Virtual Firewall Mobility in Cloud Host Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing systems face challenges in seamlessly migrating virtual machines and their associated stateful or stateless virtual services between hosts, particularly when the destination host lacks the necessary virtual services, leading to disruptions and inefficiencies in security and network management.

Innovation Solution

A method and system that determine the need for virtual machine migration and instantiate a corresponding virtual service at the destination host, synchronizing session data and shutting down the original virtual machine if necessary, ensuring continuous service availability and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a virtual machine is migrated to a new host, then resource utilization and flexibility are improved, but service continuity and security may be disrupted if the destination host lacks the necessary virtual services

Engineering Contradiction:
Improvevirtual machine mobilityVSAvoidservice continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary detection of virtual service availability at the destination host before completing the migration. If the required virtual services are not available, the migration is blocked or deferred, preventing service disruption. This advance checking mechanism ensures that virtual machines are only migrated to hosts that can provide the necessary security and network services.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces a cloud management entity as an intermediary between the virtual machine migration process and the host infrastructure. This entity coordinates the migration by detecting virtual service availability, managing the migration workflow, and ensuring that the destination host has the necessary services before allowing the virtual machine to move, thereby maintaining service continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If virtual services are virtualized to improve flexibility, then resource efficiency increases, but complexity of managing service migration and availability detection increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidservice management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The cloud management entity automatically detects whether required virtual services are available at the destination host without manual intervention. The system self-manages the complexity of service availability checking, migration coordination, and host capability assessment, thereby reducing the operational burden while maintaining high resource efficiency through virtualized service management.

Inventive Principle:
Principle #25Self-service

3Speed

If virtual machine migration is allowed without service availability checking, then migration speed increases, but service disruption and security breaches may occur

Engineering Contradiction:
Improvemigration speedVSAvoidsecurity breach risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs rapid automated detection of virtual service availability at the destination host before migration completion. This preliminary check ensures that security services and network configurations are present and functional, preventing security breaches while maintaining fast migration throughput through efficient automated verification processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2907291B1Virtual firewall mobility
Publication Date: 2021.11.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2907291B1 patent drawingFigure 1
  • EP2907291B1 patent drawingFigure 2
  • EP2907291B1 patent drawingFigure 3

AI summary

A cloud management device determines that a virtual machine should be migrated from a first host to a second host, the virtual machine being associated with a virtual service, such as a virtual firewall, in the first host. The cloud management device verifies if fonctionality corresponding to the virtual service is available in the second host if the required ninctionality is not available, a new virtual service is instaicted to be instantiated in the second host State synchronization can be performed between the virtual services in the first and second hosts. The cloud management device instructs the virtual machine to be instantiated in the second host.