Hardware Protected VMM Integrity Watcher
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack effective runtime integrity protection for virtual machine monitors (VMMs) in cloud environments, making them vulnerable to compromise, which can lead to the security breach of all managed virtual machines.
Innovation Solution
A hardware-based runtime integrity watcher is implemented, utilizing a protected memory space and cryptographic verification to monitor and ensure the integrity of the VMM, with a hardware timer and secondary watcher program for continuous monitoring and reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a VMM is deployed in a cloud environment for extended periods, then productivity and resource utilization are improved, but the vulnerability and exposure to malware compromise increase
Solution Approach 1:
A hardware-based integrity watcher is introduced as an intermediary component between the VMM and potential malware. This watcher operates in a protected memory space and periodically samples the VMM's code to detect unauthorized modifications, thereby protecting the VMM without interfering with its normal operational productivity
Solution Approach 2:
The integrity watcher performs preliminary security checks by periodically sampling and verifying the VMM's code against stored hash values before malware can compromise the system. This proactive approach detects integrity violations early, preventing the VMM from being fully compromised while maintaining continuous operation
2Reliability
If runtime integrity monitoring is implemented for the VMM, then security assurance is improved, but device complexity increases
Solution Approach 1:
The patent replaces complex software-based integrity monitoring mechanisms with a hardware-based solution. The integrity watcher is implemented using CPU hardware components (memory management units, execution control logic) that automatically perform integrity checks without requiring complex software frameworks or manual configuration
Solution Approach 2:
The integrity watcher operates autonomously within the CPU architecture, self-managing its own execution and monitoring functions. It periodically samples the VMM code automatically and compares hashes without external intervention, reducing the complexity burden on the VMM itself while maintaining strong security
Data Source
AI summary
An apparatus and method for hardware protection of a virtual machine monitor (VMM) runtime integrity watcher is described. A set of one or more hardware range registers that protect a contiguous memory space that is to store the VMM runtime integrity watcher. The set of hardware range registers are to protect the VMM runtime integrity watcher from being modified when loaded into the contiguous memory space. The VMM runtime integrity watcher, when executed, performs an integrity check on a VMM during runtime of the VMM.


