Hypervisor Access Privileges for Secure Autonomous Vehicle VMs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Operating systems of virtual machines require access to resources for functionality, but allowing full access presents security vulnerabilities across multiple operating system modalities in autonomous vehicles.
Innovation Solution
A hypervisor allocates specific access privileges to virtual machines based on their operating system modalities, ensuring secure resource access by differentiating between real-time and non-real-time, as well as formally verified and unverified operating systems, thereby managing access to computational resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If full access to all devices is allowed by all virtual machines, then functionality and ease of operation are improved, but security vulnerabilities increase
Solution Approach 1:
The patent implements modality-specific access control policies where different virtual machines receive different access privileges based on their operating system modalities. Formally verified real-time operating systems receive broader access privileges compared to unverified non-real-time operating systems, creating localized quality differences in access rights that balance functionality with security requirements for each specific virtual machine type.
Solution Approach 2:
The system segments access privileges into distinct categories based on operating system modality characteristics. The hypervisor divides resource access rights into different levels, granting specific privileges to virtual machines running formally verified real-time operating systems while restricting access for those running unverified non-real-time operating systems, thereby segmenting the previously unified access model into security-differentiated segments.
2Object-affected harmful factors
If access privileges are restricted based on operating system modalities, then security is improved, but device complexity increases
Solution Approach 1:
The system employs self-service mechanisms where virtual machines automatically declare their operating system modality characteristics to the hypervisor. The hypervisor then automatically assigns appropriate access privileges based on pre-configured security policies for different modalities, eliminating the need for manual access control configuration and reducing operational complexity despite the differentiated security model.
Solution Approach 2:
The patent changes the parameter of access privileges from a static uniform setting to a dynamic modality-based setting. The hypervisor modifies access control parameters automatically based on the detected operating system modality of each virtual machine, allowing security restrictions to be applied through parameter changes rather than complex structural modifications to the virtualization architecture.
Data Source
AI summary
Device security across multiple operating system modalities, including: allocating, by a hypervisor, to a first virtual machine comprising a first operating system, based on the first modality, a first one or more access privileges to one or more resources; allocating, by the hypervisor, to a second virtual machine comprising a second operating system, based on the second modality, a second one or more access privileges to the one or more resources; and modifying, by the hypervisor, the second one or more access privileges in response to a change in an execution state of the first virtual machine.


