IP Library Granted Patent US 10,489,594
Granted Patent B2
US 10,489,594 · App. 15/654,424 · Granted Nov 26, 2019

System and method for secure migration of virtual machines between host servers

Inventors: Shekar Babu Suryanarayana (Bangalore, IN); Lucky Pratap Khemani (Bangalore, IN); Sumanth Vidyadhara (Bangalore, IN); Chandrasekhar Puthillathe (Bangalore, IN)
Assignee: Dell Products, LP
G06F21/57G06F9/45558G06F9/5088G06F2009/4557G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,489,594
App. No.
15/654,424
Granted
Nov 26, 2019
Kind
B2
Abstract

A pair of servers may include a source server hosting a source virtual machine (VM) and a target server hosting a target VM. The source server may include a source central processing unit (CPU) and a source baseboard management controller (BMC), and the target server may include a target CPU and a target BMC. The source server and the target server are connected by an inband connection, and the source BMC and the target BMC are connected by a connection distinct from the inband connection. The source VM may be migrated to the target server over the inband connection, and in response to migrating the source VM, security data corresponding to the source VM is communicated from the source BMC to the target BMC over the connection between the BMCs.

Claims (31)

1. A server set comprising:

a first server including a first central processing unit (CPU) and a first baseboard management controller (BMC), wherein the first CPU hosts a source virtual machine (VM); and

a second server including a second CPU and a second BMC, wherein the second CPU hosts a target VM, wherein the first server and the second server are connected by a first connection and the first BMC and the second BMC are connected by a second connection distinct from the first connection, and wherein:

the source VM is migrated from the first server to the second server over the first connection, and

in response to migrating the source VM, security data corresponding to the source VM is communicated from the first BMC to the second BMC over the second connection, wherein the security data includes a time-limited duration that is negotiated between the source BMC and the target VM.

2. The server set of claim 1 , wherein the first connection is an inband connection and the second connection is an out of band connection.

3. The server set of claim 1 , wherein the security data comprises an SBK corresponding to source VM and the SBK is to be used to securely boot the target VM.

4. The server set of claim 1 , wherein the security data is maintained at a first BIOS hosted by the first CPU.

5. The server set of claim 4 , wherein the first BMC and the first CPU are communicatively connected internal to the server by an internal server connection.

6. The server set of claim 5 , wherein in response to migrating the source VM, the security data is transferred from the first BIOS to the first BMC over the internal server connection.

7. The server set of claim 6 , wherein the internal server connection includes an SMA path.

8. The server set of claim 1 , wherein the second BMC and the second CPU are communicatively connected internal to the server by an internal server connection providing a communication channel between the second BMC and the second CPU.

9. The server set of claim 8 , wherein in response to migrating the source VM, the security data is obtained from the second BMC at the second CPU over the communication channel.

10. The server set of claim 9 , wherein migrating the source VM triggers execution of virtual runtime services at the second CPU and the virtual runtime services access a system configuration table of the second server to dynamically map a path to the second BMC to obtain the security data.

11. A source server comprising:

a source central processing unit (CPU), wherein the source CPU hosts a source virtual machine (VM);

a source baseboard management controller (BMC), wherein the source CPU and the source BMC are communicatively connected internal to the server by an internal server connection providing a communication channel between the source BMC and the source CPU, and wherein:

in response to identifying a target VM on a target server, the source VM is migrated to the target VM over an inband connection connecting the source server to the target server, and

in response to migrating the source VM, security data corresponding to the source VM is transferred from a BIOS hosted by the source CPU to the source BMC over the internal server connection, wherein the security data includes a time-limited duration that is negotiated between the source BMC and the target VM.

12. The source server of claim 11 , wherein the security data includes an SBK for securely booting the target VM.

13. The source server of claim 11 , wherein the source BMC communicates the security data to a target BMC of the target server over a BMC connection distinct from the inband connection.

14. The source server of claim 13 , wherein the BMC connection is a sideband connection out of band with the inband connection.

15. A method comprising:

identifying a target virtual machine (VM) hosted by a target central processing unit (CPU) of a target server, the target server including a target baseboard management controller (BMC);

migrating a source VM hosted by a source CPU of a source server over a first connection between the source server and the target server to the target server, the source server including a source BMC; and

in response to migrating the source VM, communicating security data corresponding to the source VM from the source BMC to the target BMC over a second connection connecting source BMC with target BMC and distinct from the first connection, wherein the security data includes a time-limited duration that is negotiated between the source BMC and the target VM.

16. The method of claim 15 , wherein the security data includes a SBK corresponding to the source VM to be used to securely boot the target VM at the target server.

17. The method of claim 15 , wherein the first connection is an inband connection and the second connection is a sideband connection out of band to the inband connection.

18. The method of claim 15 , wherein the source CPU is connected to the source BMC by an internal server connection internal to the source server and the security data is communicated from a BIOS hosted by the source CPU to the source BMC over the internal server connection.

19. The method of claim 15 , wherein the target BMC and the target CPU are communicatively connected internal to the server by an internal server connection.

20. The method of claim 19 , wherein migrating the source VM triggers execution of virtual runtime services at the target CPU and the virtual runtime services access a system configuration table of the target server to dynamically map a path to the target BMC over the internal server connection to obtain the security data.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (043775/0082) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060958/0468 →
RELEASE OF SECURITY INTEREST AT REEL 043772 FRAME 0750 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0606 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2017
From: SURYANARAYANA, SHEKAR BABU; KHEMANI, LUCKY PRATAP; VIDYADHARA, SUMANTH; PUTHILLATHE, CHANDRASEKHAR
To: DELL PRODUCTS, LP
Reel/Frame 043868/0013 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 043772/0750 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Sep 6, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 043775/0082 →
Continuity (1)
Related Publication 20190026467A1 · Jan 24, 2019
Cited By (1)
US 12,499,236