Host OS License Blob Storage for VM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The isolation of guest operating systems in virtual machines or containers poses challenges when launching applications, as they often lack access to licensing information due to security boundaries, leading to software piracy risks when applications are copied across hosts without valid licenses.

Innovation Solution

Storing license information in a random memory location allocated by the host operating system, accessible only to the host, and informing the guest operating system of this location, ensuring that the license blob is not accessible when memory content is copied to another host.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If license information is stored in a location accessible to the guest operating system, then application launching is enabled, but security boundaries are compromised and software piracy risks increase

Engineering Contradiction:
Improveapplication launchingVSAvoidsecurity boundary
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The host operating system acts as an intermediary that stores license information in its own memory space and provides controlled access to the guest operating system. The guest OS cannot directly access the license blob but must request it through the host OS, which validates and manages the licensing information. This mediator approach enables application launching in the guest while maintaining security boundaries through the host OS's control layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves license information storage from the guest OS memory space to the host OS memory space, changing the dimensional layer where licensing data resides. By storing the license blob in host memory rather than guest memory, the system achieves both goals: the guest can access licensing functionality through the host interface, while the actual license data remains protected in the host's secure memory space outside the guest's accessible range.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If memory content is copied from one host to another, then virtual machine portability is improved, but license information security is compromised

Engineering Contradiction:
Improvevirtual machine portabilityVSAvoidsoftware piracy risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts license information from the guest OS memory space and places it in the host OS memory space. When a virtual machine is copied or migrated, the license blob remains in the original host's memory space and is not copied along with the VM. This extraction approach maintains VM portability while preventing license theft, as the license information stays bound to the original host system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a controlled copy mechanism where the host OS can provide license information to the guest OS when needed, but the guest OS cannot independently copy or export the license blob. The license data is replicated only when explicitly authorized by the host OS for legitimate operational needs, not for migration or porting purposes. This selective copying prevents software piracy while enabling legitimate application execution.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If untrusted code is allowed to run in a container, then application flexibility is improved, but license information protection is weakened

Engineering Contradiction:
Improveapplication flexibilityVSAvoidlicense theft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The host operating system serves as a protective intermediary between untrusted containerized applications and the license information. Even though untrusted code can execute within the container, it cannot directly access the license blob stored in host memory. The host OS mediates all licensing requests, validating them against security policies before granting access. This maintains application flexibility while preventing license theft by untrusted code.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a thin protective layer of host OS memory management that separates the containerized application from the license information. This flexible protective boundary allows the container to operate with high flexibility and access necessary system resources, while simultaneously blocking unauthorized access paths to the license blob. The host OS memory space acts as a flexible shield that adapts to container needs while maintaining security.

Inventive Principle:
Principle #30Flexible shells and thin films

Data Source

PatentEP3785149B1Memory assignment for guest operating systems
Publication Date: 2023.06.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3785149B1 patent drawingFigure 1~2A
  • EP3785149B1 patent drawingFigure 2B~2C
  • EP3785149B1 patent drawingFigure 2D~2E

AI summary

Techniques for memory assignment for guest operating systems are disclosed herein. In one embodiment, a method includes generating a license blob containing data representing a product key copied from a record of license information in the host storage upon receiving a user request to launch an application in the guest operating system. The method also includes storing the generated license blob in a random memory location accessible by the guest operating system. The guest operating system can then query the license blob for permission to launch the application and launching the application in the guest operating system without having a separate product key for the guest operating system.