Secure VM Communication Control for Protected Memory Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face challenges in ensuring that anomaly detection results can be output to the outside, particularly in environments where virtualization software or device drivers are vulnerable to malicious attacks, which can prevent proper processing and lead to safety issues in systems like in-vehicle infotainment and advanced driver-assistance systems.

Innovation Solution

An information processing apparatus with a processor that operates in multiple modes, allowing access to protected and unprotected memory regions, includes controllers to manage virtual machines and communication, and a secure monitor to determine anomalies, ensuring that monitoring results can be securely transmitted to external apparatuses even if the communication path is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtualization software is used to operate multiple virtual machines on a single apparatus, then resource utilization is improved, but security against malicious attacks deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The memory is segmented into a protected region and an unprotected region. The protected region stores communication control data that is isolated from virtual machines and hypervisor, while the unprotected region is accessible by them. This segmentation prevents malicious code in virtual machines or hypervisor from accessing or corrupting critical communication control data, thus maintaining security while enabling virtualization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A dedicated protected region acts as an intermediary storage area between the communication device and the virtualization software. The first controller reads communication control data from this protected region to establish communication, ensuring that even if the hypervisor or virtual machines are compromised, the communication control data remains secure and accessible only through the protected interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the processor operates in a single mode with full memory access, then ease of operation is improved, but system security deteriorates

Engineering Contradiction:
Improvememory accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The processor dynamically switches between a first mode (with full memory access) and a second mode (with restricted memory access). In the first mode, the processor can access both protected and unprotected regions for general operations. In the second mode, access to the protected region is prohibited while unprotected region access remains allowed. This dynamic mode switching enables flexible operation while maintaining security boundaries when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12116002B2Information processing apparatus, information processing method, and recording medium
Publication Date: 2024.10.15 PANASONIC AUTOMOTIVE SYST CO LTD
  • US12116002B2 patent drawing
  • US12116002B2 patent drawing
  • US12116002B2 patent drawing

AI summary

An information processing apparatus includes: a communication device that communicates with an external apparatus outside the information processing apparatus; a memory that includes a protected region and an unprotected region; a processor that operates in a first mode and a second mode, the first mode being a mode in which access to the protected region and access to the unprotected region are allowed, the second mode being a mode in which access to the protected region is prohibited and access to the unprotected region is allowed; a first device controller that controls the communication device by the processor operating in the first mode; a virtual machine manager that causes one or more virtual machines to operate by the processor operating in the second mode; and a second device controller that controls the communication device by the processor operating in the second mode.