VM Migration Security via BMC Out-of-Band Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in securely migrating virtual machines between host servers, as they lack effective mechanisms to ensure the secure transfer and booting of virtual machines on target servers, compromising security and reliability.
Innovation Solution
The solution involves a pair of servers with a source server hosting a source virtual machine and a target server, where the source Baseboard Management Controller (BMC) communicates security data, such as secure boot keys, over a distinct out-of-band connection to the target BMC, ensuring secure boot and authorization of the migrated virtual machine.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machines are migrated over the inband connection, then migration functionality is achieved, but security data may be compromised
Solution Approach 1:
The system separates the migration data path (inband connection for VM traffic) from the security data path (out-of-band connection for security data). This segmentation ensures that security data is transmitted through a dedicated, isolated channel that is not vulnerable to attacks or compromises affecting the general network infrastructure.
Solution Approach 2:
The out-of-band connection acts as an intermediary channel specifically for security data transmission. This separate communication path mediates the transfer of security data between source and target systems, ensuring that security information is not exposed to the same network vulnerabilities as the primary migration channel.
2Device complexity
If security data is transmitted through the same connection as VM migration, then system complexity is reduced, but security risks increase
Solution Approach 1:
The communication infrastructure is divided into distinct segments: the inband connection handles VM migration traffic while the out-of-band connection is exclusively dedicated to security data transmission. This segmentation eliminates cross-contamination risks between different types of data traffic.
Solution Approach 2:
The out-of-band connection serves as a dedicated intermediary channel for security data, isolating it from the main migration traffic. This intermediary path provides an additional layer of security by preventing attackers who compromise the migration channel from accessing security data.
Data Source
AI summary
A pair of servers may include a source server hosting a source virtual machine (VM) and a target server hosting a target VM. The source server may include a source central processing unit (CPU) and a source baseboard management controller (BMC), and the target server may include a target CPU and a target BMC. The source server and the target server are connected by an inband connection, and the source BMC and the target BMC are connected by a connection distinct from the inband connection. The source VM may be migrated to the target server over the inband connection, and in response to migrating the source VM, security data corresponding to the source VM is communicated from the source BMC to the target BMC over the connection between the BMCs.


