Kernel Virtual Machine Isolation for Xen Domain-0 Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments using Xen virtualization, the security of domain-0 is compromised due to vulnerabilities, leading to poor communication performance and resource inefficiency between service components, as existing methods either deteriorate communication performance or provide low security by isolating service components into different virtual machines.

Innovation Solution

An isolation method for management virtual machines that involves acquiring a guest identifier, searching for and creating a kernel virtual machine, dividing services into multiple components with different permissions, and running them in execution environments corresponding to those permissions, enabling longitudinal and lateral isolation within the same management virtual machine.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service components are isolated into different virtual machines, then security of domain-0 is improved, but communication performance deteriorates and resource consumption increases

Engineering Contradiction:
Improvesecurity of domain-0VSAvoidcommunication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments service components into different permission levels (privileged and unprivileged) and runs them in separate execution environments within the same management virtual machine. This segmentation provides security isolation without requiring separate virtual machines, thus maintaining communication performance while improving security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different permission levels to different service components based on their security requirements. Privileged service components run in execution environments with higher permissions, while unprivileged components run with restricted permissions. This local quality approach ensures that only necessary components have elevated privileges, improving security without affecting overall communication performance.

Inventive Principle:
Principle #3Local quality

2Reliability

If service components are isolated into different virtual machines, then security of domain-0 is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity of domain-0VSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple execution environments with different permission levels into a single management virtual machine. This allows service components to be isolated for security purposes while sharing the underlying virtual machine resources, thereby improving security without proportionally increasing resource consumption as would occur with separate virtual machines.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a nested structure where execution environments with different permission levels are nested within the management virtual machine. This nested architecture provides multiple layers of isolation (execution environment level and virtual machine level) while consolidating resources at the virtual machine level, reducing overall resource consumption compared to fully separate virtual machines.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If service components run with high permission, then functionality is improved, but security risk increases

Engineering Contradiction:
Improvefunctionality of service componentsVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent assigns different permission levels locally to different service components based on their functional requirements. Privileged service components that require high functionality run in execution environments with higher permissions, while unprivileged components run with restricted permissions. This ensures that security risk is localized to only those components that absolutely require elevated privileges.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments service components into privileged and unprivileged categories, with each segment running in execution environments with appropriate permission levels. This segmentation allows components to have the functionality they need while limiting the security risk exposure to only the necessary segments, rather than elevating permissions system-wide.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9971623B2Isolation method for management virtual machine and apparatus
Publication Date: 2018.05.15 HUAWEI TECH CO LTD
  • US9971623B2 patent drawing
  • US9971623B2 patent drawing
  • US9971623B2 patent drawing

AI summary

An isolation method for a management virtual machine and an apparatus, which resolves problems that performance of communication between service components is deteriorated, more resources are required for running a virtual machine, and security of the service components is relatively low. The method includes: acquiring a guest identifier; searching, according to the guest identifier, the management virtual machine for a kernel virtual machine; when the kernel virtual machine is not found in the management virtual machine, creating the kernel virtual machine in the management virtual machine; dividing a service provided for a guest virtual machine by the kernel virtual machine into multiple service components; and running the multiple service components in execution environments corresponding to permission of the service components, where the kernel virtual machine includes the multiple execution environments, and the multiple execution environment have different permission.