Hypervisor Access Control Across Mixed OS Modalities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Operating systems of virtual machines require access to resources, but allowing full access presents security vulnerabilities across multiple operating system modalities in autonomous vehicles.
Innovation Solution
A hypervisor allocates specific access privileges to virtual machines based on their operating system modalities, ensuring secure resource access by differentiating between real-time and non-real-time, as well as formally verified and unverified operating systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full access to all devices is allowed by all virtual machines, then resource accessibility is improved, but security vulnerabilities increase
Solution Approach 1:
The patent applies local quality by assigning different access privileges to different virtual machines based on their specific operating system modality requirements. Each virtual machine receives tailored access rights (e.g., real-time vs. non-real-time, formally verified vs. unverified) rather than uniform access, allowing resource accessibility where needed while limiting exposure to security vulnerabilities in other areas.
Solution Approach 2:
The patent segments access privileges into distinct categories (real-time/non-real-time, formally verified/unverified) and assigns them selectively to different virtual machines. This segmentation allows the system to provide targeted resource access to specific virtual machines while preventing others from accessing resources they don't need, thereby reducing security vulnerabilities without compromising overall resource accessibility.
2Object-affected harmful factors
If access privileges are differentiated by operating system modality, then device security is improved, but system complexity increases
Solution Approach 1:
The patent introduces a hypervisor as an intermediary layer between the virtual machines and the underlying resources. The hypervisor manages and enforces the complex access privilege assignments based on operating system modality, shielding the virtual machines from the complexity of security management while maintaining strong device security through modality-based differentiation.
Solution Approach 2:
The hypervisor serves multiple functions: it manages virtual machine creation, allocates resources, enforces access privileges based on operating system modality, and maintains security policies. By consolidating these diverse functions into a single universal component, the system achieves strong device security without proportionally increasing overall system complexity.
Data Source
AI summary
Device security across multiple operating system modalities may include allocating, by a hypervisor, to a first virtual machine comprising a first operating system of a first modality, based on the first modality, a first one or more access privileges to one or more resources; and allocating, by the hypervisor, to a second virtual machine comprising a second operating system of a second modality, based on the second modality, a second one or more access privileges to the one or more resources.


