VM-Specific Stable System Values for Cloning Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing environments, existing data protection methods using stable system values (SSVs) face challenges in uniquely identifying virtual machines (VMs) and distinguishing between legitimate migration and unauthorized cloning, as VMs share physical-level SSVs and lack unique hardware identifiers.

Innovation Solution

A method is introduced where a virtual machine creates and stores a 'stored system fingerprint' using VM-specific SSVs that change upon cloning but not upon migration, allowing for controlled access by comparing current and stored fingerprints to ensure authorized access, employing VM identifiers and other VM-specific values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical-level stable system values are used for data protection in virtualized environments, then data protection capability is provided, but the values are not unique to a given VM and cannot distinguish between migration and cloning

Engineering Contradiction:
Improvedata protection capabilityVSAvoidVM identification uniqueness
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the stable system values into two categories: physical-level SSVs (CPU, disk, BIOS) and virtual-level SSVs (VM identifier, VM BIOS identifier). This segmentation allows the system to maintain data protection while achieving unique VM identification through the virtual-level values that change upon cloning but remain stable during migration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces VM-specific SSVs as intermediary values that mediate between the physical hardware level and the virtual machine level. These intermediary values (VM identifier, VM BIOS identifier) provide the necessary uniqueness for VM identification without being affected by physical hardware changes or migrations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If VM-specific stable system values are introduced to enable unique identification, then VM identification precision is improved, but device complexity increases

Engineering Contradiction:
ImproveVM identification uniquenessVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent makes the stable system value collection universal by incorporating both physical-level and virtual-level values into a single fingerprinting mechanism. This multi-functional approach allows the same fingerprinting system to handle both physical hardware identification and virtual machine unique identification, avoiding the need for separate complex systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8826033B1Data protection using virtual-machine-specific stable system values
Publication Date: 2014.09.02 EMC IP HLDG CO LLC
  • US8826033B1 patent drawing
  • US8826033B1 patent drawing
  • US8826033B1 patent drawing

AI summary

A virtual machine on a physical host computer provides controlled access to protected data by creating and storing a “stored system fingerprint” from stable system values (SSVs) as existing when creating the stored system fingerprint. The SSVs include virtual-machine-specific values that change upon cloning the virtual machine (VM) but do not change upon migration of the VM. Upon a request for access to the protected data, a current system fingerprint is calculated from the SSVs as existing when processing the request, the current system fingerprint is compared to the stored system fingerprint to determine whether there is a predetermined degree of matching, and the requested access to the protected data is permitted only if there is the predetermined degree of matching.