Virtual Machine Image Segmentation for Cloud Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual machine data in cloud environments is vulnerable to unauthorized access and migration/re-provisioning is cumbersome and time-consuming in existing systems.
Innovation Solution
Partitioning a virtual machine image file into segments, generating unique keys for each segment, and distributing them across multiple nodes with an image mapping file for secure storage and rapid retrieval.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machine data is stored in a cloud environment, then data accessibility and scalability are improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent divides the virtual machine image into multiple segments and distributes them across different nodes in the cloud environment. This segmentation ensures that no single node contains the complete virtual machine data, reducing the risk of unauthorized access while maintaining data accessibility through distributed storage.
Solution Approach 2:
The patent introduces an image mapping file as an intermediary component that contains unique keys for each segment. This mapping file acts as a mediator between the storage system and the retrieval process, enabling secure access control without compromising data accessibility. The mapping file is transmitted to authorized nodes to facilitate legitimate access while preventing unauthorized reconstruction of the virtual machine image.
2Adaptability or versatility
If virtual machine data is migrated between cloud environments, then flexibility and adaptability are improved, but migration time and complexity increase
Solution Approach 1:
By dividing the virtual machine image into segments with unique keys stored in a mapping file, the patent enables selective and parallel transmission of segments during migration. This segmentation reduces migration time by allowing concurrent data transfer across multiple nodes and environments, while maintaining the ability to reconstruct the complete virtual machine image at the destination.
Solution Approach 2:
The patent prepares the virtual machine image for migration by pre-generating segments and their corresponding unique keys before actual migration occurs. This preliminary segmentation and key generation process enables rapid migration execution, as the data is already organized for efficient transmission and can be quickly transferred to different cloud environments without extensive processing during the migration event.
3Device complexity
If virtual machine data is stored in a single location, then storage simplicity is improved, but redundancy and security are reduced
Solution Approach 1:
The patent segments the virtual machine image and distributes segments across multiple nodes, creating redundancy without significantly increasing system complexity. Each node stores only a portion of the data, and the image mapping file with unique keys provides a simple mechanism for tracking and retrieving segments. This approach achieves both redundancy for reliability and relative simplicity through the use of a centralized mapping structure.
Data Source
AI summary
A method includes partitioning a disk image file into a plurality of segments. The method also includes generating a unique key for each segment, storing the unique keys in an image mapping file, and transmitting the image mapping file to a particular one of a plurality of nodes on a network. The method further includes transmitting a first segment and a second segment of the plurality of segments to different nodes of the plurality of nodes.


