Hypervisor-Trusted Client for Secure VM Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualization environments, there is a need to securely manage and isolate sensitive information, particularly in scenarios where employees access both personal and work-related data on the same computing device, without compromising security by preventing unauthorized access between trusted and non-trusted virtual machines.

Innovation Solution

A method and system utilizing a hypervisor-trusted client to manage input data injection, where a control virtual machine launches a client agent, assigns a secure memory section for graphical data, and directs input data based on focus windows, ensuring that sensitive information is protected from non-trusted virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single computing device is used to access both personal and work-related data, then convenience and accessibility are improved, but security and data isolation are compromised

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The computing device is segmented into multiple virtual machines (work-related VM and personal VM) that operate independently. Each VM is assigned specific resources and access permissions, allowing employees to access both personal and work data on the same physical device while maintaining security isolation through the hypervisor layer.

Inventive Principle:
Principle #1Segmentation

2Reliability

If virtual machines are isolated to prevent unauthorized access, then security is improved, but resource sharing and communication between VMs are restricted

Engineering Contradiction:
ImprovesecurityVSAvoidresource sharing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The hypervisor acts as an intermediary layer between virtual machines and the physical hardware resources. It enables controlled resource sharing and communication between isolated VMs by managing resource allocation and enforcing access policies, allowing secure collaboration while maintaining isolation boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If sensitive information is stored in a secure section of graphics processing unit memory, then data protection is improved, but access complexity and system complexity increase

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Sensitive graphical data is extracted from the general graphics memory and placed into a dedicated secure section of the graphics processing unit memory. This separation ensures that even if the main graphics memory is compromised, sensitive information remains protected in the isolated secure section with controlled access.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9804866B2Methods and systems for securing sensitive information using a hypervisor-trusted client
Publication Date: 2017.10.31 CITRIX SYSTEMS INC
  • US9804866B2 patent drawing
  • US9804866B2 patent drawing
  • US9804866B2 patent drawing

AI summary

The methods and systems described herein provide for securing sensitive information using a hypervisor-trusted client, in a computing device executing a hypervisor hosting a control virtual machine and a non-trusted virtual machine. A user of a non-trusted virtual machine requests to establish a connection to a remote computing device. Responsive to the request, a control virtual machine launches a client agent. A graphics manager executed by the processor of the computing device assigns a secure section of a memory of a graphics processing unit of the computing device to the client agent. The graphics manager renders graphical data generated by the client agent to the secure section of the graphics processing unit memory.