Bare-Metal Hypervisor for Mobile VMs with Hardware-Enforced Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile security solutions are ineffective due to the large and complex kernel and operating system size of mobile devices, leading to numerous vulnerabilities and resource constraints, making it difficult to implement lightweight hardware-enforced hypervisor solutions that provide isolated security environments.

Innovation Solution

A type-1 bare-metal hypervisor architecture that allows virtual machines (VMs) direct access to hardware without a traditional virtualization layer, maintaining hardware-enforced isolation between VMs and optimizing resource usage on mobile devices with limited CPU resources and power capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional virtualization layer is added between the operating system and device hardware, then security isolation between VMs is improved, but resource consumption increases and power capacity is drained

Engineering Contradiction:
Improvesecurity isolationVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the essential security isolation function from the traditional virtualization layer and implements it directly through hardware virtualization features. By removing the intermediate software virtualization layer and using hardware-enforced isolation, the system maintains security while reducing the resource overhead and power consumption associated with software-based virtualization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a lightweight hypervisor that acts as an intermediary between the VMs and hardware, but unlike traditional solutions, this hypervisor leverages hardware virtualization features to minimize its own resource footprint. The hardware itself becomes the primary mediator for isolation, reducing the burden on software components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a traditional virtualization layer is added between the operating system and device hardware, then security isolation between VMs is improved, but device performance deteriorates

Engineering Contradiction:
Improvesecurity isolationVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent removes the performance-deteriorating software virtualization layer and replaces it with hardware-enforced isolation mechanisms. This extraction of the virtualization function to the hardware level eliminates the performance overhead associated with software interpretation and context switching, while maintaining security isolation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the software-based virtualization mechanism with hardware-based virtualization features. This substitution eliminates the computational overhead of software virtualization and allows direct hardware access for VMs, significantly improving performance while maintaining isolation through hardware-enforced boundaries.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If the kernel and operating system size is reduced to improve security, then vulnerability exposure is reduced, but functionality and adaptability are limited

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the system into multiple isolated VMs, each with its own minimized kernel and operating system. This segmentation allows each VM to have a small, secure footprint while the overall system provides diverse functionality through multiple specialized VM instances. Each VM can be independently optimized for specific functions without requiring a large monolithic OS.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal platform where multiple VMs with different functionalities can coexist on the same hardware. Instead of requiring a large OS to handle all functions, the system uses a set of smaller, specialized VMs that collectively provide diverse capabilities while maintaining security through isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If direct hardware access is provided to VMs, then performance is improved, but security isolation becomes more difficult to maintain

Engineering Contradiction:
ImproveperformanceVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces software-based security checks with hardware-enforced isolation mechanisms. By using hardware virtualization features, the system can provide VMs with direct hardware access while the hardware itself enforces security boundaries, eliminating the need for software to mediate every access and reducing the attack surface.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a lightweight hypervisor as an intermediary that leverages hardware virtualization features to manage direct hardware access. This hypervisor uses hardware-enforced isolation to maintain security boundaries while allowing VMs to directly access hardware resources, achieving both performance and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10948967B2Mobile device virtualization solution based on bare-metal hypervisor with optimal resource usage and power consumption
Publication Date: 2021.03.16 INZERO TECHNOLOGIES LLC
  • US10948967B2 patent drawing
  • US10948967B2 patent drawing
  • US10948967B2 patent drawing

AI summary

The invention provides multiple secure virtualized environments operating in parallel with optimal resource usage, power consumption and performance. The invention provides a method whereby virtual machines (VMs) have direct access to the computing system's hardware without adding traditional virtualization layers while the hypervisor maintains hardware-enforced isolation between VMs, preventing risks of cross-contamination. Additionally, some of the VMs can be deactivated and reactivated dynamically when needed, which saves the computing system resources. As a result, the invention provides bare-metal hypervisor use and security but without the limitations that make such hypervisors impractical, inefficient and inconvenient for use in mobile devices due to the device's limited CPU and battery power capacity.