Virtual Machine Migration via Isolated Network Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual machine migration across different network infrastructures is limited by the need for rebuilding interactions, resulting in poor portability and security concerns in distributed computer systems.
Innovation Solution
A control process for a distributed computer system that involves creating a secondary network environment with isolated access rights, allowing network elements to be transferred and activated with lower access rights, ensuring the user maintains control without granting full access to the cloud operator.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machine migration across different network infrastructures is enabled, then virtual machine portability is improved, but security is worsened due to the need to grant cloud operator access rights
Solution Approach 1:
The patent segments access rights into two distinct levels: maximum access rights retained by the user for the virtual machine, and lower access rights granted to the cloud operator only for the second network environment. This segmentation allows the cloud operator to perform migration tasks without accessing the user's primary network environment, thus maintaining security while enabling portability.
Solution Approach 2:
The patent applies local quality by creating a second network environment with specific localized access rights that are different from the user's primary network environment. The cloud operator is granted access only to this specific second environment with lower access rights, while the user maintains full control over the first network environment. This localized approach enables migration functionality without compromising overall system security.
2Ease of manufacture
If cloud operator is granted maximum access rights to configure network infrastructure, then network configuration capability is improved, but user control is worsened
Solution Approach 1:
The patent segments the network infrastructure into two distinct environments: a first network environment controlled by the user with maximum access rights, and a second network environment controlled by the cloud operator with lower access rights. This segmentation allows the cloud operator to configure the second environment independently without affecting or requiring access to the user's primary environment, thus maintaining both configuration capability and user control.
Solution Approach 2:
The second network environment acts as an intermediary between the cloud operator's configuration capabilities and the user's primary network environment. The cloud operator configures network elements in this intermediate environment, which then connects to the user's first network environment, allowing configuration capability to be provided without direct access to or control over the user's primary system.
3Adaptability or versatility
If virtual machine migration requires rebuilding all interactions with infrastructure, then migration compatibility is improved, but migration complexity is worsened
Solution Approach 1:
The patent applies preliminary action by having the cloud operator pre-configure the second network environment and its network elements before the virtual machine migration occurs. This preliminary configuration includes setting up network interfaces, routing, and other network interactions in advance, so that when the virtual machine is migrated, the interactions are already in place and do not require rebuilding, thus reducing migration complexity while maintaining compatibility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for controlling a distributed computer system, the distributed computer system comprising at least one virtual machine and a set of network elements, the set of network elements forming a first environment of the virtual machine, the control method being implemented by the virtual machine and comprising, upon starting up the virtual machine, the steps of: - instantiating a second environment formed by a set of virtual network elements, the second environment being different from the first environment, - transferring at least one network element from the first environment to the second environment, - activating the at least one transferred network element, - instantiating at least one link between the first environment and each network element of the second environment, and - starting the at least one instantiated link.