Wrapped Nested Virtualization for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Virtual machine (VM) based services in cloud platforms are limited by the underlying hypervisor's capabilities, particularly in supporting VM introspection and migration, which restricts their ability to provide comprehensive runtime integrity monitoring and defense against malware and other threats, especially in commercial cloud infrastructures.
Innovation Solution
The implementation of wrapped nested virtualization through HyperShell, a portable layer of software services that runs a hypervisor within a guest virtual machine, providing transparent security and migration capabilities across heterogeneous cloud platforms, decoupling platform-specific resource management from platform-agnostic security services, and enabling real-time situational awareness and proactive defense mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If VM-based services rely on the underlying hypervisor's capabilities, then they can leverage existing virtualization infrastructure, but their ability to provide comprehensive runtime integrity monitoring and defense against malware is restricted
Solution Approach 1:
The patent implements a nested virtualization architecture where a second hypervisor is embedded within a guest VM of the first hypervisor. This nested hypervisor provides additional runtime integrity monitoring and security services independent of the underlying hypervisor's capabilities, allowing comprehensive defense while leveraging the existing virtualization infrastructure.
Solution Approach 2:
The nested hypervisor acts as an intermediary layer between the guest VM and the underlying hypervisor. It provides runtime integrity monitoring and security services by intercepting and analyzing VM operations, thereby enhancing reliability without being constrained by the underlying hypervisor's native capabilities.
2Adaptability or versatility
If a nested hypervisor is implemented within a guest VM, then portable and customizable security services can be provided across heterogeneous cloud platforms, but the system complexity increases
Solution Approach 1:
The nested hypervisor is designed as a universal security service layer that can operate across heterogeneous cloud platforms. It provides multiple functions including runtime integrity monitoring, malware detection, and migration support, making the security system adaptable and portable while managing complexity through standardized interfaces.
3Ease of operation
If wrapped nested virtualization is used to decouple platform-specific resource management from platform-agnostic security services, then security services become portable and customizable, but the device structure becomes more complex
Solution Approach 1:
The patent segments the virtualization system into distinct layers: the underlying hypervisor handles platform-specific resource management, while the nested hypervisor within the guest VM provides platform-agnostic security services. This segmentation enables security services to be portable and customizable, as they are decoupled from platform-specific implementations.
Data Source
AI summary
A number of embodiments can include a Layer 0(L0) VMM configured to provide a first number of services and a Layer 1(L1) virtual machine (VM) that is running on the L0 VMM. A number of embodiments can also include a L1 VMM that is running on the L1 VM. A number of embodiments can include configuring the L1 VMM to provide a second number of services to a target VM, second number of services being different than the first number of services. A number of embodiments can also include configuring the target VM to execute a user application.


