential virtual machines require significant downtime and resource expenditure, as they involve creating new virtual machine images, provisioning, and launching from a starting state.
Innovation Solution
The technology enables live migration of legacy virtual machines to confidential virtual machines by capturing the state of a running legacy VM, encrypting it, securely transferring it to a confidential computing-capable device, and having a trusted security module decrypt and validate the state before provisioning and starting the confidential VM.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If legacy virtual machines are converted to confidential virtual machines using traditional methods (creating new images, provisioning, launching from starting state), then security protection is improved, but conversion time and system downtime increase significantly
Solution Approach 1:
The patent applies preliminary action by capturing and encrypting the legacy VM state before conversion is needed. The state capture mechanism prepares the VM data in advance, allowing rapid conversion when the transition to confidential VM is initiated, thus reducing conversion time while maintaining security through pre-established encryption
Solution Approach 2:
The patent introduces a state capture and encryption mechanism as an intermediary between the legacy VM and the confidential VM. This intermediary component captures the VM state, encrypts it, and transfers it to the confidential VM environment, enabling seamless conversion without requiring traditional time-consuming provisioning processes
2Reliability
If legacy virtual machines are converted to confidential virtual machines using traditional methods, then security protection is improved, but resource expenditure increases
Solution Approach 1:
The patent uses copying by creating a state snapshot of the legacy VM rather than duplicating the entire VM infrastructure. This state capture approach copies only the essential runtime data, reducing resource consumption compared to traditional methods that require creating complete new VM images and provisioning full system resources
Solution Approach 2:
The patent applies parameter changes by transitioning the VM from unencrypted to encrypted state through state capture and decryption in the confidential environment. This parameter transformation allows the VM to maintain its operational characteristics while changing its security properties, avoiding the need to provision entirely new resources
3Reliability
If legacy virtual machines are converted to confidential virtual machines using traditional methods, then security protection is improved, but operational continuity deteriorates
Solution Approach 1:
The patent implements continuity of useful action by maintaining VM execution throughout the conversion process. The state capture mechanism allows the VM to continue running while its state is captured and encrypted, and the confidential VM can be launched with the captured state to resume execution, ensuring uninterrupted operational continuity
Solution Approach 2:
By capturing the VM state in advance and keeping it in a ready-to-use encrypted format, the system prepares for rapid conversion without stopping the VM. This preliminary state capture enables the confidential VM to start execution immediately upon conversion, maintaining continuous operation
Data Source
AI summary
A legacy virtual machine (a virtual machine not operating in a secure environment) can be converted to a confidential virtual machine (a virtual that operates in a secure environment) on the fly, with little downtime experienced by the legacy virtual machine (VM) owner. A legacy VM operating either on a legacy platform (a platform not having confidential computing capabilities) or a confidential computing-capable platform can be converted to a confidential VM (CVM). The legacy VM can be migrated to another computing device as part of the conversion or be converted into a CVM that executes on the same computing device on which the legacy VM was running. A trusted security module can be responsible for starting a VM-to-CVM conversion session, validating the state of legacy virtual machine to be converted, provision a CVM with the state of the legacy virtual machine, and end a VM-to-CVM conversion session.


