Ultravisor Secure Memory Isolation for Cloud VMs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud Service Providers manage customer applications with software that has complete control over data, leading to security vulnerabilities as operating systems and hypervisors can tamper with customer data without detection, requiring customers to trust the security of CSP-managed software against attacks compromising confidentiality and integrity.

Innovation Solution

Implementing a Secure Memory Facility (SMF) in hardware and firmware as an ultravisor, which provides independent protection for Virtual Machines (VMs) by restricting access to secure memory, even from privileged attackers like malicious hypervisors, and ensuring secure data handling through encryption and secure state management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based security control is used in cloud computing environments, then ease of operation and management is improved, but security reliability deteriorates due to potential tampering by operating systems and hypervisors

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments memory into secure memory regions and non-secure memory regions, with the ultravisor specifically protecting secure memory from access by the hypervisor and customer applications. This segmentation allows the system to maintain software-based ease of operation while improving security reliability through hardware-enforced memory isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an ultravisor as an intermediary layer between the hypervisor and secure memory. The ultravisor acts as a hardware-based mediator that selectively grants or denies access to secure memory, preventing the hypervisor from tampering with secure data while maintaining the overall software-based operation model.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If complete control over customer data is given to CSP-managed software, then ease of operation is improved, but security reliability deteriorates due to undetected tampering

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments memory into secure memory regions and non-secure memory regions, with the ultravisor specifically protecting secure memory from access by the hypervisor and customer applications. This segmentation allows the system to maintain software-based ease of operation while improving security reliability through hardware-enforced memory isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an ultravisor as an intermediary layer between the hypervisor and secure memory. The ultravisor acts as a hardware-based mediator that selectively grants or denies access to secure memory, preventing the hypervisor from tampering with secure data while maintaining the overall software-based operation model.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware-based isolation is implemented through ultravisor, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service through automatic context switching between hypervisor mode and ultravisor mode. The processor automatically switches to ultravisor mode when executing instructions from secure memory sections and returns to hypervisor mode otherwise, eliminating the need for complex manual mode management while maintaining hardware-based security isolation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces complex software-based security management mechanisms with hardware-based ultravisor mechanisms. The processor's instruction execution automatically triggers mode switching based on the memory section being executed, substituting complex software security controls with simpler hardware-enforced isolation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If secure memory access is restricted to ultravisor only, then security reliability is improved, but productivity deteriorates due to limited access

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service through automatic context switching between hypervisor mode and ultravisor mode. The processor automatically switches to ultravisor mode when executing instructions from secure memory sections and returns to hypervisor mode otherwise, eliminating the need for complex manual mode management while maintaining hardware-based security isolation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10387686B2Hardware based isolation for secure execution of virtual machines
Publication Date: 2019.08.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10387686B2 patent drawing
  • US10387686B2 patent drawing
  • US10387686B2 patent drawing

AI summary

Hardware based isolation for secure execution of virtual machines (VMs). At least one virtual machine is executed via operation of a hypervisor and an ultravisor. A first memory component is configured for access by the hypervisor and the ultravisor, and a second memory component is configured for access by the ultravisor and not by the hypervisor. A first mode of operation is operated, such that the virtual machine is executed using the hypervisor, wherein the first memory component is accessible to the virtual machine and the second memory component is not accessible to the virtual machine. A second mode of operation is operated, such that the virtual machine is executed using the ultravisor, wherein the first memory component and the second memory component are accessible to the virtual machine, thereby executing application code and operating system code using the second memory component without code changes.