Virtual Machine Image Segmentation for Cloud Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machine data in cloud environments is vulnerable to unauthorized access and migration/re-provisioning is cumbersome and time-consuming in existing systems.

Innovation Solution

Partitioning a virtual machine image file into segments, generating unique keys for each segment, and distributing them across multiple nodes with an image mapping file for secure storage and rapid retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machine data is stored in a cloud environment, then data accessibility and scalability are improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the virtual machine image into multiple segments and distributes them across different nodes in the cloud environment. This segmentation ensures that no single node contains the complete virtual machine data, reducing the risk of unauthorized access while maintaining data accessibility through distributed storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an image mapping file as an intermediary component that contains unique keys for each segment. This mapping file acts as a mediator between the storage system and the retrieval process, enabling secure access control without compromising data accessibility. The mapping file is transmitted to authorized nodes to facilitate legitimate access while preventing unauthorized reconstruction of the virtual machine image.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If virtual machine data is migrated between cloud environments, then flexibility and adaptability are improved, but migration time and complexity increase

Engineering Contradiction:
Improvecloud environment flexibilityVSAvoidmigration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

By dividing the virtual machine image into segments with unique keys stored in a mapping file, the patent enables selective and parallel transmission of segments during migration. This segmentation reduces migration time by allowing concurrent data transfer across multiple nodes and environments, while maintaining the ability to reconstruct the complete virtual machine image at the destination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent prepares the virtual machine image for migration by pre-generating segments and their corresponding unique keys before actual migration occurs. This preliminary segmentation and key generation process enables rapid migration execution, as the data is already organized for efficient transmission and can be quickly transferred to different cloud environments without extensive processing during the migration event.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If virtual machine data is stored in a single location, then storage simplicity is improved, but redundancy and security are reduced

Engineering Contradiction:
Improvestorage system simplicityVSAvoiddata redundancy
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the virtual machine image and distributes segments across multiple nodes, creating redundancy without significantly increasing system complexity. Each node stores only a portion of the data, and the image mapping file with unique keys provides a simple mechanism for tracking and retrieving segments. This approach achieves both redundancy for reliability and relative simplicity through the use of a centralized mapping structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8838968B2System and method for virtual machine data protection in a public cloud
Publication Date: 2014.09.16 CA TECH INC
  • US8838968B2 patent drawing
  • US8838968B2 patent drawing
  • US8838968B2 patent drawing

AI summary

A method includes partitioning a disk image file into a plurality of segments. The method also includes generating a unique key for each segment, storing the unique keys in an image mapping file, and transmitting the image mapping file to a particular one of a plurality of nodes on a network. The method further includes transmitting a first segment and a second segment of the plurality of segments to different nodes of the plurality of nodes.