Security-Aware Virtual Machine Allocation in Cloud Hypervisors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing systems, particularly public clouds, face security risks due to shared hypervisors, where a compromise in one virtual machine can affect others, leading to potential large losses for users, and current allocation methods do not systematically consider security, discouraging users with significant assets from utilizing cloud services.
Innovation Solution
A method for allocating virtual machines over hypervisors in a security-aware fashion using game theory to induce equilibrium among users, grouping VMs of similar loss potential, creating risk-tiered hypervisor environments, and implementing a risk-balanced allocation process to minimize interdependency and enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple virtual machines are allocated to the same hypervisor to maximize resource utilization, then productivity and resource efficiency are improved, but security risk increases due to potential compromise propagation across VMs
Solution Approach 1:
The patent segments VMs into different security tiers based on their security requirements and risk profiles. High-security VMs are isolated from low-security VMs by allocating them to different hypervisors or different partitions within the same hypervisor, thereby containing potential security breaches while maintaining overall resource utilization.
Solution Approach 2:
The patent applies different allocation strategies to different VMs based on their specific security needs. Critical VMs receive preferential allocation to secure hypervisors with enhanced security features, while less critical VMs can be placed on hypervisors with standard security configurations, optimizing both security and resource utilization.
2Reliability
If security-aware allocation is implemented to protect against hypervisor compromise, then security is improved, but device complexity increases due to additional allocation constraints and game theory modeling
Solution Approach 1:
The patent transforms the security allocation problem into a game theory model where VMs are assigned to hypervisors based on security parameters such as risk tolerance, security requirements, and potential loss. This parameter-based approach provides a systematic framework that manages complexity through mathematical modeling rather than ad-hoc security decisions.
Solution Approach 2:
The patent enables VMs to self-allocate to appropriate hypervisors based on their own security requirements and the current state of hypervisor security profiles. This self-service mechanism reduces the need for complex centralized allocation decisions while maintaining security-aware placement.
3Reliability
If VMs are isolated on separate hypervisors to minimize security interdependency, then security is improved, but productivity decreases due to reduced resource sharing and consolidation
Solution Approach 1:
The patent applies differentiated isolation strategies where VMs with high security requirements are isolated on dedicated hypervisors, while VMs with lower security requirements can share hypervisors to maximize resource utilization. This local quality approach ensures security-critical VMs receive appropriate isolation while maintaining overall system efficiency.
4Ease of operation
If cloud providers allocate VMs without considering security externalities, then ease of operation is improved through simpler allocation processes, but security deteriorates due to negative externalities affecting other users
Solution Approach 1:
The patent implements a feedback mechanism where the security state of each hypervisor is continuously monitored and used to inform allocation decisions. When a hypervisor's security profile changes or a compromise is detected, the system adjusts VM allocations accordingly, providing automatic feedback that addresses security externalities without requiring complex manual intervention.
Data Source
AI summary
A method for enhancing security in a cloud computing system by allocating virtual machines over hypervisors, in a cloud computing environment, in a security-aware fashion. The invention solves the cloud user risk problem by inducing a state such that, unless there is a change in the conditions under which the present invention operates, the cloud users do not gain by deviating from the allocation induced by the present invention. The invention's methods include grouping virtual machines of similar loss potential on the same hypervisor, creating hypervisor environments of similar total loss, and implementing a risk tiered system of hypervisors based on expense factors.


