Virtual Machine State Data Storage Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern storage arrays struggle to effectively manage and manipulate virtual machine state data, which includes sensitive information, due to limitations in isolating and securing non-disk data, making it vulnerable to leaks or malicious access.
Innovation Solution
The method involves encoding virtual machine state data in network storage units, using block-level I/O access and encapsulation techniques to isolate non-disk data, while leveraging storage array functionalities for operations like snapshotting, replication, and migration, thereby securing and managing virtual machine state data efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual machine state data is stored in network storage units, then data management and manipulation capabilities are improved, but data security and isolation are worsened due to vulnerability to leaks and malicious access
Solution Approach 1:
The patent segments virtual machine state data into separate network storage units, isolating sensitive information from general storage operations. This segmentation allows storage array functionality to be applied to non-sensitive data while maintaining security boundaries around sensitive state data, resolving the contradiction between improved data management and maintained security.
Solution Approach 2:
The patent introduces an intermediary layer between the storage system and virtual machine state data, using encapsulation techniques and controlled access interfaces. This intermediary enables storage array operations to be performed on encoded representations of state data without exposing the actual sensitive information, thus improving management capability while preserving security.
2Productivity
If storage array functionality is used to manipulate virtual machine state data, then operational efficiency is improved, but data isolation and security control are worsened
Solution Approach 1:
The patent creates encoded copies of virtual machine state data that can be manipulated by storage array functionality without exposing the original sensitive data. These encoded representations enable efficient operations like snapshotting and replication while maintaining security boundaries, thus improving operational efficiency without increasing isolation complexity.
Solution Approach 2:
The patent applies parameter changes by encoding virtual machine state data in transformed representations that are compatible with storage array operations. This encoding allows storage functionality to operate on the data with improved efficiency while the encoding parameters maintain security and isolation, avoiding increased complexity in the isolation mechanism.
3Ease of operation
If network storage units are used for virtual machine state data, then centralized management is improved, but access control and security are worsened
Solution Approach 1:
The patent applies preliminary action by pre-encoding and pre-securing virtual machine state data before it is stored in network storage units. This preliminary security measure enables centralized management of the storage resources while the pre-applied encoding and access controls prevent unauthorized access, thus improving ease of operation without increasing vulnerability to harmful factors.
Data Source
AI summary
One embodiment of the present invention includes a method comprising: (a) representing at least state data of a virtual machine in a unit of network storage of a network storage system; and (b) employing data manipulation functionality of the network storage system to implement a virtual machine operation that manipulates at least the state data of the virtual machine.


