Local Secure Service Partition for VM Security Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional operating systems face challenges in isolating critical trusted computing base (TCB) components from modification and ensuring their integrity, leading to security breaches and unpredictable behavior, especially in virtual machine (VM) environments.
Innovation Solution
Implementing an isolation kernel or hypervisor beneath the operating system to move specific service modules into isolated partitions within the VM environment, providing strict security isolation and certification using a TPM attestation identity key, thereby reducing the size of the trusted computing base and enhancing assurance levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If critical TCB components are kept within the operating system, then the system can provide security services, but the TCB becomes vulnerable to modification by attacking code
Solution Approach 1:
The patent divides the TCB into separate service partitions that are isolated from the main operating system. Critical security services are moved into dedicated partitions with their own address spaces, preventing attacking code in the OS from modifying them. This segmentation allows the system to maintain security assurance while protecting against harmful factors.
Solution Approach 2:
The patent introduces service partitions as intermediary environments between the operating system and critical TCB components. These partitions act as protected mediators that provide security services without being directly accessible to attacking code in the OS, thus resolving the vulnerability issue while maintaining reliability.
2Reliability
If service modules are moved into isolated partitions, then security isolation is improved, but system complexity increases
Solution Approach 1:
The patent implements segmentation by creating separate service partitions for different security services. Each partition is isolated with its own address space and execution environment. While this increases structural complexity, it provides the necessary security isolation through clear separation of critical components from the main OS.
Solution Approach 2:
The service partitions are designed to be universal containers that can host multiple different security services. This multi-functionality approach allows the same partition infrastructure to serve various TCB components, reducing the overall complexity compared to creating separate isolated environments for each service.
3Adaptability or versatility
If a large monolithic TCB is used, then comprehensive security services are provided, but the complexity of interfaces increases and breaches become more likely
Solution Approach 1:
The patent segments the monolithic TCB into distributed service partitions, each handling specific security functions. This maintains comprehensive security service coverage while reducing interface complexity within each partition, as each partition has a focused, simplified interface rather than dealing with the complexity of the entire TCB.
Solution Approach 2:
The patent moves security services from a single-dimensional monolithic structure to a multi-dimensional distributed partition architecture. This dimensional change allows comprehensive security coverage to be achieved through multiple independent partitions, each with simpler interfaces, rather than one complex monolithic interface.
Data Source
AI summary
Systems and methods provide multiple partitions hosted on an isolation technology such as a hypervisor where at least one of the partitions, a local secure service partition (LSSP), provides security services to other partitions. The service partitions (LSSPs) host those high assurance services that require strict security isolation, where the service can be shared across partitions and accessed even when the user is not connected to a network. The LSSP also can certify the results of any computation using a key signed by a TPM attestation identity key (AIK), or other key held securely by the hypervisor or a service partition. The LSSPs may be configured to provide trusted audit logs, trusted security scans, trusted cryptographic services, trusted compilation and testing, trusted logon services, and the like.


