Locked Virtual Machines Prevent Unauthorized Host Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud provider networks, virtual machines may experience accidental interruptions due to migration, rebooting, or termination, which can disrupt critical services like emergency call centers and dispatch management, as these actions are not always authorized or controlled.

Innovation Solution

Implementing a system where virtual machines can be locked to specific host machines, preventing unauthorized mutations such as migration, pausing, rebooting, or termination, by enforcing policies at the host machine level, ensuring only authorized entities can perform operations on locked virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machines are allowed to be migrated or terminated for load balancing, then resource utilization and system flexibility are improved, but service availability and reliability deteriorate

Engineering Contradiction:
Improvesystem flexibilityVSAvoidservice availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by implementing different permission levels for different virtual machines. Critical virtual machines are designated with restricted migration and termination permissions, while non-critical virtual machines maintain standard flexibility. This allows the system to have localized restrictions where needed while preserving overall adaptability for non-critical workloads.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic permission assignment where virtual machines can be configured with different levels of migration and termination restrictions based on their criticality. The system dynamically adjusts resource management behavior based on the designated importance of individual virtual machines, allowing flexible resource allocation for non-critical VMs while protecting critical ones.

Inventive Principle:
Principle #15Dynamics

2Reliability

If virtual machines are locked to prevent migration and termination, then service availability is improved, but resource utilization and load balancing capability worsen

Engineering Contradiction:
Improveservice availabilityVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing differentiated resource management policies. Critical virtual machines with locked status maintain high availability while non-critical virtual machines remain subject to standard resource management and load balancing operations. This localized approach ensures resource utilization is optimized for non-critical workloads while protecting critical services.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts resource allocation and load balancing behavior based on the locked status of virtual machines. When load balancing is needed, the system respects the locked status of critical VMs and redistributes loads to non-critical or unlocked VMs, maintaining both resource utilization efficiency and service availability for critical workloads.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If virtual machines can be freely managed by administrators, then ease of operation is improved, but accidental interruptions and unauthorized actions increase

Engineering Contradiction:
Improveadministrative flexibilityVSAvoidaccidental interruptions
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-designating critical virtual machines with locked status before incidents can occur. This preventive measure blocks potential accidental interruptions, unauthorized terminations, and unintended migrations of critical virtual machines, while still allowing administrators full access and control over non-critical virtual machines.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements local quality by applying different levels of administrative control to different virtual machines. Critical virtual machines have restricted permissions that prevent accidental or unauthorized actions, while non-critical virtual machines maintain full administrative accessibility. This allows ease of operation for routine management while protecting against harmful actions on critical services.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11507408B1Locked virtual machines for high availability workloads
Publication Date: 2022.11.22 AMAZON TECH INC
  • US11507408B1 patent drawing
  • US11507408B1 patent drawing
  • US11507408B1 patent drawing

AI summary

Disclosed are various embodiments for a system that hardware locks a virtual machine to a host machine. The host machine can include a processor and a memory. A hypervisor can be stored in the memory that, when executed by the processor, causes the computing device to host one or more virtual machines. In addition, machine readable instructions stored in the memory that, when executed by the processor, cause the computing device to at least: receive a request to perform an operation on a virtual machine hosted by the hypervisor; evaluate the request to determine that the request complies with a policy; and in response to a determination that the request complies with the policy, cause the hypervisor to initiate the operation.