Hypervisor Secure Mode Virtualization Without Mode Transitions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing systems lack a secure virtualization environment that effectively prevents attacks and interference between secure and low-security domains, leading to reduced processing speed and security vulnerabilities during OS operations.

Innovation Solution

A system with a hypervisor operating in secure mode, which enables secure access to protected regions while prohibiting access to unprotected regions, allowing for virtualization without mode transitions, thereby maintaining security and processing speed by setting distinct operating conditions for each OS and providing virtualized access to shared devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the processing unit switches from low security mode to secure mode to virtualize operations, then security is improved, but processing speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the virtualization environment into two distinct modes: secure mode for the hypervisor and low security mode for guest OSes. This segmentation allows each component to operate in its optimal security level without requiring continuous mode switching, thereby maintaining both security and processing speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of operation by allowing the hypervisor to run in secure mode while guest OSes operate in low security mode within the same system. This dimensional separation enables virtualization without requiring mode transitions, resolving the contradiction between security and processing speed.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If the hypervisor runs in secure mode, then security against attacks is improved, but access to unprotected regions is restricted

Engineering Contradiction:
ImprovesecurityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The hypervisor acts as an intermediary between the secure mode environment and resources in both protected and unprotected regions. It manages access to unprotected regions on behalf of guest OSes, allowing secure operation while maintaining necessary access flexibility through controlled mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hypervisor running in secure mode provides universal access capabilities to both protected and unprotected regions, enabling a single secure environment to handle diverse access requirements without compromising security or flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If mode transitions are enabled for device access, then device sharing between OSes is improved, but processing speed drops due to frequent transitions

Engineering Contradiction:
Improvedevice sharingVSAvoidprocessing speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

Devices are segmented into shared devices and non-shared devices. Guest OSes in low security mode can access non-shared devices directly without mode transitions, while shared devices are accessed through controlled mechanisms. This segmentation reduces unnecessary mode transitions and maintains processing speed while enabling necessary device sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies mode transitions only partially - only when absolutely necessary for accessing shared devices from secure mode. For most operations in low security mode, the system avoids mode transitions entirely, thus minimizing speed drops while maintaining device sharing capabilities where required.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10902112B2System including a hypervisor
Publication Date: 2021.01.26 SEKISUI HOUSE KK
  • US10902112B2 patent drawing
  • US10902112B2 patent drawing
  • US10902112B2 patent drawing

AI summary

There is provided a system (1) comprising: a processing unit (11) equipped with execution modes including a non-secure mode (3) in which access to a protected region of a memory is prohibited by a support function (12) and a secure mode (2) in which access to the protected region is permitted; and a hypervisor (20) which runs in the secure mode. The hypervisor includes: a first setting unit (23) for setting a first operation condition (21), which includes enabling a first OS (30) running in the secure mode to access the protected region and the unprotected region of the memory; and a second setting unit (24) for setting a second operation condition (22a), which includes enabling a second OS (41) running in the non-secure mode to access the unprotected region, using the support function to prevent the second OS (41) from accessing the secure region, and enabling a transition to the secure mode by accessing of the second OS to a first device shared with the first OS.