Memory Logging and Remediation Logic for Region Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant, virtualized computing applications, preventing unauthorized access to restricted memory regions is challenging, often requiring the shutdown of entire servers, which is inefficient and costly.
Innovation Solution
Integration of remediation and logging logic within memory devices to isolate compromised memory regions and provide real-time security measures, using hypervisor data and memory-specific information to manage data allocation and quarantine faulty areas.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the entire server is taken offline to resolve a security breach, then security is improved, but productivity and resource utilization deteriorate
Solution Approach 1:
The patent divides the memory system into multiple independent memory regions, each with its own security context. When a security breach is detected in one region, only that specific region is isolated rather than the entire server. This segmentation allows other memory regions to continue operating normally, maintaining productivity while addressing security concerns in the affected region.
Solution Approach 2:
The patent implements local security measures by associating specific security protocols and access controls with individual memory regions rather than applying uniform security across the entire server. This allows differentiated security responses where compromised regions can be isolated with targeted remediation while non-compromised regions maintain normal access and operation.
2Reliability
If the entire memory device is restricted by the hypervisor, then security is improved, but productivity deteriorates due to loss of memory resources
Solution Approach 1:
The patent segments the memory device into multiple addressable regions with independent security attributes. The hypervisor can apply access restrictions to specific regions rather than the entire memory device, allowing un compromised regions to remain accessible to virtual machines and maintain productivity while secured regions are protected.
Solution Approach 2:
The patent introduces a new dimension of memory management by adding region-specific security attributes and access control layers. This allows the hypervisor to manage memory security in a granular manner, controlling access to specific memory regions without affecting the availability of other regions, thus resolving the contradiction between security and resource utilization.
3Reliability
If memory-specific security information is not available to the hypervisor, then device complexity is reduced, but reliability deteriorates due to inability to implement targeted security measures
Solution Approach 1:
The patent merges the security information storage and management functions directly into the memory device structure. Security attributes, access controls, and region identification information are integrated with the memory regions themselves, allowing the hypervisor to obtain memory-specific security information without adding separate complex external security subsystems.
Solution Approach 2:
The memory device is designed to self-manage its own security information, maintaining region attributes and security contexts internally. This self-service capability allows the memory device to provide its own security information to the hypervisor without requiring complex external security management infrastructure, balancing reliability with manageable complexity.
Data Source
AI summary
A system includes a memory comprising a memory cell array configured to store data and a logging logic circuit configured to generate a log of detected faults or attacks on the memory cell array, and a host hosting a hypervisor. The hypervisor is configured to host a virtual machine, including managing data allocation for processes of the virtual machine to a first region of the memory cell array. The hypervisor is further configured to receive the log of detected faults or attacks? generated by the logging logic circuit. In response to a determination that the first region of the memory cell array has a detected fault or attack based on the log of detected faults or attacks, re-direct data allocation for the virtual machine to a second region of the memory cell array.


