Concealed Namespace Object Store for Virtualized Memory Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized information handling systems face significant security vulnerabilities due to weaknesses in the hypervisor layer, which can lead to unauthorized access and corruption of virtual machines, especially when attackers exploit namespace mappings and metadata, potentially affecting multiple virtual machines and the hypervisor.

Innovation Solution

Implementing a concealed namespace object store as a hidden metadata area within the memory subsystem, unexposed to the hypervisor and virtual machines, to securely manage namespace metadata and provide secure access, using a management library and concealed real-time service to control privileges and validate signatures for authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If namespace metadata is exposed to the hypervisor and virtual machines for management, then ease of operation is improved, but security vulnerability increases allowing unauthorized access and corruption

Engineering Contradiction:
Improvenamespace metadata managementVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the namespace metadata storage from the exposed hypervisor/virtual machine environment and places it in a concealed, protected area of the memory subsystem. The concealed namespace object store is implemented as a hidden metadata area that is unexposed to the hypervisor and virtual machines, thereby separating the metadata management function from the vulnerable virtualized environment while maintaining management capabilities through controlled access interfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a concealed real-time service as an intermediary between authorized management entities and the concealed namespace object store. This service validates signatures and controls privileges, allowing legitimate namespace metadata management while blocking unauthorized access attempts. The intermediary layer enables ease of operation for authorized users while preventing security vulnerabilities from affecting the actual metadata storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If hypervisor is used to manage virtual machines and namespaces, then productivity is improved through resource virtualization, but reliability deteriorates due to hypervisor vulnerabilities

Engineering Contradiction:
Improveresource virtualization efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the namespace metadata storage into a separate, concealed portion that is independent from the hypervisor's addressable memory space. By dividing the memory subsystem into exposed areas (for virtual machine operation) and concealed areas (for metadata storage), the system maintains the productivity benefits of hypervisor-mediated resource virtualization while isolating critical namespace metadata from hypervisor vulnerabilities and potential corruption.

Inventive Principle:
Principle #1Segmentation

3Ease of manufacture

If namespace metadata is stored in accessible memory areas, then ease of manufacture and access is improved, but susceptibility to corruption and harmful factors increases

Engineering Contradiction:
Improvememory implementation simplicityVSAvoidmetadata corruption risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies different quality properties to different portions of the memory subsystem. The concealed namespace object store is implemented with enhanced security properties (unexposed to hypervisor, signature-validated access) while other memory areas maintain standard accessibility. This local differentiation allows the system to protect critical metadata from corruption risks while maintaining ease of manufacture and access for non-critical memory operations.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10706152B2Systems and methods for concealed object store in a virtualized information handling system
Publication Date: 2020.07.07 DELL PROD LP
  • US10706152B2 patent drawing
  • US10706152B2 patent drawing
  • US10706152B2 patent drawing

AI summary

In accordance with embodiments of the present disclosure, an information handling system may include a processor subsystem configured to execute a hypervisor, wherein the hypervisor is configured to host a plurality of virtual machines and a memory subsystem communicatively coupled to the processor subsystem. The memory subsystem may be configured to implement namespaces for the hypervisor and the plurality of virtual machines and implement for each of the namespaces a concealed namespace object store as a hidden metadata area of the memory subsystem unexposed to the hypervisor and the plurality of virtual machines, each concealed namespace object store comprising metadata for an associated namespace.