Virtual Machine Fault Tolerance via Branch Instruction Timing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional fault-tolerant systems using virtual machines face challenges in accurately synchronizing the execution states of primary and secondary virtual machines due to issues with interrupt timing and counter accuracy, leading to potential hardware failure detection difficulties and interference with debugging processes.
Innovation Solution
A fault-tolerant system that transmits timing information including the number of branch instructions and execution suspension position from the primary virtual machine to the secondary virtual machine, allowing for accurate synchronization of virtual interrupts and reducing the need for output data checking, while avoiding interference with debugging processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the secondary virtual machine generates a virtual interrupt at the same timing as the primary virtual machine using conventional synchronization methods, then the execution states can be synchronized, but the timing information transmission accuracy deteriorates due to issues with interrupt timing and counter accuracy
Solution Approach 1:
The patent introduces a timing information transmission mechanism as an intermediary between the primary and secondary virtual machines. The primary virtual machine transmits timing information (including branch instruction counts and execution suspension positions) to the secondary virtual machine, which then generates the virtual interrupt at the correct timing. This intermediary transmission mechanism resolves the synchronization accuracy issue by enabling precise timing coordination without direct interrupt generation conflicts.
2Reliability
If output data checking is performed to detect hardware failures, then reliability can be monitored, but processing load increases and hardware failure detection becomes difficult due to the checking process itself
Solution Approach 1:
The patent implements a feedback mechanism where the secondary virtual machine monitors its own execution state and compares it with the timing information received from the primary virtual machine. When a discrepancy is detected (indicating hardware failure), the secondary virtual machine generates a notification to alert the system. This feedback approach enables reliable hardware failure detection without requiring continuous output data checking, thereby reducing processing load while maintaining detection capability.
3Ease of operation
If break instructions are embedded in the guest OS for debugging purposes, then debugging functionality is enabled, but the synchronization process is interfered with
Solution Approach 1:
The patent applies local quality by treating break instructions and synchronization mechanisms as separate, non-interfering elements. The timing information transmission system operates independently of the guest OS's debugging mechanisms. The primary virtual machine transmits timing information based on actual execution state (branch instruction counts and suspension positions), which remains accurate even when break instructions are present in the guest OS. This local independence ensures synchronization stability while preserving debugging capability.
Data Source
AI summary
A fault tolerant system includes a primary virtual machine that is formed on a primary machine in which a primary hypervisor runs, and is configured to input virtual interrupt based on an external interrupt from the primary hypervisor to a primary guest OS, and a secondary virtual machine that is formed on a secondary machine in which a secondary hypervisor runs, and is configured to input the virtual interrupt to a secondary guest OS on the basis of timing information on the virtual interrupt transmitted from the primary virtual machine. The primary virtual machine is configured to transmit the timing information on the virtual interrupt including the number of branch instructions executed by the primary guest OS before inputting the virtual interrupt, and including an execution suspension position when inputting the virtual interrupt to the secondary virtual machine.


