FPGA Hypervisor Architecture for Secure Virtual Machine Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies are susceptible to security breaches such as hardware-based attacks, memory leaks, and guest collusion, compromising system security while maintaining performance and power efficiency.

Innovation Solution

Implementing a hypervisor processing unit (HPU) entirely within the reprogrammable fabric of a reconfigurable hardware device (RHD) to provide isolated and dedicated hardware instances, which are dynamically provisioned and de-provisioned to mitigate security threats and maintain performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a traditional software-based hypervisor is used to virtualize hardware resources, then flexibility and ease of provisioning are improved, but security vulnerabilities increase due to susceptibility to attacks like Rowhammer, Spectre, and Meltdown

Engineering Contradiction:
Improveflexibility of virtualizationVSAvoidsecurity of virtualized environment
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the software-based hypervisor with a hardware-based virtualization layer implemented in reconfigurable logic (FPGA). This substitution eliminates software vulnerabilities while maintaining virtualization functionality, as the hardware layer is immune to software-based attacks like Spectre and Meltdown.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a hardware-based virtualization layer as an intermediary between the physical hardware and guest operating systems. This intermediate hardware layer provides secure isolation and controlled access, preventing direct attacks on the hypervisor while maintaining the benefits of virtualization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based security isolation is implemented to prevent attacks, then security is improved, but system complexity and power consumption increase

Engineering Contradiction:
Improvesecurity isolation between guestsVSAvoidcomplexity of virtualization architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal hardware virtualization layer that can dynamically configure and provision multiple virtual machines with different requirements. This single hardware platform provides security isolation, resource management, and flexible provisioning capabilities, reducing overall system complexity compared to multiple specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses reconfigurable hardware logic that can dynamically change its configuration to adapt to different virtualization scenarios. This dynamic capability allows the system to optimize its structure for specific workloads while maintaining security isolation, avoiding the need for overly complex static architectures.

Inventive Principle:
Principle #15Dynamics

3Reliability

If dedicated hardware instances are provisioned for each virtual machine to enhance security, then security isolation is improved, but resource utilization and power efficiency deteriorate

Engineering Contradiction:
Improveisolation between virtual machinesVSAvoidpower consumption of hardware instances
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent combines multiple virtual machine instances within a single reconfigurable hardware platform, allowing shared resources while maintaining isolation. The hardware can dynamically allocate and de-allocate resources to active VMs, ensuring that power is consumed only for actually used hardware instances rather than dedicating permanent hardware to each VM.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements dynamic provisioning where hardware resources are allocated to virtual machines only when needed and recovered when not in use. The reconfigurable logic can be reprogrammed to de-allocate resources from inactive VMs and reallocate them to active ones, optimizing power consumption while maintaining security isolation through proper hardware state management.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS12561155B2Virtual controller architecture and systems and methods implementing same
Publication Date: 2026.02.24 BATTELLE MEMORIAL INST
  • US12561155B2 patent drawing
  • US12561155B2 patent drawing
  • US12561155B2 patent drawing

AI summary

An aspect of the present disclosure is directed to a system for dynamic provisioning of hardware instances via reprogrammable fabric provided by a reprogrammable hardware device (RHD). The system preferably includes a memory having a first instruction set disposed therein, the first instruction set for provisioning a hypervisor processing unit (HPU) instance (also referred to herein as an orchestrator instance) within the reprogrammable fabric of the RHD, and a startup sequence for execution by the HPU instance. The startup sequence of the HPU instance is preferably configured to cause provisioning of at least a first hardware instance within the second portion of the reprogrammable fabric of the RHD, and for provisioning an interface instance to allow for a physical hardware device of the host computer system to communicate with the first hardware instance via a virtualized communication channel.