Virtualization Information Memory Scrubbing for VM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies fail to ensure secure access to virtualization information when a virtual machine instance is terminated or migrated, as they do not adequately protect data in de-allocated memory regions from unauthorized access, particularly in collaborative computing environments where security risks are heightened.

Innovation Solution

Implementing logic within the computer platform to detect a close event for a virtual machine instance and write over virtualization information in the allocated memory region before it is made available for re-allocation, using circuit logic that operates with memory allocation repositories like RVI or EPT, independent of specific software requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If memory regions are rapidly re-allocated after VM instance termination to improve resource utilization, then productivity increases, but security deteriorates because sensitive virtualization information remains exposed in de-allocated memory

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by detecting VM instance close events and proactively writing over sensitive virtualization information in de-allocated memory regions before they can be re-allocated to new VM instances. This advance scrubbing operation ensures that memory regions are secured prior to re-use, resolving the contradiction between rapid resource re-utilization and security protection.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If software-based memory management is used to track and clear memory regions, then ease of operation is maintained, but reliability decreases due to potential software failures and delays in memory security

Engineering Contradiction:
Improvememory managementVSAvoidmemory security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based memory management with hardware-based circuit logic that automatically detects VM instance close events and writes over sensitive information in memory. This hardware implementation eliminates software failures and delays, providing deterministic and reliable memory security while maintaining ease of operation through automatic hardware-enforced memory scrubbing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The circuit logic autonomously detects VM instance termination events and performs memory scrubbing operations without requiring software intervention. The hardware system self-manages the security-critical task of clearing sensitive information from de-allocated memory regions, ensuring reliable and timely security enforcement independent of software state.

Inventive Principle:
Principle #25Self-service

3Reliability

If all memory regions are continuously monitored and scrubbed to ensure maximum security, then reliability improves, but use of energy increases due to continuous security operations

Engineering Contradiction:
ImprovesecurityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic action by triggering memory scrubbing operations only at specific events - namely when VM instances are terminated or migrated. Rather than continuously monitoring and scrubbing all memory regions, the system performs security operations periodically at relevant transition points, reducing energy consumption while maintaining security reliability through event-driven memory protection.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8893124B2Method, apparatus and system for limiting access to virtualization information in a memory
Publication Date: 2014.11.18 INTEL CORP
  • US8893124B2 patent drawing
  • US8893124B2 patent drawing
  • US8893124B2 patent drawing

AI summary

Techniques for limiting access to virtualization information which is stored in a memory region allocated to a virtual machine instance. In an embodiment, virtualization information is written over in response to an indication of a close event which is to change an allocation of the memory region to the virtual machine instance. In another embodiment, the virtualization information is written over before the memory region is made available for a subsequent allocation.