Virtualized Trusted Descriptors for Secure Resource Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems lack effective mechanisms to securely manage and isolate access to sensitive resources among multiple security domains in virtualized environments, leading to potential unauthorized access to secret keys and other sensitive information.
Innovation Solution
The implementation of virtualized trusted descriptors, which are digitally signed with a security domain identifier, allowing only authorized operating systems to access specific resources, thereby separating and securing access to different security domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple security domains share access to cryptographic resources in a virtualized environment, then resource utilization efficiency is improved, but security isolation is compromised and unauthorized access to secret keys becomes possible
Solution Approach 1:
The patent segments cryptographic resources by introducing security domain identifiers that partition access to cryptographic operations. Each security domain is assigned unique identifiers that restrict which descriptors can access which cryptographic resources, thereby maintaining security isolation while allowing multiple domains to utilize the same physical cryptographic hardware simultaneously.
Solution Approach 2:
The patent introduces security domain identifiers as an intermediary mechanism between multiple security domains and cryptographic resources. These identifiers act as mediators that control and regulate access, ensuring that each domain can only access resources authorized for its security level, thus enabling secure shared access without compromising isolation.
2Adaptability or versatility
If trusted descriptors are made accessible to multiple operating systems, then system versatility is improved, but access control is weakened and unauthorized access to sensitive information becomes possible
Solution Approach 1:
The patent applies local quality by associating specific security domain identifiers with specific descriptors and cryptographic resources. Each descriptor is tagged with security domain information that determines its accessible resource set, creating localized access control policies that enable versatile system operation while maintaining precise access control boundaries.
Solution Approach 2:
The patent changes the access control parameter by incorporating security domain identifiers into the descriptor structure itself. This parameter change transforms descriptors from generic execution units into security-aware entities that automatically enforce access control based on their embedded security domain information, thereby maintaining ease of operation while enhancing security.
3Productivity
If cryptographic resources are shared among multiple security domains, then resource efficiency is improved, but the complexity of managing security isolation increases
Solution Approach 1:
The patent achieves universality by designing a unified security domain identifier mechanism that handles access control for all cryptographic resources across all security domains. This single universal approach to security isolation management replaces multiple domain-specific control mechanisms, thereby reducing overall system complexity while enabling efficient resource sharing.
Data Source
AI summary
Embodiments of information processing systems and associated components can include logic operable to perform operations in a virtualized system including a plurality of guest operating systems using descriptors. The descriptors specify a set of commands defining the operations in a plurality of security domains and specify permission to a plurality of resources selectively for the plurality of guest operating systems.


