Secure Interface Control for Cloud Storage Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud computing environments face challenges in ensuring secure storage isolation between virtual machines and hypervisors, particularly in multi-tenant data centers where data from multiple customers is stored on the same server, requiring effective security measures to prevent unauthorized access and breaches.
Innovation Solution
A secure interface control mechanism is implemented, which uses firmware and hardware to manage and isolate storage, allowing the hypervisor to query and donate storage based on predetermined values, ensuring secure storage areas are marked and registered, and only accessible by authorized secure entities, preventing access by non-secure entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If storage is donated to secure interface control for secure entities, then security isolation is improved, but storage resource availability for non-secure entities deteriorates
Solution Approach 1:
The storage system is segmented into secure and non-secure portions through the secure interface control mechanism. The hypervisor queries the secure interface control to determine the amount of storage needed for secure entities, then donates only that specific amount, leaving the remainder available for non-secure entities. This segmentation resolves the contradiction by creating distinct storage domains with appropriate access controls.
Solution Approach 2:
The secure interface control acts as an intermediary between the hypervisor and storage resources. It receives queries from the hypervisor about storage requirements, calculates the needed amount based on secure entity configurations, and manages the donation process. This intermediary mechanism ensures that storage is allocated securely while maintaining availability for non-secure uses.
2Measurement precision
If granular control over storage allocation is implemented, then security precision is improved, but system complexity deteriorates
Solution Approach 1:
The secure interface control autonomously determines the amount of storage needed by querying the hypervisor and calculating requirements based on secure entity configurations. The system self-manages the storage donation process without requiring manual intervention or complex external coordination, achieving granular control while limiting complexity growth.
Solution Approach 2:
The hypervisor queries the secure interface control to obtain feedback about storage requirements. Based on this feedback, the hypervisor donates the appropriate amount of storage. This feedback loop enables precise storage allocation matched to actual secure entity needs, avoiding both over-allocation and under-allocation.
3Loss of energy
If storage donation is minimized, then resource efficiency is improved, but security coverage deteriorates
Solution Approach 1:
The storage donation amount is dynamic rather than fixed. The secure interface control determines the needed amount based on the number and configuration of secure entities. As secure entities are added or removed, the donated storage automatically adjusts, ensuring adequate security coverage while minimizing excess allocation.
Solution Approach 2:
The system changes the storage allocation parameter dynamically based on secure entity configurations. The secure interface control calculates the required storage based on parameters such as the number of secure domains and their specific requirements, adjusting the donation amount to match actual security needs without providing unnecessary excess.
Data Source
AI summary
According to one or more embodiments of the present invention, a computer implemented method includes receiving a query for an amount of storage in memory of a computer system to be donated to a secure interface control of the computer system. The secure interface control can determine the amount of storage to be donated based on a plurality of secure entities supported by the secure interface control as a plurality of predetermined values. The secure interface control can return a response to the query indicative of the amount of storage as a response to the query. A donation of storage to secure for use by the secure interface control can be received based on the response to the query.


