Virtual Machine Migration via Data Flow Buffering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Live migration of virtual machines outside a secure computing environment introduces security vulnerabilities due to compromised data communications between applications, and existing methods do not effectively manage the synchronization of dependent virtual machines during migration.
Innovation Solution
A method that involves acquiring a list of active and connected virtual machines, rerouting their connections to a buffer to capture data flow, migrating the source virtual machines to a target hypervisor, reconnecting them in the same manner, migrating buffered data, and activating the target virtual machines, while considering data flow dependencies to ensure secure and synchronized migration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machines are migrated outside a secure computing environment, then hardware platform flexibility and maintenance capabilities are improved, but security vulnerabilities increase due to compromised data communications between applications
Solution Approach 1:
The patent introduces a buffer as an intermediary component that captures and stores data communications between virtual machines during migration. This buffer acts as a mediator that decouples the data flow from the migration process, allowing VMs to be migrated to different hardware platforms while maintaining secure data communication channels. The buffer ensures that sensitive data communications are captured, protected, and properly routed even when VMs move outside the secure computing environment.
2Productivity
If virtual machines are migrated live to maintain continuous operation, then service availability is improved, but synchronization of dependent virtual machines becomes difficult
Solution Approach 1:
The patent implements preliminary actions by first capturing data communications in a buffer before the actual migration occurs. This preliminary capture of data flows allows the system to prepare the migration path and ensure all necessary data is accounted for before VMs are moved. The buffer is pre-configured to intercept and store communications, ensuring that when VMs are migrated live, their dependent communications are already captured and can be properly re-routed without synchronization issues.
Solution Approach 2:
The patent establishes feedback mechanisms by monitoring data communications between virtual machines and using this information to control the migration process. The buffer provides feedback about captured data flows, which is used to coordinate the migration of dependent VMs. This feedback loop ensures that VMs are migrated in the correct sequence and that data communications are properly re-established after migration, maintaining synchronization without requiring complex manual coordination.
3Reliability
If data communications between virtual machines are captured in a buffer during migration, then security is improved, but migration time increases due to additional data handling steps
Solution Approach 1:
The patent maintains continuity of useful action by implementing the buffer in a way that does not interrupt the normal data flow between virtual machines. The buffer captures data communications in real-time without requiring the VMs to pause or stop their operations. This continuous capturing approach allows security to be enhanced through data interception and protection while the VMs continue to function normally, minimizing the time impact of the additional security measures.
Data Source
AI summary
To migrate two or more virtual machines in a source hypervisor to a target hypervisor, a list of active and connected virtual machines in the source hypervisor is acquired. Connections between the source virtual machines are rerouted to a buffer so that data flowing between the source virtual machines is captured. The source virtual machines are migrated to a target hypervisor and are connected in the same manner as in the source hypervisor. The buffered data is migrated to the respective migrated virtual machines, and the target virtual machines are activated. The virtual machines can be migrated in order of data flow dependency such that the least dependent virtual machine is migrated first.


