Secure Live Migration of Trusted Execution Environment Virtual Machines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current live migration of trusted execution environment virtual machines (TVMs) in computing systems requires manual intervention by cloud service providers (CSPs), limiting scalability and efficiency, as it can only be performed one-to-one from a source to a destination computing system without automating the process.

Innovation Solution

Implementing secure live migration using smart contracts and blockchain technology to automate the migration process, allowing TVMs to be migrated from a single source to multiple destinations without manual intervention, by broadcasting system configuration information and using auctions to allocate TVMs to compatible destination systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If manual intervention is used to change system configuration on destination computing system, then migration can be performed, but the process is burdensome and not scalable

Engineering Contradiction:
Improvemigration process automationVSAvoidsystem configuration complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The destination computing system automatically performs configuration changes by retrieving system configuration information from the source computing system and applying it to itself, eliminating the need for manual administrator intervention. The system serves itself by autonomously completing the migration setup process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The source computing system transmits system configuration information to the destination computing system in advance of the actual migration execution. This preliminary transmission of configuration data enables the destination system to be pre-prepared for the migration, reducing on-site configuration complexity.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If one-to-one live migration is performed, then security is maintained, but scalability is limited

Engineering Contradiction:
Improvemigration throughputVSAvoidmigration security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The migration process is segmented into independent parallel operations: multiple source computing systems can simultaneously migrate to multiple destination computing systems. Each migration pair operates independently, maintaining security protocols while increasing overall throughput through parallelization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a universal migration framework that can handle both one-to-one and one-to-many migration scenarios. The same security protocols and configuration mechanisms apply universally across different migration topologies, enabling scalable deployment without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If manual configuration changes are required on destination system, then compatibility can be verified, but time consumption increases

Engineering Contradiction:
Improvemigration timeVSAvoidconfiguration accuracy
Core Design Contradiction:
Loss of timeVSManufacturing precision

Solution Approach 1:

The destination computing system automatically verifies configuration compatibility by comparing its current state with the received system configuration information. This feedback mechanism ensures configuration accuracy without requiring manual verification, reducing time loss while maintaining precision.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Manual configuration verification and changes are replaced with automated electronic processes. The system uses software-based configuration management and validation algorithms to substitute human administrators, dramatically reducing time consumption while maintaining or improving configuration accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240168787A1Secure live migration of trusted execution environment virtual machines using smart contracts
Publication Date: 2024.05.23 INTEL CORP
  • US20240168787A1 patent drawing
  • US20240168787A1 patent drawing
  • US20240168787A1 patent drawing

AI summary

The technology disclosed herein includes broadcasting, to a plurality of destination computing systems, a request to live migrate at least one trusted execution environment virtual machine (TVM) to at least one of the plurality of destination computing systems, receiving one or more bids from at least one of the plurality of destination computing systems, allocating the at least one TVM to at least one of the plurality of destination computing systems based at least on a bidding price in the one or more bids, automatically live migrating the at least one TVM to the at least one of the plurality of destination computing systems based on the allocating, and storing live migration allocation information of the at least one TVM on a first blockchain.