Secure Interface Control for Cloud Storage Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face challenges in ensuring secure storage isolation between virtual machines and hypervisors, particularly in multi-tenant data centers where data from multiple customers is stored on the same server, requiring effective security measures to prevent unauthorized access and breaches.

Innovation Solution

A secure interface control mechanism is implemented, which uses firmware and hardware to manage and isolate storage, allowing the hypervisor to query and donate storage based on predetermined values, ensuring secure storage areas are marked and registered, and only accessible by authorized secure entities, preventing access by non-secure entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If storage is donated to secure interface control for secure entities, then security isolation is improved, but storage resource availability for non-secure entities deteriorates

Engineering Contradiction:
Improvesecurity isolationVSAvoidstorage resource availability
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The storage system is segmented into secure and non-secure portions through the secure interface control mechanism. The hypervisor queries the secure interface control to determine the amount of storage needed for secure entities, then donates only that specific amount, leaving the remainder available for non-secure entities. This segmentation resolves the contradiction by creating distinct storage domains with appropriate access controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure interface control acts as an intermediary between the hypervisor and storage resources. It receives queries from the hypervisor about storage requirements, calculates the needed amount based on secure entity configurations, and manages the donation process. This intermediary mechanism ensures that storage is allocated securely while maintaining availability for non-secure uses.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If granular control over storage allocation is implemented, then security precision is improved, but system complexity deteriorates

Engineering Contradiction:
Improvestorage allocation precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The secure interface control autonomously determines the amount of storage needed by querying the hypervisor and calculating requirements based on secure entity configurations. The system self-manages the storage donation process without requiring manual intervention or complex external coordination, achieving granular control while limiting complexity growth.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The hypervisor queries the secure interface control to obtain feedback about storage requirements. Based on this feedback, the hypervisor donates the appropriate amount of storage. This feedback loop enables precise storage allocation matched to actual secure entity needs, avoiding both over-allocation and under-allocation.

Inventive Principle:
Principle #23Feedback

3Loss of energy

If storage donation is minimized, then resource efficiency is improved, but security coverage deteriorates

Engineering Contradiction:
Improvestorage resource efficiencyVSAvoidsecurity coverage
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The storage donation amount is dynamic rather than fixed. The secure interface control determines the needed amount based on the number and configuration of secure entities. As secure entities are added or removed, the donated storage automatically adjusts, ensuring adequate security coverage while minimizing excess allocation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the storage allocation parameter dynamically based on secure entity configurations. The secure interface control calculates the required storage based on parameters such as the number of secure domains and their specific requirements, adjusting the donation amount to match actual security needs without providing unnecessary excess.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11635991B2Secure storage query and donation
Publication Date: 2023.04.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11635991B2 patent drawing
  • US11635991B2 patent drawing
  • US11635991B2 patent drawing

AI summary

According to one or more embodiments of the present invention, a computer implemented method includes receiving a query for an amount of storage in memory of a computer system to be donated to a secure interface control of the computer system. The secure interface control can determine the amount of storage to be donated based on a plurality of secure entities supported by the secure interface control as a plurality of predetermined values. The secure interface control can return a response to the query indicative of the amount of storage as a response to the query. A donation of storage to secure for use by the secure interface control can be received based on the response to the query.