Virtualization Partitioning for Hardware Resource Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies face challenges in consolidating multiple execution environments on a single data processing system, leading to complex hardware designs, high costs, and security vulnerabilities, particularly in embedded systems and network infrastructure, where legacy real-time operating systems struggle to adapt to modern hardware and are susceptible to malware attacks.

Innovation Solution

A real-time virtualization technology that partitions hardware resources among execution environments, allowing multiple independent environments to run on a single-core or multi-core processor, with efficient communication mechanisms, and isolates trusted and untrusted domains using virtualization and isolator modules to manage access to shared devices and resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If multiple execution environments are consolidated on a single data processing system, then device complexity and cost are reduced, but security isolation between trusted and untrusted domains becomes compromised

Engineering Contradiction:
Improvehardware design complexityVSAvoidsecurity isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system segments the execution environments into distinct virtual machines, each with isolated memory spaces and protected execution contexts. This allows multiple environments to coexist on a single processor while maintaining security boundaries through software-based partitioning rather than requiring separate physical hardware for each environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A virtualization layer acts as an intermediary between the physical hardware and multiple execution environments. This mediator manages resource allocation, enforces security policies, and provides controlled access to shared devices, ensuring that untrusted environments cannot directly compromise trusted domain operations while sharing the same physical infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated hardware is provided for each execution environment, then security isolation and real-time performance are guaranteed, but device complexity, cost, and power consumption increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidhardware design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple execution environments onto a single data processing system by implementing virtualization technology. This consolidation allows trusted and untrusted domains to share the same physical processor and hardware resources while maintaining logical isolation through software mechanisms, thereby reducing hardware complexity and cost without sacrificing security guarantees.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

A single data processing system is designed to universally support multiple execution environments through virtualization. The system can dynamically allocate resources to different virtual machines and adjust isolation levels based on trust requirements, enabling one hardware platform to serve multiple functions and environments that traditionally would have required separate dedicated systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If legacy real-time operating systems are adapted to modern hardware, then compatibility with modern systems is improved, but security vulnerabilities to malware attacks increase

Engineering Contradiction:
Improvehardware compatibilityVSAvoidmalware attack susceptibility
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements a nested structure where legacy real-time operating systems run within virtualized containers that are themselves managed by a more secure host environment. This nesting allows legacy systems to maintain compatibility with modern hardware while being protected by outer layers of security enforcement and isolation mechanisms that prevent malware from compromising the underlying trusted domain.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8996864B2System for enabling multiple execution environments to share a device
Publication Date: 2015.03.31 VIRTUALLOGIX
  • US8996864B2 patent drawing
  • US8996864B2 patent drawing
  • US8996864B2 patent drawing

AI summary

According to the present invention, there is provided a data processing system comprising: a dedicated physical device for access by a single client only; a shared physical device for shared access by multiple clients; a partition of a first type associated with the dedicated physical device, the first type partition comprising said single client and a first device driver for accessing the dedicated physical device; a partition of a second type associated with the shared physical device, the second type partition comprising a second device driver for accessing the shared physical device, and a back end driver for accessing the second device driver; and multiple partitions of the third type each comprising a respective one of said multiple clients and a front end driver for accessing the shared physical device via the second type partition. There is also provided a method of operating the data processing system comprising: executing a user application in the standard domain; and executing in the trusted domain, one or more predetermined operations, services and/or functions relating to the user application.