Wrapped Nested Virtualization for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machine (VM) based services in cloud platforms are limited by the underlying hypervisor's capabilities, particularly in supporting VM introspection and migration, which restricts their ability to provide comprehensive runtime integrity monitoring and defense against malware and other threats, especially in commercial cloud infrastructures.

Innovation Solution

The implementation of wrapped nested virtualization through HyperShell, a portable layer of software services that runs a hypervisor within a guest virtual machine, providing transparent security and migration capabilities across heterogeneous cloud platforms, decoupling platform-specific resource management from platform-agnostic security services, and enabling real-time situational awareness and proactive defense mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VM-based services rely on the underlying hypervisor's capabilities, then they can leverage existing virtualization infrastructure, but their ability to provide comprehensive runtime integrity monitoring and defense against malware is restricted

Engineering Contradiction:
Improveruntime integrity monitoring capabilityVSAvoiddependency on underlying hypervisor
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a nested virtualization architecture where a second hypervisor is embedded within a guest VM of the first hypervisor. This nested hypervisor provides additional runtime integrity monitoring and security services independent of the underlying hypervisor's capabilities, allowing comprehensive defense while leveraging the existing virtualization infrastructure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The nested hypervisor acts as an intermediary layer between the guest VM and the underlying hypervisor. It provides runtime integrity monitoring and security services by intercepting and analyzing VM operations, thereby enhancing reliability without being constrained by the underlying hypervisor's native capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a nested hypervisor is implemented within a guest VM, then portable and customizable security services can be provided across heterogeneous cloud platforms, but the system complexity increases

Engineering Contradiction:
Improveportability across cloud platformsVSAvoidnested virtualization structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The nested hypervisor is designed as a universal security service layer that can operate across heterogeneous cloud platforms. It provides multiple functions including runtime integrity monitoring, malware detection, and migration support, making the security system adaptable and portable while managing complexity through standardized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If wrapped nested virtualization is used to decouple platform-specific resource management from platform-agnostic security services, then security services become portable and customizable, but the device structure becomes more complex

Engineering Contradiction:
Improvesecurity service portabilityVSAvoidwrapped nested structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the virtualization system into distinct layers: the underlying hypervisor handles platform-specific resource management, while the nested hypervisor within the guest VM provides platform-agnostic security services. This segmentation enables security services to be portable and customizable, as they are decoupled from platform-specific implementations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9342343B2Wrapped nested virtualization
Publication Date: 2016.05.17 ADVENTIUM ENTERPRISES LLC
  • US9342343B2 patent drawing
  • US9342343B2 patent drawing
  • US9342343B2 patent drawing

AI summary

A number of embodiments can include a Layer 0(L0) VMM configured to provide a first number of services and a Layer 1(L1) virtual machine (VM) that is running on the L0 VMM. A number of embodiments can also include a L1 VMM that is running on the L1 VM. A number of embodiments can include configuring the L1 VMM to provide a second number of services to a target VM, second number of services being different than the first number of services. A number of embodiments can also include configuring the target VM to execute a user application.