Adaptive Session Forwarding for VM Migration Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machine live migration disrupts data connections due to the disconnection from security devices like firewalls, and existing methods rely on inefficient virtual machine management system APIs, which are not practical for continuous operation.

Innovation Solution

A mechanism that detects network events during virtual machine migration, allowing security session forwarding to be modified by network security devices without relying on virtual machine management systems, ensuring continuous data operation by routing packets to the new location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual machine live migration is detected by querying virtual machine management system APIs, then migration information can be obtained, but the system complexity increases and efficiency decreases due to constant connections required

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the detection function from the virtual machine management system by having network security devices independently detect migration through network traffic analysis. This removes the dependency on management system APIs and constant connections, reducing system complexity while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Network security devices perform self-service detection by monitoring network traffic patterns themselves rather than relying on external management system queries. This autonomous detection approach eliminates the need for constant connections to management systems while maintaining reliable migration detection.

Inventive Principle:
Principle #25Self-service

2Reliability

If security session forwarding is not updated during virtual machine migration, then security policies remain consistent, but data connections are interrupted and traffic stops

Engineering Contradiction:
Improveconnection continuityVSAvoidsession management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback by having network security devices monitor network traffic to detect migration events, then automatically update security session forwarding based on detected migration. This closed-loop approach maintains connection continuity by responding to migration events while keeping session management automated rather than manually complex.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary action by pre-establishing security session forwarding rules that can be quickly updated upon migration detection. This allows seamless transition during migration by having forwarding rules ready to be activated, maintaining connection continuity without complex real-time negotiation.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If virtual machine migration is detected through network events, then dependency on centralized management systems is reduced, but detection precision may be affected

Engineering Contradiction:
Improveindependence from management systemVSAvoiddetection precision
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent uses network traffic patterns as an intermediary to detect virtual machine migration. By analyzing traffic characteristics, source/destination addresses, and flow patterns, the system achieves independent detection while maintaining precision through multiple correlation checks of network event data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent monitors changes in network traffic parameters such as source IP addresses, destination IP addresses, port assignments, and traffic flow patterns to detect migration. By tracking multiple parameter changes simultaneously, the system achieves both independence from management systems and high detection precision through correlated parameter analysis.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10333827B2Adaptive session forwarding following virtual machine migration detection
Publication Date: 2019.06.25 GRYPHO5 LLC
  • US10333827B2 patent drawing
  • US10333827B2 patent drawing
  • US10333827B2 patent drawing

AI summary

A network system includes a first network access device having an input/output (IO) module of a firewall to capture a packet of a network session originated from a first node associated with the first network access device, a first security device having a firewall processing module to determine based on the captured packet whether the first node is a destination node that is receiving VM migration from a second node that is associated with a second network access device. The first security device is to update a first flow table within the first network access device. The network system further includes a second security device to receive a message from the first security device concerning the VM migration to update a second flow table of the second network access device, such that further network traffic of the network session is routed to the first node without interrupting the network session.