Virtual Device Emulation for Secure Distributed Computing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Implementing reliable and secure distributed computing systems that manage virtual machines is challenging due to the difficulty of exposing real devices to guest operating systems without risking malware or erroneous code, and ensuring resilience and reliability across the system without additional user effort or delay.
Innovation Solution
A system that provides varying degrees of reliability and security by hiding reliability and security functions from users, allowing them to specify desired levels without implementation, using a hierarchy of failure groups to protect against simultaneous failures, and emulating virtual devices that mimic real devices, ensuring data redundancy and security without user intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If real devices are exposed to guest operating systems, then device functionality is provided, but security risks increase due to potential malware or erroneous code
Solution Approach 1:
The patent introduces virtual devices as an intermediary layer between the guest operating system and real physical devices. The virtual device driver in the guest OS interacts with virtual devices, which are then mapped to real devices by the hypervisor. This intermediary approach allows device functionality to be provided while preventing direct exposure of real devices to potentially malicious guest OS code, thus resolving the security risk.
Solution Approach 2:
The patent creates virtual copies of real devices that can be safely exposed to guest operating systems. Instead of providing direct access to physical devices, the system creates virtual device instances that replicate the functionality of real devices but operate within controlled boundaries enforced by the hypervisor, eliminating security risks while maintaining operational functionality.
2Reliability
If reliability functions are implemented in distributed systems, then system resilience is improved, but user effort and system complexity increase
Solution Approach 1:
The patent implements automatic failure detection and recovery mechanisms where the system monitors itself and performs corrective actions without user intervention. The distributed system automatically detects failures in nodes or devices and reallocates workloads or activates backup resources, providing enhanced reliability while keeping the system transparent to users and avoiding additional complexity from manual management.
Solution Approach 2:
The patent combines reliability management functions directly into the hypervisor and virtual device layer, merging monitoring, failure detection, and recovery operations with the existing virtualization infrastructure. This integration approach provides system resilience without requiring separate complexity layers, as the reliability functions are embedded within the existing system architecture.
3Object-affected harmful factors
If virtual devices are used to protect against security risks, then security is improved, but device emulation complexity increases
Solution Approach 1:
The patent creates a universal virtual device framework that can represent multiple types of physical devices through a common virtualization interface. The hypervisor handles device-specific emulation details while presenting standardized virtual devices to guest OSs, providing security protection through virtualization while reducing emulation complexity through universal device models that can be applied across different device types.
Data Source
AI summary
Providing differing degrees of reliability or security for distinct devices within a reliable distributed system. Allowing virtual machines to operate in a reliable distributed system without either exposing the actual available devices to guest operating systems, or requiring the guest OS to maintain, or to maintain information about, reliability or security. Methods are responsive to a hierarchy of possible reliability or security failures, to guard more carefully against simultaneous failures of reliability or breaches of security, without additional work or delay. Functions invoked by the user that relate to reliability and security are hidden, so the user can specify a degree of reliability or security without having to implement those requirements themselves. Providing a uniform set of resources available to all users, separating out those individual resources that are allocated to particular users, and emulating particular devices at the request of those particular users. Users do not have access to “real” devices the distributed system can use, only “virtual” devices presented by the distributed system, where those virtual devices have properties similar, but not necessarily equal, to real devices.

