Guest Virtual Resource Trust Layers for Host-Isolated Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based platforms face challenges in providing secure isolation of tenant data due to potential exposure through interactions between virtual resources and host components, especially for sensitive data like health and financial information, making tenants hesitant to use these platforms.
Innovation Solution
The system emulates a security component within a tenant's virtual resource unit, creating distinct virtual trust layers with varying privileges and isolating sensitive operations from lower privileged components by using hardware virtualization features and a virtual secure mode to encrypt memory and CPU states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security component is configured on the host operating system to provide security operations for virtual resources, then security operations can be performed efficiently, but tenant data may be exposed to host component vulnerabilities and lower privileged components
Solution Approach 1:
The patent segments the security component into separate virtual trust layers within the virtual resource unit. A first virtual trust layer executes basic resource components while a second virtual trust layer executes the security component with higher privileges. This segmentation isolates security operations from lower privileged components and host vulnerabilities, resolving the contradiction between efficient security operations and data isolation.
Solution Approach 2:
The patent introduces virtual trust layers as intermediary structures between the virtual resource unit and the host operating system. These layers act as mediators that enable security operations while maintaining isolation boundaries, preventing direct exposure to host vulnerabilities while still allowing necessary security functions to operate.
2Adaptability or versatility
If virtual resources interact with host components to access hardware resources, then resource access is enabled, but security isolation between tenant data and host components is compromised
Solution Approach 1:
The patent adds a dimensional layer of virtual trust layers between the virtual resource unit and host components. This additional dimension enables resource access while maintaining security isolation, as interactions must pass through the isolated virtual trust layer boundaries rather than directly accessing host components.
3Reliability
If a virtual security component is emulated within the virtual resource unit to isolate tenant data, then data isolation is enhanced, but the complexity of the virtual resource unit increases
Solution Approach 1:
The patent implements virtual trust layers that serve multiple functions: they provide security isolation, enable privilege escalation for security operations, and maintain resource access capabilities. By making these layers multi-functional, the patent reduces overall system complexity while achieving enhanced data isolation, as a single structural element accomplishes multiple security objectives.
Data Source
AI summary
The techniques disclosed herein enable a system to configure a confidential virtual resource unit by provisioning a security component to a tenant's virtual resource unit. The system creates multiple different virtual trust layers within the confidential virtual resource unit. This creation effectively defines security boundaries between the virtual trust layers. The virtual trust layers are associated with different privileges, such that a higher privileged virtual trust layer is provided with more privileges compared to a lower privileged virtual trust layer. In one example, a lower privileged virtual trust layer may include basic virtual resource components (e.g., drivers, applications, processes, functions, workloads executing within a guest operating system) and a higher privileged virtual trust layer is the location to which a virtual security component is provisioned by the system.


