Secure VM Communication Control for Protected Memory Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization technologies face challenges in ensuring that anomaly detection results can be output to the outside, particularly in environments where virtualization software or device drivers are vulnerable to malicious attacks, which can prevent proper processing and lead to safety issues in systems like in-vehicle infotainment and advanced driver-assistance systems.
Innovation Solution
An information processing apparatus with a processor that operates in multiple modes, allowing access to protected and unprotected memory regions, includes controllers to manage virtual machines and communication, and a secure monitor to determine anomalies, ensuring that monitoring results can be securely transmitted to external apparatuses even if the communication path is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtualization software is used to operate multiple virtual machines on a single apparatus, then resource utilization is improved, but security against malicious attacks deteriorates
Solution Approach 1:
The memory is segmented into a protected region and an unprotected region. The protected region stores communication control data that is isolated from virtual machines and hypervisor, while the unprotected region is accessible by them. This segmentation prevents malicious code in virtual machines or hypervisor from accessing or corrupting critical communication control data, thus maintaining security while enabling virtualization.
Solution Approach 2:
A dedicated protected region acts as an intermediary storage area between the communication device and the virtualization software. The first controller reads communication control data from this protected region to establish communication, ensuring that even if the hypervisor or virtual machines are compromised, the communication control data remains secure and accessible only through the protected interface.
2Ease of operation
If the processor operates in a single mode with full memory access, then ease of operation is improved, but system security deteriorates
Solution Approach 1:
The processor dynamically switches between a first mode (with full memory access) and a second mode (with restricted memory access). In the first mode, the processor can access both protected and unprotected regions for general operations. In the second mode, access to the protected region is prohibited while unprotected region access remains allowed. This dynamic mode switching enables flexible operation while maintaining security boundaries when needed.
Data Source
AI summary
An information processing apparatus includes: a communication device that communicates with an external apparatus outside the information processing apparatus; a memory that includes a protected region and an unprotected region; a processor that operates in a first mode and a second mode, the first mode being a mode in which access to the protected region and access to the unprotected region are allowed, the second mode being a mode in which access to the protected region is prohibited and access to the unprotected region is allowed; a first device controller that controls the communication device by the processor operating in the first mode; a virtual machine manager that causes one or more virtual machines to operate by the processor operating in the second mode; and a second device controller that controls the communication device by the processor operating in the second mode.


