Reserving Security Modules for Secure Guest Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing environments, secure guests rely on hardware security modules for protection, but existing systems lack mechanisms to ensure exclusive access and integrity of these modules, particularly when hypervisors are not fully trustworthy, leading to potential misconfiguration and unauthorized access.

Innovation Solution

A method to reserve hardware security modules, such as crypto adapters, exclusively for secure guests by managing queues and reservations through trusted firmware, ensuring that the module is not reassigned or accessed by other guests during the secure guest's lifetime, and maintaining cryptographic key integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a hypervisor is used to manage multiple guests, then resource utilization and virtualization efficiency are improved, but security and integrity protection of secure guests deteriorate when the hypervisor is not fully trustworthy

Engineering Contradiction:
Improvevirtualization efficiencyVSAvoidsecurity integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a security module as an intermediary between the hypervisor and secure guests. This security module acts as a trusted mediator that protects secure guest operations from potential hypervisor interference, allowing virtualization to continue while adding a layer of security that doesn't compromise the hypervisor's resource management capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system into distinct trust zones: the hypervisor manages resources but cannot access secure guest memory directly, while a security module handles cryptographic operations. This segmentation isolates the secure guest from potential hypervisor attacks while maintaining the hypervisor's productivity benefits

Inventive Principle:
Principle #1Segmentation

2Productivity

If hardware security modules are shared among multiple guests, then resource utilization is improved, but security and exclusivity for secure guests deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidexclusive access
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic allocation of security modules to secure guests based on operational needs. The security module can be reserved for a specific secure guest during critical operations and released when not needed, allowing flexible resource utilization while maintaining exclusivity when required for security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent reserves security modules in advance for secure guests before they need them. This preliminary reservation ensures exclusive access is guaranteed when the secure guest needs cryptographic operations, while allowing the module to be shared with other non-secure guests during idle periods

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11475167B2Reserving one or more security modules for a secure guest
Publication Date: 2022.10.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11475167B2 patent drawing
  • US11475167B2 patent drawing
  • US11475167B2 patent drawing

AI summary

A security module, such as a cryptographic adapter, is reserved for a secure guest of a computing environment. The reserving includes binding one or more queues of the security module to the secure guest. The one or more queues are then managed based on one or more actions relating to the reservation.