IP Library Granted Patent US 11,614,956
Granted Patent B2
US 11,614,956 · App. 16/705,929 · Granted Mar 28, 2023

Multicast live migration for encrypted virtual machines

Inventors: Michael Tsirkin (Lexington, MA); Andrea Arcangeli (Imola, IT)
Assignee: Red Hat, Inc.
G06F9/45558G06F21/602H04L9/0819G06F2009/4557G06F2009/45583G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,614,956
App. No.
16/705,929
Granted
Mar 28, 2023
Kind
B2
Abstract

A method includes receiving a request to migrate a virtual machine executing on a source host computer system to a first destination host computer system. The method further includes receiving, from the virtual machine executing on the source host computer system, an encryption key specific to the virtual machine. One or more memory pages associated with the virtual machine are encrypted using the encryption key specific to the virtual machine. The method further includes causing the one or more memory pages associated with the virtual machine to be copied to the first destination host computer system.

Claims (46)

1. A method comprising:

receiving, by a processing device of a source host computer system, a request to migrate a virtual machine (VM) running on the source host computer system to a first destination host computer system;

receiving, by the processing device, from the VM, an encryption key associated with the VM;

decrypting, using an encryption key associated with the source host computer system, one or more memory pages associated with the VM, wherein the encryption key associated with the source host computer system is derived from an address of a memory page of the one or more memory pages;

encrypting, using the encryption key associated with the VM, the one or more memory pages; and

causing the one or more memory pages to be copied to the first destination host computer system.

2. The method of claim 1 , further comprising:

receiving a request to migrate the VM from the source host computer system to a second destination host computer system; and

causing the one or more memory pages to be copied to the second destination host computer system while the one or more memory pages are copied to the first destination host computer system.

3. The method of claim 1 , wherein the encryption key is isolated from a hypervisor managing the VM on the source host computer system.

4. The method of claim 1 , wherein the encryption key is derived from a feature that is specific to the VM.

5. The method of claim 1 , wherein the encryption key associated with the source host computer system is derived from a memory address of the source host computer system associated with the one or more memory pages of the VM.

6. The method of claim 1 , further comprising:

receiving a request to initialize the VM on the destination host computer system; and injecting, into the VM on the destination host computer system, the encryption key associated with the VM.

7. The method of claim 1 , further comprising:

generating a snapshot of the VM running on the source host computer system, by storing, in a non-volatile storage, the one or more memory pages associated with the VM that are encrypted using the encryption key associated with the VM.

8. A system comprising:

a memory component; and

a processing device of a destination host computer system, the processing device to:

detect that an encryption key associated with a virtual machine (VM) that is being migrated from a source host computer system to the destination host computer system is provided by the VM to an encryption engine running at the source host computer system;

receive, from the source host computer system, one or more memory pages associated with a virtual machine (VM);

decrypt, using the encryption key provided by the VM to the encryption engine, the one or more memory pages associated with the VM;

encrypt, using an encryption key associated with the destination host computer system, the one or more memory pages associated with the VM, wherein the encryption key associated with the destination host computer system is derived from a memory address of the destination host computer system associated with the one or more memory pages of the VM;

store the one or more memory pages at the memory component; and

execute the VM on the destination host computer system.

9. The system of claim 8 , wherein the encryption key is isolated from a hypervisor managing the VM on the destination host computer system.

10. The system of claim 8 , wherein the encryption key is derived from a feature that is specific to the VM.

11. The system of claim 8 , wherein the encryption key associated with the destination host computer system is a hardware-generated token.

12. The system of claim 8 , wherein the processing device is further to:

receive, from the source host computer system, a snapshot of the VM executing on the source host computer system, wherein the snapshot comprises one or more memory pages associated with the VM that are encrypted using the encryption key;

decrypt the one or more memory pages using the encryption key; and

initialize the VM to execute on the destination host computer system.

13. A non-transitory computer readable storage medium including instructions that, when executed by a processing device, cause the processing device to perform a method comprising:

receiving a request to migrate a virtual machine (VM) running on a source host computer system to a first destination host computer system;

receiving, from the VM, an encryption key associated with the VM;

decrypting, using an encryption key associated with the source host computer system, one or more memory pages associated with the VM, wherein the encryption key associated with the source host computer system is derived from an address of a memory page of the one or more memory pages;

encrypting, using the encryption key associated with the VM, the one or more memory pages; and

causing the one or more memory pages to be copied to the first destination host computer system.

14. The non-transitory computer readable storage medium of claim 13 , wherein the processing device is further to perform:

receiving a request to migrate the VM from the source host computer system to a second destination host computer system; and

causing the one or more memory pages to be copied to the second destination host computer system while the one or more memory pages are copied to the first destination host computer system.

15. The non-transitory computer readable storage medium of claim 13 , wherein the encryption key is isolated from a hypervisor managing the VM on the source host computer system.

16. The non-transitory computer readable storage medium of claim 13 , wherein the encryption key is derived from a feature that is specific to the VM.

17. The non-transitory computer readable storage medium of claim 13 , further comprising:

generating a snapshot of the VM executing on the source host computer system, by

storing, in a non-volatile storage, the one or more memory pages associated with the VM that are encrypted using the encryption key associated with the VM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2019
From: TSIRKIN, MICHAEL; ARCANGELI, ANDREA
To: RED HAT, INC.
Reel/Frame 051205/0337 →
Continuity (1)
Related Publication 20210173685A1 · Jun 10, 2021
Cited By (30)
US 12,212,586 US 12,217,079 US 12,219,048 US 12,219,053 US 12,244,627 US 12,244,634 US 12,267,326 US 12,277,216 US 12,278,819 US 12,278,840 US 12,278,897 US 12,284,220 US 12,287,899 US 12,353,474 US 12,395,488 US 12,406,071 US 12,411,937 US 12,411,957 US 12,443,720 US 12,443,722 US 12,489,781 US 12,495,049 US 12,505,200 US 12,506,755 US 12,524,550 US 12,531,881 US 12,547,765 US 12,579,251 US 12,645,785 US 12,688,277