Virtual Machine Migration for Confidential Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web-based application services face risks of data leakage when transmitting user data containing confidential information over networks, especially due to insufficient encryption and the need to download applications even for non-confidential data processing, leading to resource wastage and environmental preparation issues.

Innovation Solution

A web service system utilizing a virtual machine on a remote site with a local site virtualization platform, where a network processor assesses user data for confidentiality and migrates the virtual machine to the local site for processing sensitive data, thereby preventing data leakage and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user data containing confidential information is transmitted to a remote AP server for processing, then web-based application services can be utilized without local installation, but confidential data may be leaked over the network

Engineering Contradiction:
Improveweb-based application accessVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of transmitting data to the server for processing, the patent inverts the approach by migrating the virtual machine (containing the application) to the local client machine. This allows the application to process data locally without exposing confidential information to the network, while still providing web-based application services.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a virtual machine as an intermediary between the user data and the network. The virtual machine runs locally on the client machine, acting as a mediator that enables web-based application access without requiring data transmission over the network, thus preventing data leakage while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If applications are downloaded and executed locally to avoid data transmission, then data security is improved, but computer resources are wasted and environment preparation is required

Engineering Contradiction:
Improvedata leakage preventionVSAvoidenvironment preparation
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent makes the virtual machine universally adaptable by designing it to be migratable between remote and local environments. The virtual machine can function remotely when data transmission is acceptable and can be migrated locally when data security is paramount, providing multi-functional capability that avoids environment preparation issues while maintaining data security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces dynamic migration capability where the virtual machine can move between remote and local locations based on data sensitivity requirements. This dynamic approach eliminates the need for static environment preparation, as the virtual machine adapts its location based on the confidentiality level of the data being processed.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If virtual machines are migrated to local site for confidential data processing, then data security is enhanced, but network and system complexity increases

Engineering Contradiction:
Improveconfidential data protectionVSAvoidvirtualization platform complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent uses copying technology to replicate the virtual machine from the remote site to the local site for migration. This copying mechanism simplifies the complexity of virtual machine migration by using established virtualization copying techniques, making the system manageable despite the added complexity of remote-local migration capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8990350B2Web service system, web service method, and program
Publication Date: 2015.03.24 NEC CORP
  • US8990350B2 patent drawing
  • US8990350B2 patent drawing
  • US8990350B2 patent drawing

AI summary

To eliminate necessity of transmitting user data containing confidential information to an external network and necessity of preparing a proper environment for a user to execute an application. A web service system includes a virtualization platform on a local site side and a virtualization platform on a remote site side. The virtualization platform on the local site side includes: a network processor which separately establishes communication lines connected, respectively, to the client machine and to a network processor of the virtualization platform on the remote site side; a confidential data control section which judges whether the user data contains confidential information, and determines the destination; and a virtual machine service section which, upon receiving the judgment result indicating that the user data contains the confidential information, executes migration of the virtual machine of the virtualization platform on the remote site side to the virtualization platform on the local site side.