Virtual Machine Storage Architecture Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual machine technologies face complexity and overhead when accessing and managing state data through intermediary file systems, which can lead to data corruption and security risks due to undesired exposure of sensitive information.
Innovation Solution
The method involves provisioning distinct units of network storage for each virtual machine, allowing for secure management and operation without an intermediary file system, by isolating and encrypting virtual machine state data while exposing only appropriate subsets to guest computations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If an intermediary file system is used to access virtual machine state data, then data access and management are facilitated, but system complexity and overhead increase, and security risks arise from undesired exposure of sensitive information
Solution Approach 1:
The patent extracts and removes the intermediary file system layer from the virtual machine storage architecture. By directly accessing storage units without a file system intermediary, the system eliminates the complexity and overhead associated with file system operations while maintaining data access capabilities through block-level I/O operations.
Solution Approach 2:
The patent introduces a virtual machine monitor (VMM) as a new intermediary that provides simplified access to storage units. The VMM directly manages block-level I/O operations between the virtual machine and storage, replacing the traditional file system mediator with a more efficient mechanism that reduces overhead while maintaining ease of operation.
2Ease of operation
If an intermediary file system is used to access virtual machine state data, then data access is enabled, but security risks increase due to undesired exposure of sensitive information
Solution Approach 1:
The patent segments the storage architecture into distinct storage units, each dedicated to a specific virtual machine. This segmentation isolates sensitive state data from other virtual machines, preventing undesired exposure. Each storage unit contains only the necessary data for its associated virtual machine, eliminating the security risks associated with shared file system access.
Solution Approach 2:
The patent removes the file system intermediary that causes security vulnerabilities. By eliminating the file system layer that exposes sensitive information through directories and file names, the system directly accesses storage units through controlled block-level I/O operations managed by the VMM, thereby reducing security risks while maintaining data access functionality.
3Quantity of substance
If state data for multiple virtual machines are stored in the same storage unit, then storage efficiency is improved, but reliability decreases due to potential data corruption and commingling
Solution Approach 1:
The patent divides storage resources into separate storage units for each virtual machine. This segmentation ensures that state data for different virtual machines are completely isolated, preventing data corruption and commingling. Each storage unit is dedicated to a single virtual machine, maintaining reliability while the overall storage system achieves efficiency through centralized management and potential pooling of unused capacity.
4Reliability
If distinct storage units are provisioned for each virtual machine, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent creates a universal storage management mechanism through the virtual machine monitor that handles multiple storage units with a single interface. The VMM provides multi-functional capabilities including allocation, access control, and data management across all storage units, thereby reducing the apparent complexity for individual virtual machines while maintaining the security and reliability benefits of distinct storage units.
Data Source
AI summary
Some embodiments of the present invention include a method comprising: accessing units of network storage that encode state data of respective virtual machines, wherein the state data for respective ones of the virtual machines are stored in distinct ones of the network storage units such that the state data for more than one virtual machine are not commingled in any one of the network storage units.


