Proxy-Based Virtual Resource Migration Across Remote Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Long-distance migration of virtual resources between remotely connected networks poses challenges in maintaining autonomy, privacy, and security, as existing methods fail to adequately protect the infrastructure and data from external access and breaches.

Innovation Solution

Establishing secure communication channels between proxy servers in source and destination networks, using proxy servers to maintain anonymity and security by routing traffic through public networks while keeping private addresses confidential, and employing virtual application networks to ensure insularity and efficient data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual resources are migrated over long-distance networks, then resource utilization and flexibility are improved, but network security and autonomy are compromised due to direct access requirements

Engineering Contradiction:
Improveresource migration flexibilityVSAvoidnetwork security vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces proxy servers as intermediary components between source and destination networks. These proxies establish secure communication channels that enable virtual resource migration while preventing direct access to internal network addresses. The proxy acts as a mediator that forwards traffic without exposing the actual host addresses, thus maintaining security while enabling migration flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If direct network access is used for migration, then communication efficiency is improved, but privacy and autonomy of network infrastructure are lost

Engineering Contradiction:
Improvemigration efficiencyVSAvoidnetwork address privacy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

Proxy servers serve as intermediaries that forward migration traffic without revealing actual network addresses. The source proxy and destination proxy communicate with each other using their own addresses, while keeping the source host and destination host addresses confidential. This maintains address privacy while enabling efficient migration communication through the proxy channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If remote network migration is implemented, then resource capacity utilization is improved, but complexity of securing communication channels increases

Engineering Contradiction:
Improveresource capacity utilizationVSAvoidsecure communication infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The proxy servers simplify the security infrastructure by centralizing the secure communication function. Instead of implementing complex security measures at each host, the patent uses proxies to establish and manage secure channels. This reduces the complexity at the host level while maintaining robust security through the proxy layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the communication channel through the proxy servers. The actual migration traffic is copied and forwarded through the secure proxy channel, while the original host addresses remain hidden. This copying mechanism enables secure remote migration without requiring complex point-to-point security configurations between all possible host pairs.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8924541B2Migration of virtual resources over remotely connected networks
Publication Date: 2014.12.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8924541B2 patent drawing
  • US8924541B2 patent drawing
  • US8924541B2 patent drawing

AI summary

Systems and methods for migrating a virtual resource from a source host in a source network to a destination host in a destination network are provided. In one embodiment, the method comprises establishing a secure communication connection between a source proxy in the source network and a destination proxy in the destination network; and monitoring migration traffic directed from the source host to the source proxy and forwarding said traffic to the destination proxy which in turn forwards the traffic to the destination host over the secure communication connection between the source proxy and the destination proxy, such that the communication addresses of the source host and the destination host remain guarded from direct access by an entity outside of the source network or the destination network.