Device Interface Security Management for Virtual Machines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems lack effective mechanisms for securely managing device interfaces between virtual machines and physical devices on a computer bus, particularly in ensuring confidentiality and integrity of memory contents and CPU states, which is crucial for trusted virtual machines to prevent data exfiltration and tampering.

Innovation Solution

A protocol is introduced to lock down device interfaces, report configurations, and manage their operational states securely, utilizing trust domain extensions (TDX) and memory encryption to protect the confidentiality and integrity of trusted virtual machines, enabling direct assignment and secure operation of PCIe/CXL devices within a trusted domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If device interfaces are made accessible to virtual machines for direct assignment, then device utilization efficiency and performance are improved, but security risks and vulnerability to data exfiltration increase

Engineering Contradiction:
Improvedevice utilization efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a device interface management protocol that acts as an intermediary between virtual machines and physical device interfaces. This protocol includes state machine logic that mediates all access requests, transitions device interfaces between locked and operational states, and enforces security policies without preventing direct assignment. The intermediary mechanism enables both high device utilization and security by controlling the manner of access rather than blocking it.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic state transitions for device interfaces, moving between locked and operational states based on security requirements. The device interface state machine dynamically adjusts accessibility: locked state prevents unauthorized access while operational state enables performance-optimized direct access. This dynamic approach allows the system to optimize for security or performance depending on the operational context, resolving the contradiction between device utilization and security.

Inventive Principle:
Principle #15Dynamics

2Reliability

If device interfaces are locked down to prevent unauthorized access, then security and integrity are improved, but device accessibility and operational flexibility deteriorate

Engineering Contradiction:
ImproveintegrityVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic state transitions for device interfaces, moving between locked and operational states based on security requirements. The device interface state machine dynamically adjusts accessibility: locked state prevents unauthorized access while operational state enables performance-optimized direct access. This dynamic approach allows the system to optimize for security or performance depending on the operational context, resolving the contradiction between device utilization and security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies preliminary locking actions to device interfaces before assigning them to virtual machines. The management protocol locks device interfaces in a secure state prior to assignment, then controls the transition to operational states through authenticated commands. This preliminary security measure ensures integrity is established before accessibility is granted, and the structured state transition process maintains both security and operational flexibility.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If memory encryption and trust domain extensions are implemented, then confidentiality and security are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
ImproveconfidentialityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional hardware capabilities (memory encryption units, trust domain extensions, device state machine logic) to provide security without adding separate dedicated security hardware. The same hardware resources perform both computational tasks and security functions, reducing overall system complexity while maintaining strong confidentiality protections through integrated security features.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3772009B1Device interface security management for computer buses
Publication Date: 2024.08.14 INTEL CORP
  • EP3772009B1 patent drawingFigure 1
  • EP3772009B1 patent drawingFigure 2(a)
  • EP3772009B1 patent drawingFigure 2(b)

AI summary

Systems, apparatuses, methods, and computer-readable media are provided for device interface management. A device includes a device interface, a virtual machine (VM) includes a device driver, both to facilitate assignment of the device to the VM, access of the device by the VM, or removal of the device from being assigned to the VM. The VM is managed by a hypervisor of a computing platform coupled to the device by a computer bus. The device interface includes logic in support of a device management protocol to place the device interface in an unlocked state, a locked state to prevent changes to be made to the device interface, or an operational state to enable access to device registers of the device by the VM or direct memory access to memory address spaces of the VM, or an error state. Other embodiments may be described and/or claimed.