VM-Specific Stable System Values for Cloning Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized computing environments, existing data protection methods using stable system values (SSVs) face challenges in uniquely identifying virtual machines (VMs) and distinguishing between legitimate migration and unauthorized cloning, as VMs share physical-level SSVs and lack unique hardware identifiers.
Innovation Solution
A method is introduced where a virtual machine creates and stores a 'stored system fingerprint' using VM-specific SSVs that change upon cloning but not upon migration, allowing for controlled access by comparing current and stored fingerprints to ensure authorized access, employing VM identifiers and other VM-specific values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical-level stable system values are used for data protection in virtualized environments, then data protection capability is provided, but the values are not unique to a given VM and cannot distinguish between migration and cloning
Solution Approach 1:
The patent segments the stable system values into two categories: physical-level SSVs (CPU, disk, BIOS) and virtual-level SSVs (VM identifier, VM BIOS identifier). This segmentation allows the system to maintain data protection while achieving unique VM identification through the virtual-level values that change upon cloning but remain stable during migration.
Solution Approach 2:
The patent introduces VM-specific SSVs as intermediary values that mediate between the physical hardware level and the virtual machine level. These intermediary values (VM identifier, VM BIOS identifier) provide the necessary uniqueness for VM identification without being affected by physical hardware changes or migrations.
2Measurement precision
If VM-specific stable system values are introduced to enable unique identification, then VM identification precision is improved, but device complexity increases
Solution Approach 1:
The patent makes the stable system value collection universal by incorporating both physical-level and virtual-level values into a single fingerprinting mechanism. This multi-functional approach allows the same fingerprinting system to handle both physical hardware identification and virtual machine unique identification, avoiding the need for separate complex systems.
Data Source
AI summary
A virtual machine on a physical host computer provides controlled access to protected data by creating and storing a “stored system fingerprint” from stable system values (SSVs) as existing when creating the stored system fingerprint. The SSVs include virtual-machine-specific values that change upon cloning the virtual machine (VM) but do not change upon migration of the VM. Upon a request for access to the protected data, a current system fingerprint is calculated from the SSVs as existing when processing the request, the current system fingerprint is compared to the stored system fingerprint to determine whether there is a predetermined degree of matching, and the requested access to the protected data is permitted only if there is the predetermined degree of matching.


