I/O Proxy Device for Secure Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale data centers face complexities in provisioning, administering, and managing physical computing resources due to increased scale and scope, and existing virtualization technologies do not adequately address security and resource management issues within computer systems.

Innovation Solution

An I/O proxy device is interposed between hardware processing elements and data storage devices, enabling the application of customizable I/O filters to perform actions on I/O messages, such as encryption, format conversion, and security filtering, independent of other hardware and software components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization technologies are used to share computing resources among multiple customers, then resource utilization efficiency is improved, but security and isolation between customers deteriorate

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity and isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

An I/O proxy device is introduced as an intermediary component between hardware processing elements and data storage devices. This proxy device intercepts and filters I/O messages, applying security policies and filtering rules to prevent unauthorized access and ensure proper isolation between virtual machines while maintaining efficient resource sharing. The proxy acts as a mediator that enforces security boundaries without preventing legitimate resource utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If I/O filtering is implemented to enhance security, then security against undesirable operations is improved, but I/O message processing time increases

Engineering Contradiction:
Improvesecurity against undesirable operationsVSAvoidI/O message processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Filtering rules and security policies are pre-configured in the I/O proxy device before I/O operations occur. The proxy device is pre-programmed with patterns for identifying undesirable operations, allowing it to quickly match and filter I/O messages without requiring complex real-time analysis. This preliminary configuration reduces processing time during actual I/O operations while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If an I/O proxy device is interposed between hardware processing elements and data storage devices, then security filtering capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity filtering capabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The I/O proxy device is designed to perform multiple functions within a single component: it acts as an I/O message router, a security filter, a policy enforcement point, and a communication intermediary. By consolidating these functions into one universal device, the overall system complexity is managed more effectively than if separate components were used for each function, while still providing comprehensive security filtering capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11216391B1Using an I/O proxy device to filter I/O messages in a computer system
Publication Date: 2022.01.04 AMAZON TECH INC
  • US11216391B1 patent drawing
  • US11216391B1 patent drawing
  • US11216391B1 patent drawing

AI summary

Techniques are described for the creation and use of input/output (I/O) filters used to perform actions relative to I/O requests passing through an I/O proxy device of a computer system. A computer system includes one or more hardware processing elements (for example, one or more central processing units (CPUs), graphics processing units (GPUs), or other types of processing elements), one or more data storage devices (for example, hard-disk drives, solid-state drives (SSDs), network-accessible block storage devices, and so forth), and an I/O proxy device that is interposed between at least one of the hardware processing elements and at least one of the one or more data storage devices. The interposition of an I/O proxy device between hardware processing elements and data storage devices enables the I/O proxy device to participate in the I/O data path, for example, to receive I/O messages and to perform various actions relative to such messages.