Network Storage Access Control for Live Virtual Machine Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized computing resources face challenges in maintaining data integrity and performance during live migration across network-based storage, as modifications may not be confirmed before instance migration, potentially leading to data inconsistencies and service disruptions.

Innovation Solution

Implementing a live migration process with phases such as prepare, flip, and cleanup, where the destination host is pre-configured, hot data is copied, and access limitations are modified to ensure seamless transition, with network-based storage access control enforcing lease states to manage access rights and prevent data inconsistencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If live migration is performed without storage access control, then migration speed is improved, but data integrity deteriorates due to unconfirmed modifications

Engineering Contradiction:
Improvemigration speedVSAvoiddata integrity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a standby connection at the destination host before the actual migration occurs. This allows the destination to be pre-configured and ready, enabling faster migration while maintaining data integrity through controlled access transitions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary access control mechanism that mediates between source and destination hosts during migration. This intermediary controls storage access rights, ensuring data integrity by managing the transition of access permissions while allowing rapid migration to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control is enforced during migration, then data integrity is improved, but operational downtime increases due to access limitations

Engineering Contradiction:
Improvedata integrityVSAvoidoperational downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Access control configurations are established in advance during the prepare phase. The standby connection is set up before migration, so access limitations are already in place and do not cause downtime during the actual migration execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous useful action by allowing the standby connection to be established and configured while the instance continues to operate at the source. The transition of access rights occurs seamlessly, minimizing interruption to service.

Inventive Principle:
Principle #20Continuity of useful action

3Stability of the object's composition

If hot data is copied during migration, then data consistency is improved, but migration time increases due to additional data transfer

Engineering Contradiction:
Improvedata consistencyVSAvoidmigration time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

Hot data copying is performed as a preliminary action during the prepare phase before the instance is switched to the destination. This allows data consistency to be established in advance, so the actual migration can proceed quickly without additional data transfer delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9836327B1Network-based storage access control for migrating live storage clients
Publication Date: 2017.12.05 AMAZON TECH INC
  • US9836327B1 patent drawing
  • US9836327B1 patent drawing
  • US9836327B1 patent drawing

AI summary

A network-based storage resource may implement access control for virtual computing resources that utilize the storage resource during live migration of the virtual computing resources. A network-based storage resource may enforce an access control that limits access to a host of a virtual compute instance. Upon detecting migration of the virtual compute instance, the network-based storage resource may allow a connection to be established with a destination host for the virtual compute instance. The access control mechanism may be updated to limit access to the destination host for data stored for the virtual compute instance at the network-based storage resource.