Client Hosted Virtualization Manager for Secure VM Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems lack secure and efficient methods for supporting task-oriented devices and full volume encryption in client-hosted virtualization environments, which are essential for secure data processing and storage, especially in environments vulnerable to malicious software and data breaches.
Innovation Solution
The implementation of a secure client-hosted virtualization (CHV) architecture with a CHV manager that resides in secure memory, supports I/O port assignment and security policies, provides pre-boot authentication, and enables full volume encryption, ensuring secure access to resources and storage across multiple virtual machines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional virtualization is used without secure isolation, then device compatibility and ease of operation are improved, but security and reliability deteriorate due to vulnerability to malicious software and data breaches
Solution Approach 1:
The system segments the virtualization environment into distinct secure containers (virtual machines) with isolated resource access. Each virtual machine is confined to specific I/O ports and resources assigned by the CHV manager, preventing malicious software in one VM from accessing or affecting other VMs or host resources. This segmentation provides security without requiring complete system redesign.
Solution Approach 2:
The CHV manager acts as an intermediary between virtual machines and physical resources. It sits between the VMs and the I/O ports, managing resource assignment and access control. This intermediary layer enforces security policies and prevents direct unauthorized access to hardware resources, maintaining security while preserving ease of operation for legitimate users.
2Reliability
If full volume encryption is implemented, then data security and integrity are improved, but processing speed and productivity deteriorate due to encryption overhead
Solution Approach 1:
The system performs preliminary encryption actions by encrypting data at the point of storage in encrypted containers. The CHV manager and secure container architecture establish encryption mechanisms in advance, so that data is protected before it becomes vulnerable to attacks. This preliminary protection maintains data integrity without requiring continuous decryption/encryption cycles during normal operations.
Solution Approach 2:
The encrypted container architecture enables self-service encryption where data is automatically encrypted and protected within isolated containers managed by the CHV manager. The system handles encryption operations autonomously within the secure container environment, reducing the performance overhead that would otherwise impact general processing speed.
3Productivity
If multiple virtual machines share common storage resources, then resource utilization and productivity are improved, but security and reliability deteriorate due to potential cross-contamination from malicious software
Solution Approach 1:
The system segments storage resources into isolated encrypted containers, with each virtual machine assigned to specific container(s). The CHV manager manages this segmentation and ensures that VMs can share physical storage infrastructure while maintaining logical isolation through encrypted container boundaries. This allows high resource utilization through sharing while preventing cross-contamination between VMs.
Solution Approach 2:
The CHV manager serves as an intermediary that controls all access to shared storage resources. It manages the assignment of encrypted containers to virtual machines and enforces access policies that prevent unauthorized cross-access. This intermediary layer enables multiple VMs to safely share storage resources while maintaining security through controlled access and isolation mechanisms.
Data Source
AI summary
A client hosted virtualization system includes a task oriented device, a processor, and non-volatile memory with BIOS code and virtualization manager code. The virtualization manager initializes the client hosted virtualization system, authenticates a virtual machine image, launches the virtual machine based on the image, receives a transaction targeted to the task oriented device, prioritizes the transaction, sends the transaction to the task oriented device, receives a response from the task oriented device, and sends the response to the virtual machine. The client hosted virtualization system is configurable to execute the BIOS or the virtualization manager.


