Virtual Machine State Data Storage Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern storage arrays struggle to effectively manage and manipulate virtual machine state data, which includes sensitive information, due to limitations in isolating and securing non-disk data, making it vulnerable to leaks or malicious access.

Innovation Solution

The method involves encoding virtual machine state data in network storage units, using block-level I/O access and encapsulation techniques to isolate non-disk data, while leveraging storage array functionalities for operations like snapshotting, replication, and migration, thereby securing and managing virtual machine state data efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machine state data is stored in network storage units, then data management and manipulation capabilities are improved, but data security and isolation are worsened due to vulnerability to leaks and malicious access

Engineering Contradiction:
Improvedata management capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments virtual machine state data into separate network storage units, isolating sensitive information from general storage operations. This segmentation allows storage array functionality to be applied to non-sensitive data while maintaining security boundaries around sensitive state data, resolving the contradiction between improved data management and maintained security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between the storage system and virtual machine state data, using encapsulation techniques and controlled access interfaces. This intermediary enables storage array operations to be performed on encoded representations of state data without exposing the actual sensitive information, thus improving management capability while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If storage array functionality is used to manipulate virtual machine state data, then operational efficiency is improved, but data isolation and security control are worsened

Engineering Contradiction:
Improveoperational efficiencyVSAvoidisolation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates encoded copies of virtual machine state data that can be manipulated by storage array functionality without exposing the original sensitive data. These encoded representations enable efficient operations like snapshotting and replication while maintaining security boundaries, thus improving operational efficiency without increasing isolation complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent applies parameter changes by encoding virtual machine state data in transformed representations that are compatible with storage array operations. This encoding allows storage functionality to operate on the data with improved efficiency while the encoding parameters maintain security and isolation, avoiding increased complexity in the isolation mechanism.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If network storage units are used for virtual machine state data, then centralized management is improved, but access control and security are worsened

Engineering Contradiction:
Improvecentralized managementVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-encoding and pre-securing virtual machine state data before it is stored in network storage units. This preliminary security measure enables centralized management of the storage resources while the pre-applied encoding and access controls prevent unauthorized access, thus improving ease of operation without increasing vulnerability to harmful factors.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9098347B2Implementation of virtual machine operations using storage system functionality
Publication Date: 2015.08.04 VMWARE INC
  • US9098347B2 patent drawing
  • US9098347B2 patent drawing
  • US9098347B2 patent drawing

AI summary

One embodiment of the present invention includes a method comprising: (a) representing at least state data of a virtual machine in a unit of network storage of a network storage system; and (b) employing data manipulation functionality of the network storage system to implement a virtual machine operation that manipulates at least the state data of the virtual machine.