Locked Virtual Machines Prevent Unauthorized Host Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud provider networks, virtual machines may experience accidental interruptions due to migration, rebooting, or termination, which can disrupt critical services like emergency call centers and dispatch management, as these actions are not always authorized or controlled.
Innovation Solution
Implementing a system where virtual machines can be locked to specific host machines, preventing unauthorized mutations such as migration, pausing, rebooting, or termination, by enforcing policies at the host machine level, ensuring only authorized entities can perform operations on locked virtual machines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machines are allowed to be migrated or terminated for load balancing, then resource utilization and system flexibility are improved, but service availability and reliability deteriorate
Solution Approach 1:
The patent applies local quality by implementing different permission levels for different virtual machines. Critical virtual machines are designated with restricted migration and termination permissions, while non-critical virtual machines maintain standard flexibility. This allows the system to have localized restrictions where needed while preserving overall adaptability for non-critical workloads.
Solution Approach 2:
The patent implements dynamic permission assignment where virtual machines can be configured with different levels of migration and termination restrictions based on their criticality. The system dynamically adjusts resource management behavior based on the designated importance of individual virtual machines, allowing flexible resource allocation for non-critical VMs while protecting critical ones.
2Reliability
If virtual machines are locked to prevent migration and termination, then service availability is improved, but resource utilization and load balancing capability worsen
Solution Approach 1:
The patent applies local quality by implementing differentiated resource management policies. Critical virtual machines with locked status maintain high availability while non-critical virtual machines remain subject to standard resource management and load balancing operations. This localized approach ensures resource utilization is optimized for non-critical workloads while protecting critical services.
Solution Approach 2:
The system dynamically adjusts resource allocation and load balancing behavior based on the locked status of virtual machines. When load balancing is needed, the system respects the locked status of critical VMs and redistributes loads to non-critical or unlocked VMs, maintaining both resource utilization efficiency and service availability for critical workloads.
3Ease of operation
If virtual machines can be freely managed by administrators, then ease of operation is improved, but accidental interruptions and unauthorized actions increase
Solution Approach 1:
The patent applies preliminary anti-action by pre-designating critical virtual machines with locked status before incidents can occur. This preventive measure blocks potential accidental interruptions, unauthorized terminations, and unintended migrations of critical virtual machines, while still allowing administrators full access and control over non-critical virtual machines.
Solution Approach 2:
The patent implements local quality by applying different levels of administrative control to different virtual machines. Critical virtual machines have restricted permissions that prevent accidental or unauthorized actions, while non-critical virtual machines maintain full administrative accessibility. This allows ease of operation for routine management while protecting against harmful actions on critical services.
Data Source
AI summary
Disclosed are various embodiments for a system that hardware locks a virtual machine to a host machine. The host machine can include a processor and a memory. A hypervisor can be stored in the memory that, when executed by the processor, causes the computing device to host one or more virtual machines. In addition, machine readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least: receive a request to perform an operation on a virtual machine hosted by the hypervisor; evaluate the request to determine that the request complies with a policy; and in response to a determination that the request complies with the policy, cause the hypervisor to initiate the operation.


