IP Library Granted Patent US 11,645,103
Granted Patent B2
US 11,645,103 · App. 16/936,465 · Granted May 9, 2023

Method and system for securing the movement of virtual machines between hosts

Inventors: Suren Kumar (Tamil Nadu, IN); Vinod Durairaj (Bangalore, IN); Veena Rao (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
G06F9/45558H04L9/0825H04L63/0428G06F2009/4557G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,645,103
App. No.
16/936,465
Granted
May 9, 2023
Kind
B2
Abstract

A method for securing the movement of virtual machines (VMs) between hosts. The method includes obtaining a first VM movement request; in response to obtaining the first VM movement request, identifying a first VM of the VMs and a first targeted host of the hosts associated with the first VM movement request using VM metadata and host metadata; making a first determination that the first targeted host is registered; in response to making the first determination, initiating the movement of the first VM to the first targeted host; and initiating, after the movement of the first VM, encryption of communication between the first VM and the first targeted host.

Claims (109)

1. A method for securing movement of virtual machines (VMs) between hosts, the method comprising:

obtaining a first VM movement request;

in response to obtaining the first VM movement request:

identifying a first VM of the VMs and a first targeted host of the hosts associated with the first VM movement request using VM metadata and host metadata,

wherein the VM metadata comprises:

VM identifiers associated with VMs comprising the first VM,

host identifiers associated with hosts currently hosting the VMs,

a list of unsecured VMs of the VMs, and

a hierarchical listing of the VMs specifying nested VMs;

making a first determination that the first targeted host is registered;

in response to making the first determination:

initiating the movement of the first VM to the first targeted host; and

initiating, after the movement of the first VM, encryption of communication between the first VM and the first targeted host.

2. The method of claim 1 , further comprising:

obtaining a second VM movement request;

in response to obtaining the second VM movement request:

identifying a second VM of the VMs and a second targeted host of the hosts associated with the second VM movement request;

making a second determination that the second targeted host is not registered; and

in response to making the second determination:

blocking the movement of the second VM to the second targeted host.

3. The method of claim 1 , wherein the first targeted host is registered prior to obtaining the first VM movement request.

4. The method of claim 1 , further comprising:

obtaining a host registration request associated with the first targeted host;

in response to obtaining the host registration request:

making, using host metadata, a second determination that the first host is trustworthy; and

in response to the second determination:

generating a certificate associated with the first targeted host using the host metadata; and

sending the certificate to the first targeted host,

wherein the first determination is made, in part, using the certificate.

5. The method of claim 4 , wherein the certificate comprises:

a public key, and

the host metadata.

6. The method of claim 1 , wherein initiating the encryption of the communication between the first VM and the first targeted host comprises:

sending an encryption request associated to the first targeted host;

in response to the sending, obtaining a security confirmation from the first targeted host, wherein the security confirmation indicates that an encrypted communication channel has been established between the first VM and the first targeted host, wherein the first VM is executing on the first targeted host.

7. The method of claim 1 , wherein identifying the first VM and the first targeted host comprises using the VM metadata and the host metadata.

8. A system, comprising:

a processor;

a data manager, which when executed by the processor performs a method, the method comprising:

obtaining a first VM movement request;

in response to obtaining the first VM movement request:

identifying a first VM of VMs and a first targeted host of hosts associated with the first VM movement request using VM metadata and host metadata, wherein

the VM metadata comprises:

VM identifiers associated with VMs comprising the first VM,

host identifiers associated with hosts currently hosting the VMs,

a list of unsecured VMs of the VMs, and

a hierarchical listing of the VMs specifying nested VMs;

making a first determination that the first targeted host is registered;

in response to making the first determination:

initiating the movement of the first VM to the first targeted host; and

initiating, after the movement of the first VM, encryption of communication between the first VM and the first targeted host.

