Virtualization Information Memory Scrubbing for VM Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization technologies fail to ensure secure access to virtualization information when a virtual machine instance is terminated or migrated, as they do not adequately protect data in de-allocated memory regions from unauthorized access, particularly in collaborative computing environments where security risks are heightened.
Innovation Solution
Implementing logic within the computer platform to detect a close event for a virtual machine instance and write over virtualization information in the allocated memory region before it is made available for re-allocation, using circuit logic that operates with memory allocation repositories like RVI or EPT, independent of specific software requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If memory regions are rapidly re-allocated after VM instance termination to improve resource utilization, then productivity increases, but security deteriorates because sensitive virtualization information remains exposed in de-allocated memory
Solution Approach 1:
The patent applies preliminary action by detecting VM instance close events and proactively writing over sensitive virtualization information in de-allocated memory regions before they can be re-allocated to new VM instances. This advance scrubbing operation ensures that memory regions are secured prior to re-use, resolving the contradiction between rapid resource re-utilization and security protection.
2Ease of operation
If software-based memory management is used to track and clear memory regions, then ease of operation is maintained, but reliability decreases due to potential software failures and delays in memory security
Solution Approach 1:
The patent replaces software-based memory management with hardware-based circuit logic that automatically detects VM instance close events and writes over sensitive information in memory. This hardware implementation eliminates software failures and delays, providing deterministic and reliable memory security while maintaining ease of operation through automatic hardware-enforced memory scrubbing.
Solution Approach 2:
The circuit logic autonomously detects VM instance termination events and performs memory scrubbing operations without requiring software intervention. The hardware system self-manages the security-critical task of clearing sensitive information from de-allocated memory regions, ensuring reliable and timely security enforcement independent of software state.
3Reliability
If all memory regions are continuously monitored and scrubbed to ensure maximum security, then reliability improves, but use of energy increases due to continuous security operations
Solution Approach 1:
The patent implements periodic action by triggering memory scrubbing operations only at specific events - namely when VM instances are terminated or migrated. Rather than continuously monitoring and scrubbing all memory regions, the system performs security operations periodically at relevant transition points, reducing energy consumption while maintaining security reliability through event-driven memory protection.
Data Source
AI summary
Techniques for limiting access to virtualization information which is stored in a memory region allocated to a virtual machine instance. In an embodiment, virtualization information is written over in response to an indication of a close event which is to change an allocation of the memory region to the virtual machine instance. In another embodiment, the virtualization information is written over before the memory region is made available for a subsequent allocation.


