Virtualization Partitioning for Hardware Resource Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in consolidating multiple execution environments on a single data processing system, leading to complex hardware designs, high costs, and security vulnerabilities, particularly in embedded systems and network infrastructure, where legacy real-time operating systems struggle to adapt to modern hardware and are susceptible to malware attacks.
Innovation Solution
A real-time virtualization technology that partitions hardware resources among execution environments, allowing multiple independent environments to run on a single-core or multi-core processor, with efficient communication mechanisms, and isolates trusted and untrusted domains using virtualization and isolator modules to manage access to shared devices and resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If multiple execution environments are consolidated on a single data processing system, then device complexity and cost are reduced, but security isolation between trusted and untrusted domains becomes compromised
Solution Approach 1:
The system segments the execution environments into distinct virtual machines, each with isolated memory spaces and protected execution contexts. This allows multiple environments to coexist on a single processor while maintaining security boundaries through software-based partitioning rather than requiring separate physical hardware for each environment.
Solution Approach 2:
A virtualization layer acts as an intermediary between the physical hardware and multiple execution environments. This mediator manages resource allocation, enforces security policies, and provides controlled access to shared devices, ensuring that untrusted environments cannot directly compromise trusted domain operations while sharing the same physical infrastructure.
2Reliability
If dedicated hardware is provided for each execution environment, then security isolation and real-time performance are guaranteed, but device complexity, cost, and power consumption increase
Solution Approach 1:
The system merges multiple execution environments onto a single data processing system by implementing virtualization technology. This consolidation allows trusted and untrusted domains to share the same physical processor and hardware resources while maintaining logical isolation through software mechanisms, thereby reducing hardware complexity and cost without sacrificing security guarantees.
Solution Approach 2:
A single data processing system is designed to universally support multiple execution environments through virtualization. The system can dynamically allocate resources to different virtual machines and adjust isolation levels based on trust requirements, enabling one hardware platform to serve multiple functions and environments that traditionally would have required separate dedicated systems.
3Adaptability or versatility
If legacy real-time operating systems are adapted to modern hardware, then compatibility with modern systems is improved, but security vulnerabilities to malware attacks increase
Solution Approach 1:
The system implements a nested structure where legacy real-time operating systems run within virtualized containers that are themselves managed by a more secure host environment. This nesting allows legacy systems to maintain compatibility with modern hardware while being protected by outer layers of security enforcement and isolation mechanisms that prevent malware from compromising the underlying trusted domain.
Data Source
AI summary
According to the present invention, there is provided a data processing system comprising: a dedicated physical device for access by a single client only; a shared physical device for shared access by multiple clients; a partition of a first type associated with the dedicated physical device, the first type partition comprising said single client and a first device driver for accessing the dedicated physical device; a partition of a second type associated with the shared physical device, the second type partition comprising a second device driver for accessing the shared physical device, and a back end driver for accessing the second device driver; and multiple partitions of the third type each comprising a respective one of said multiple clients and a front end driver for accessing the shared physical device via the second type partition. There is also provided a method of operating the data processing system comprising: executing a user application in the standard domain; and executing in the trusted domain, one or more predetermined operations, services and/or functions relating to the user application.


