IP Library Patent Application 14372727
Patent Application
App. No. 14/372,727

MIGRATION OF A SECURITY POLICY OF A VIRTUAL MACHINE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/372,727
Abstract

According to an example, an apparatus for Virtual Machine (VM) security policy migration includes a migration detecting module, a locating module and a security policy managing module. The migration detecting module is to receive a VM migration report from a VM management apparatus, wherein the VM migration report includes a location parameter of a VM. The locating module is to determine, according to the location parameter of the VM and a locating function, an old security device and a new security device that the VM belongs to before and after the migration. If the old security device and the new security device are not the same security device, a notification is transmitted to the security policy managing module, and a security policy of the VM on the old security device is issued to the new security device.

Claims (22)

1 . A Virtual Machine (VM) security policy migration apparatus comprising: a migration detecting module, a locating module and a security policy managing module; wherein

the migration detecting module is to receive a VM migration report from a VM management apparatus, wherein the VM migration report comprises a location parameter of a VM, and the VM management apparatus is to create and manage the VM;

the locating module is to determine, according to the location parameter of the VM and a locating function, an old security device and a new security device that the VM belongs to before and after the migration, determine whether the old security device and the new security device are the same security device; if the old security device and the new security device are not the same security device, transmit a notification to the security policy managing module; and

the security policy managing module is to obtain, after receiving the notification of the locating module, a security policy of the VM on the old security device and issue the security policy to the new security device.

2 . The apparatus of claim 1 , wherein the security policy managing module is further to remove the security policy on the old security device if the old security device and the new security device are not the same security device.

3 . The apparatus of claim 1 , wherein the location parameter of the VM comprises any one or any combination of: an Internet Protocol (IP) address of the VM, a Media Access Control (MAC) address of the VM, an IP address of a physical server where the VM is located before the migration, an IP address of a physical server where the VM is located after the migration, an access port ID of the VM before the migration, an access port ID of the VM after the migration, and an VLAN ID of the VM.

4 . The apparatus of claim 1 , wherein the locating module comprises a plurality of locating sub-modules, the plurality of locating sub-modules respectively use different locating functions, wherein the different locating functions determine the old security device and the new security device that the VM belongs to according to different location parameters or different combinations of the location parameters.

5 . A method of Virtual Machine (VM) security policy migration comprising:

receiving a VM migration report from a VM management apparatus, wherein the VM migration report comprises a location parameter of a VM, and the VM management apparatus is to create and manage the VM;

determining, according to the location parameter and a locating function, an old security device and a new security device that the VM belongs to before and after the migration; and

determining whether the old security device and the new security device are the same security device; and

if the old security device and the new security device are not the same security device, obtaining a security policy of the VM on the old security device and issuing the security policy to the new security device.

6 . The method of claim 5 , further comprising:

if the old security device and the new security device are not the same security device, removing the security policy on the old security device.

7 . The method of claim 5 , wherein the location parameter comprises any one or any combination of: an Internet Protocol (IP) address of the VM, a Media Access Control (MAC) address of the VM, an IP address of a physical server where the VM is located before the migration, an IP address of a physical server where the VM is located after the migration, an access port ID of the VM before the migration, an access port ID of the VM after the migration, and an VLAN ID of the VM.

8 . The method of claim 5 , further comprising:

before determining the old security device and the new security device according to the location parameter and the locating function, selecting one locating function among multiple locating functions, wherein different locating functions determine the old security device and the new security device that the VM belongs to according to different location parameters or different combinations of location parameters.

9 . A Virtual Machine security policy migration apparatus, comprising: a processor and a memory, wherein the processor is communicatively connected with the memory, the memory stores machine readable instructions executable by the processor to:

receive a VM migration report from a VM management apparatus, wherein the VM migration report comprises a location parameter of a VM, and the VM management apparatus is to create and manage the VM;

determine, according to the location parameter and a locating function, an old security device and a new security device that the VM belongs to before and after the migration;

determine whether the old security device and the new security device are the same security device; and

if the old security device and the new security device are not the same security device, obtain a security policy of the VM on the old security device and issuing the security policy to the new security device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2016
From: H3C TECHNOLOGIES CO., LTD.; HANGZHOU H3C TECHNOLOGIES CO., LTD.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 039767/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2014
From: SUN, SONGER; LV, ZHENFENG
To: HANGZHOU H3C TECHNOLOGIES CO., LTD.
Reel/Frame 033541/0724 →