Hypervisor Access Privileges for Secure Autonomous Vehicle Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Operating systems of virtual machines require access to resources, but allowing full access presents security vulnerabilities across multiple operating system modalities in autonomous vehicles.

Innovation Solution

A hypervisor allocates specific access privileges to virtual machines based on their operating system modalities, ensuring secure resource access by distinguishing between real-time and non-real-time, as well as formally verified and unverified operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If full access to all devices is allowed by all virtual machines, then resource utilization and operational flexibility are improved, but security vulnerabilities increase

Engineering Contradiction:
Improveresource access flexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments resource access rights by creating distinct access privilege levels for different virtual machines based on their operating system modalities. The hypervisor divides access permissions into specific categories (read, write, execute, etc.) and assigns them selectively to each virtual machine, preventing any single virtual machine from having full access to all devices while still allowing necessary access to specific resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by granting different access privileges to different virtual machines based on their specific needs and security requirements. Each virtual machine receives tailored access permissions corresponding to its operating system modality (real-time vs. non-real-time, formally verified vs. unverified), ensuring that each component has appropriate access rights without unnecessary privileges that could create security risks.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If access privileges are restricted based on operating system modality, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity vulnerabilitiesVSAvoidaccess management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a unified access control framework within the hypervisor that handles multiple operating system modalities through a single mechanism. The same hypervisor infrastructure manages access privileges for real-time and non-real-time operating systems, formally verified and unverified systems, using consistent principles and data structures, thereby reducing overall system complexity despite the diversity of access requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11875177B1Variable access privileges for secure resources in an autonomous vehicle
Publication Date: 2024.01.16 APPLIED INTUITION INC
  • US11875177B1 patent drawing
  • US11875177B1 patent drawing
  • US11875177B1 patent drawing

AI summary

Variable access privileges for secure resources in an autonomous vehicle, including: allocating, by a hypervisor, to a first virtual machine comprising a first operating system, a first one or more access privileges to one or more resources; allocating, by the hypervisor, to a second virtual machine comprising a second operating system different than the first operating system, a second one or more access privileges to the one or more resources; and modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine; wherein the hypervisor, the first virtual machine, and the second virtual machine are implemented by an autonomous vehicle.