Bare-Metal Hypervisor for Mobile VMs with Hardware-Enforced Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile security solutions are ineffective due to the large and complex kernel and operating system size of mobile devices, leading to numerous vulnerabilities and resource constraints, making it difficult to implement lightweight hardware-enforced hypervisor solutions that provide isolated security environments.
Innovation Solution
A type-1 bare-metal hypervisor architecture that allows virtual machines (VMs) direct access to hardware without a traditional virtualization layer, maintaining hardware-enforced isolation between VMs and optimizing resource usage on mobile devices with limited CPU resources and power capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a traditional virtualization layer is added between the operating system and device hardware, then security isolation between VMs is improved, but resource consumption increases and power capacity is drained
Solution Approach 1:
The patent extracts the essential security isolation function from the traditional virtualization layer and implements it directly through hardware virtualization features. By removing the intermediate software virtualization layer and using hardware-enforced isolation, the system maintains security while reducing the resource overhead and power consumption associated with software-based virtualization.
Solution Approach 2:
The patent introduces a lightweight hypervisor that acts as an intermediary between the VMs and hardware, but unlike traditional solutions, this hypervisor leverages hardware virtualization features to minimize its own resource footprint. The hardware itself becomes the primary mediator for isolation, reducing the burden on software components.
2Reliability
If a traditional virtualization layer is added between the operating system and device hardware, then security isolation between VMs is improved, but device performance deteriorates
Solution Approach 1:
The patent removes the performance-deteriorating software virtualization layer and replaces it with hardware-enforced isolation mechanisms. This extraction of the virtualization function to the hardware level eliminates the performance overhead associated with software interpretation and context switching, while maintaining security isolation.
Solution Approach 2:
The patent replaces the software-based virtualization mechanism with hardware-based virtualization features. This substitution eliminates the computational overhead of software virtualization and allows direct hardware access for VMs, significantly improving performance while maintaining isolation through hardware-enforced boundaries.
3Reliability
If the kernel and operating system size is reduced to improve security, then vulnerability exposure is reduced, but functionality and adaptability are limited
Solution Approach 1:
The patent segments the system into multiple isolated VMs, each with its own minimized kernel and operating system. This segmentation allows each VM to have a small, secure footprint while the overall system provides diverse functionality through multiple specialized VM instances. Each VM can be independently optimized for specific functions without requiring a large monolithic OS.
Solution Approach 2:
The patent creates a universal platform where multiple VMs with different functionalities can coexist on the same hardware. Instead of requiring a large OS to handle all functions, the system uses a set of smaller, specialized VMs that collectively provide diverse capabilities while maintaining security through isolation.
4Productivity
If direct hardware access is provided to VMs, then performance is improved, but security isolation becomes more difficult to maintain
Solution Approach 1:
The patent replaces software-based security checks with hardware-enforced isolation mechanisms. By using hardware virtualization features, the system can provide VMs with direct hardware access while the hardware itself enforces security boundaries, eliminating the need for software to mediate every access and reducing the attack surface.
Solution Approach 2:
The patent introduces a lightweight hypervisor as an intermediary that leverages hardware virtualization features to manage direct hardware access. This hypervisor uses hardware-enforced isolation to maintain security boundaries while allowing VMs to directly access hardware resources, achieving both performance and security.
Data Source
AI summary
The invention provides multiple secure virtualized environments operating in parallel with optimal resource usage, power consumption and performance. The invention provides a method whereby virtual machines (VMs) have direct access to the computing system's hardware without adding traditional virtualization layers while the hypervisor maintains hardware-enforced isolation between VMs, preventing risks of cross-contamination. Additionally, some of the VMs can be deactivated and reactivated dynamically when needed, which saves the computing system resources. As a result, the invention provides bare-metal hypervisor use and security but without the limitations that make such hypervisors impractical, inefficient and inconvenient for use in mobile devices due to the device's limited CPU and battery power capacity.