9. The system of claim 8 , wherein the method further comprising:

obtaining a second VM movement request;

in response to obtaining the second VM movement request:

identifying a second VM of the VMs and a second targeted host of the hosts associated with the second VM movement request;

making a second determination that the second targeted host is not registered; and

in response to making the second determination:

blocking the movement of the second VM to the second targeted host.

10. The system of claim 8 , wherein the first targeted host is registered prior to obtaining the first VM movement request.

11. The system of claim 8 , wherein the method further comprising:

obtaining a host registration request associated with the first targeted host;

in response to obtaining the host registration request:

making, using host metadata, a second determination that the first host 1 s trustworthy; and

in response to the second determination:

generating a certificate associated with the first targeted host using the host metadata; and

sending the certificate to the first targeted host,

wherein the first determination is made, in part, using the certificate.

12. The system of claim 11 , wherein the certificate comprises:

a public key, and

the host metadata.

13. The system of claim 8 , wherein initiating the encryption of the communication between the first VM and the first targeted host comprises:

sending an encryption request associated to the first targeted host;

in response to the sending, obtaining a security confirmation from the first targeted host, wherein the security confirmation indicates that an encrypted communication channel has been established between the first VM and the first targeted host, wherein the first VM is executing on the first targeted host.

14. The system of claim 8 , wherein identifying the first VM and the first targeted host comprises using the VM metadata and the host metadata.

15. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method, the method comprising:

obtaining a first VM movement request;

in response to obtaining the first VM movement request:

identifying a first VM of VMs and a first targeted host of hosts associated with the first VM movement request using VM metadata and host metadata, wherein

the VM metadata comprises:

VM identifiers associated with VMs comprising the first VM,

host identifiers associated with hosts currently hosting the VMs,

a list of unsecured VMs of the VMs, and

a hierarchical listing of the VMs specifying nested VMs;

making a first determination that the first targeted host is registered;

in response to making the first determination:

initiating the movement of the first VM to the first targeted host; and

initiating, after the movement of the first VM, encryption of communication between the first VM and the first targeted host.

16. The non-transitory computer readable medium of claim 15 , wherein the method further comprising:

obtaining a second VM movement request;

in response to obtaining the second VM movement request:

identifying a second VM of the VMs and a second targeted host of the hosts associated with the second VM movement request;

making a second determination that the second targeted host is not registered; and

in response to making the second determination:

blocking the movement of the second VM to the second targeted host.

17. The non-transitory computer readable medium of claim 15 , wherein the first targeted host is registered prior to obtaining the first VM movement request.

18. The non-transitory computer readable medium of claim 15 , wherein the method further comprising:

obtaining a host registration request associated with the first targeted host;

in response to obtaining the host registration request:

making, using host metadata, a second determination that the first host is trustworthy; and

in response to the second determination:

generating a certificate associated with the first targeted host using the host metadata; and

sending the certificate to the first targeted host,

wherein the first determination is made, in part, using the certificate.

19. The non-transitory computer readable medium of claim 18 , wherein the certificate comprises:

a public key, and

the host metadata.

20. The non-transitory computer readable medium of claim 15 , wherein initiating the encryption of the communication between the first VM and the first targeted host comprises:

sending an encryption request associated to the first targeted host;

in response to the sending, obtaining a security confirmation from the first targeted host, wherein the security confirmation indicates that an encrypted communication channel has been established between the first VM and the first targeted host, wherein the first VM is executing on the first targeted host.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053574/0221) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053578/0183) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060332/0864 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053573/0535) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060333/0106 →
RELEASE OF SECURITY INTEREST AT REEL 053531 FRAME 0108 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0371 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053578/0183 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053573/0535 →
SECURITY INTEREST Recorded Aug 21, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 053574/0221 →
SECURITY AGREEMENT Recorded Aug 18, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 053531/0108 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2020
From: KUMAR, SUREN; DURAIRAJ, VINOD; RAO, VEENA
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 053448/0289 →