Hardware Hypervisor for Root-of-Trust Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer security systems, including hardware-based intrusion detection systems and virtual machines, are vulnerable to advanced malware that can subvert their effectiveness, and existing hardware solutions do not provide a robust, real-time monitoring and control mechanism to protect against complex and stealthy malware attacks.
Innovation Solution
A hardware hypervisor is introduced, residing below the CPU and providing isolated monitoring and control functions, combining passive and active security capabilities, with a hypervisor access controller and behavioral interface to enforce access control and integrity checking, ensuring system integrity and user-defined policies without relying on software modifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a software-based virtual machine monitor (VMM) is used to provide isolation and monitoring, then system security is improved, but the complexity of the system increases and it remains vulnerable to subversion by advanced malware
Solution Approach 1:
The patent introduces a hardware-based VMM that acts as an intermediary layer between the CPU and the operating system. This hardware VMM is implemented in dedicated hardware circuitry rather than software, providing isolation and monitoring functions while being immune to software-based subversion attempts. The hardware VMM intercepts and controls CPU operations, memory access, and I/O operations, thereby maintaining system security without the complexity and vulnerability of software-based approaches.
2Reliability
If a hardware-based intrusion detection system (IDS) is implemented to provide real-time monitoring, then detection capability is improved, but the system may be subverted by advanced malware that targets the IDS itself
Solution Approach 1:
The hardware VMM serves as a trusted intermediary that performs intrusion detection and system monitoring. By implementing the IDS functionality in hardware rather than software, the system gains real-time monitoring capability while protecting against malware that attempts to subvert software-based IDS. The hardware VMM operates at a higher privilege level and is isolated from the operating system, making it impossible for malware to directly compromise the detection mechanism.
Solution Approach 2:
The system is segmented into distinct hardware components with separate privilege levels. The hardware VMM operates in a isolated environment with direct control over CPU and memory resources, separate from the operating system and user applications. This segmentation ensures that even if the OS or applications are compromised, the intrusion detection functionality remains intact and operational.
3Measurement precision
If a tightly-coupled coprocessor IDS is used to access internal system resources, then monitoring precision is improved, but the risk of system tampering and loss of integrity increases
Solution Approach 1:
Instead of giving the IDS high privileges to access internal resources, the patent inverts the approach by having the hardware VMM operate at the highest privilege level (above the OS) and control access to all system resources. The VMM acts as a gatekeeper that can monitor all CPU operations, memory access, and I/O operations without being exposed to tampering risks. This inversion of the traditional IDS architecture allows precise monitoring while maintaining system integrity through hardware-enforced isolation.
Data Source
AI summary
A system and method for modifying a processor system with hypervisor hardware to provide protection against malware. The processor system is assumed to be of a type having at least a CPU and a high-speed bus for providing data links between the CPU, other bus masters, and peripherals (including a debug interface unit). The hypervisor hardware elements are (1) a co-processor programmed to perform one or more security tasks; (2) a communications interface between the co-processor and the debug interface unit; (3) a behavioral interface on the high-speed bus, configured to monitor control signals from the CPU, and (4) an access controller on the high-speed bus, configured to store access control data, to intercept requests on the high-speed bus, to evaluate the requests against the access control data, and to grant or deny the requests.


