Live Legacy VM to Confidential VM Conversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for converting legacy virtual machines to confidential virtual machines require significant downtime and resource expenditure, as they involve creating new virtual machine images, provisioning, and launching from a starting state.

Innovation Solution

The technology enables live migration of legacy virtual machines to confidential virtual machines by capturing the state of a running legacy VM, encrypting it, securely transferring it to a confidential computing-capable device, and having a trusted security module decrypt and validate the state before provisioning and starting the confidential VM.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy virtual machines are converted to confidential virtual machines using traditional methods (creating new images, provisioning, launching from starting state), then security protection is improved, but conversion time and system downtime increase significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidconversion time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by capturing and encrypting the legacy VM state before conversion is needed. The state capture mechanism prepares the VM data in advance, allowing rapid conversion when the transition to confidential VM is initiated, thus reducing conversion time while maintaining security through pre-established encryption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a state capture and encryption mechanism as an intermediary between the legacy VM and the confidential VM. This intermediary component captures the VM state, encrypts it, and transfers it to the confidential VM environment, enabling seamless conversion without requiring traditional time-consuming provisioning processes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If legacy virtual machines are converted to confidential virtual machines using traditional methods, then security protection is improved, but resource expenditure increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidresource expenditure
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent uses copying by creating a state snapshot of the legacy VM rather than duplicating the entire VM infrastructure. This state capture approach copies only the essential runtime data, reducing resource consumption compared to traditional methods that require creating complete new VM images and provisioning full system resources

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies parameter changes by transitioning the VM from unencrypted to encrypted state through state capture and decryption in the confidential environment. This parameter transformation allows the VM to maintain its operational characteristics while changing its security properties, avoiding the need to provision entirely new resources

Inventive Principle:
Principle #35Parameter changes

3Reliability

If legacy virtual machines are converted to confidential virtual machines using traditional methods, then security protection is improved, but operational continuity deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperational continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements continuity of useful action by maintaining VM execution throughout the conversion process. The state capture mechanism allows the VM to continue running while its state is captured and encrypted, and the confidential VM can be launched with the captured state to resume execution, ensuring uninterrupted operational continuity

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

By capturing the VM state in advance and keeping it in a ready-to-use encrypted format, the system prepares for rapid conversion without stopping the VM. This preliminary state capture enables the confidential VM to start execution immediately upon conversion, maintaining continuous operation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250123878A1Legacy virtual machine to confidential virtual machine conversion
Publication Date: 2025.04.17 INTEL CORP
  • US20250123878A1 patent drawing
  • US20250123878A1 patent drawing
  • US20250123878A1 patent drawing

AI summary

A legacy virtual machine (a virtual machine not operating in a secure environment) can be converted to a confidential virtual machine (a virtual that operates in a secure environment) on the fly, with little downtime experienced by the legacy virtual machine (VM) owner. A legacy VM operating either on a legacy platform (a platform not having confidential computing capabilities) or a confidential computing-capable platform can be converted to a confidential VM (CVM). The legacy VM can be migrated to another computing device as part of the conversion or be converted into a CVM that executes on the same computing device on which the legacy VM was running. A trusted security module can be responsible for starting a VM-to-CVM conversion session, validating the state of legacy virtual machine to be converted, provision a CVM with the state of the legacy virtual machine, and end a VM-to-CVM conversion session.