Log Management Device for Cloud Virtual Machine Fault Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based services, tenants are limited in their ability to view logs of hypervisors and hardware, which hinders fault analysis and response times due to the sensitive nature of this information.

Innovation Solution

A log management device that stores management information linking virtual machine identification with environment information, allowing it to generate and provide logs with sensitive information replaced by node identifiers, ensuring security while enabling tenants to access relevant logs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tenants are restricted from viewing logs of hypervisors and hardware to maintain system security, then system security is improved, but fault analysis capability deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidfault analysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments log information into two categories: sensitive log information (hypervisor and hardware logs) and non-sensitive log information (virtual machine logs). Tenants are granted access only to non-sensitive logs, while sensitive logs remain restricted. This segmentation allows tenants to perform fault analysis on their virtual machines without exposing them to sensitive infrastructure information, thus resolving the contradiction between security and fault analysis capability.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If all log information is made accessible to tenants for improved fault analysis, then fault analysis capability is improved, but system security deteriorates

Engineering Contradiction:
Improvefault analysis capabilityVSAvoidsystem security
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a log management device as an intermediary between tenants and log information. This intermediary selectively provides non-sensitive log information to tenants while filtering out sensitive information. The log management device acts as a mediator that enables tenants to perform fault analysis on their virtual machines without direct access to sensitive hypervisor and hardware logs, thus maintaining system security while improving fault analysis capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If sensitive log information is provided to tenants to enhance troubleshooting, then fault analysis capability is improved, but information leakage risk increases

Engineering Contradiction:
Improvefault analysis capabilityVSAvoidinformation leakage risk
Core Design Contradiction:
Loss of informationVSObject-generated harmful factors

Solution Approach 1:

The patent segments log information based on sensitivity levels, categorizing logs into sensitive (hypervisor and hardware) and non-sensitive (virtual machine) categories. This segmentation enables the system to provide tenants with adequate fault analysis capability through access to non-sensitive logs while preventing information leakage of sensitive infrastructure details. The clear division ensures that troubleshooting can be performed without exposing critical system information.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10747561B2Log management device and log management method
Publication Date: 2020.08.18 FSAS TECH INC
  • US10747561B2 patent drawing
  • US10747561B2 patent drawing
  • US10747561B2 patent drawing

AI summary

A log management device includes one or more memories configured to store management information indicating each relationship between identification information of each virtual machine and identification information regarding each environment in which the each virtual machine operates, and one or more processor coupled to the one or memories and configured to, by referring to the management information, obtain a first log regarding a first environment operating a first virtual machine on the basis of identification information of the first virtual machine, perform generation of a second log in which specific information included in the first log is changed to a specific identifier regarding the first environment, and output the second log in response to receiving a request for a log regarding the first virtual machine.