Virtual Machine Migration for Confidential Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web-based application services face risks of data leakage when transmitting user data containing confidential information over networks, especially due to insufficient encryption and the need to download applications even for non-confidential data processing, leading to resource wastage and environmental preparation issues.
Innovation Solution
A web service system utilizing a virtual machine on a remote site with a local site virtualization platform, where a network processor assesses user data for confidentiality and migrates the virtual machine to the local site for processing sensitive data, thereby preventing data leakage and optimizing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user data containing confidential information is transmitted to a remote AP server for processing, then web-based application services can be utilized without local installation, but confidential data may be leaked over the network
Solution Approach 1:
Instead of transmitting data to the server for processing, the patent inverts the approach by migrating the virtual machine (containing the application) to the local client machine. This allows the application to process data locally without exposing confidential information to the network, while still providing web-based application services.
Solution Approach 2:
The patent introduces a virtual machine as an intermediary between the user data and the network. The virtual machine runs locally on the client machine, acting as a mediator that enables web-based application access without requiring data transmission over the network, thus preventing data leakage while maintaining ease of operation.
2Object-affected harmful factors
If applications are downloaded and executed locally to avoid data transmission, then data security is improved, but computer resources are wasted and environment preparation is required
Solution Approach 1:
The patent makes the virtual machine universally adaptable by designing it to be migratable between remote and local environments. The virtual machine can function remotely when data transmission is acceptable and can be migrated locally when data security is paramount, providing multi-functional capability that avoids environment preparation issues while maintaining data security.
Solution Approach 2:
The patent introduces dynamic migration capability where the virtual machine can move between remote and local locations based on data sensitivity requirements. This dynamic approach eliminates the need for static environment preparation, as the virtual machine adapts its location based on the confidentiality level of the data being processed.
3Object-affected harmful factors
If virtual machines are migrated to local site for confidential data processing, then data security is enhanced, but network and system complexity increases
Solution Approach 1:
The patent uses copying technology to replicate the virtual machine from the remote site to the local site for migration. This copying mechanism simplifies the complexity of virtual machine migration by using established virtualization copying techniques, making the system manageable despite the added complexity of remote-local migration capability.
Data Source
AI summary
To eliminate necessity of transmitting user data containing confidential information to an external network and necessity of preparing a proper environment for a user to execute an application. A web service system includes a virtualization platform on a local site side and a virtualization platform on a remote site side. The virtualization platform on the local site side includes: a network processor which separately establishes communication lines connected, respectively, to the client machine and to a network processor of the virtualization platform on the remote site side; a confidential data control section which judges whether the user data contains confidential information, and determines the destination; and a virtual machine service section which, upon receiving the judgment result indicating that the user data contains the confidential information, executes migration of the virtual machine of the virtualization platform on the remote site side to the virtualization platform on the local site side.


