Guest Virtual Resource Trust Layers for Host-Isolated Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based platforms face challenges in providing secure isolation of tenant data due to potential exposure through interactions between virtual resources and host components, especially for sensitive data like health and financial information, making tenants hesitant to use these platforms.

Innovation Solution

The system emulates a security component within a tenant's virtual resource unit, creating distinct virtual trust layers with varying privileges and isolating sensitive operations from lower privileged components by using hardware virtualization features and a virtual secure mode to encrypt memory and CPU states.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security component is configured on the host operating system to provide security operations for virtual resources, then security operations can be performed efficiently, but tenant data may be exposed to host component vulnerabilities and lower privileged components

Engineering Contradiction:
Improvedata isolationVSAvoidexposure to host vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security component into separate virtual trust layers within the virtual resource unit. A first virtual trust layer executes basic resource components while a second virtual trust layer executes the security component with higher privileges. This segmentation isolates security operations from lower privileged components and host vulnerabilities, resolving the contradiction between efficient security operations and data isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces virtual trust layers as intermediary structures between the virtual resource unit and the host operating system. These layers act as mediators that enable security operations while maintaining isolation boundaries, preventing direct exposure to host vulnerabilities while still allowing necessary security functions to operate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If virtual resources interact with host components to access hardware resources, then resource access is enabled, but security isolation between tenant data and host components is compromised

Engineering Contradiction:
Improveresource access capabilityVSAvoidsecurity isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent adds a dimensional layer of virtual trust layers between the virtual resource unit and host components. This additional dimension enables resource access while maintaining security isolation, as interactions must pass through the isolated virtual trust layer boundaries rather than directly accessing host components.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If a virtual security component is emulated within the virtual resource unit to isolate tenant data, then data isolation is enhanced, but the complexity of the virtual resource unit increases

Engineering Contradiction:
Improvedata isolationVSAvoidvirtual resource unit structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements virtual trust layers that serve multiple functions: they provide security isolation, enable privilege escalation for security operations, and maintain resource access capabilities. By making these layers multi-functional, the patent reduces overall system complexity while achieving enhanced data isolation, as a single structural element accomplishes multiple security objectives.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12399979B2Provisioning a security component from a cloud host to a guest virtual resource unit
Publication Date: 2025.08.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12399979B2 patent drawing
  • US12399979B2 patent drawing
  • US12399979B2 patent drawing

AI summary

The techniques disclosed herein enable a system to configure a confidential virtual resource unit by provisioning a security component to a tenant's virtual resource unit. The system creates multiple different virtual trust layers within the confidential virtual resource unit. This creation effectively defines security boundaries between the virtual trust layers. The virtual trust layers are associated with different privileges, such that a higher privileged virtual trust layer is provided with more privileges compared to a lower privileged virtual trust layer. In one example, a lower privileged virtual trust layer may include basic virtual resource components (e.g., drivers, applications, processes, functions, workloads executing within a guest operating system) and a higher privileged virtual trust layer is the location to which a virtual security component is provisioned by the system.