发明公开
EP3001326A1 METHODS AND SYSTEMS FOR COMMUNICATING BETWEEN TRUSTED AND NON-TRUSTED VIRTUAL MACHINES 有权
方法和系统之间的安全和不安全的虚拟机通信

METHODS AND SYSTEMS FOR COMMUNICATING BETWEEN TRUSTED AND NON-TRUSTED VIRTUAL MACHINES
摘要:
The methods and systems described herein provide for a method for preventing a non-trusted virtual machine from reading the graphical output of a trusted virtual machine, the virtual machines being hosted by a hypervisor executing on a computing device. A graphics manager executed by a processor of a computing device receives a request from a trusted virtual machine executed by the computing device to render graphical data using a graphics processing unit of the computing device. The graphics manager assigns, to the trusted virtual machine, a secure section of a memory of the graphics processing unit. The graphics manager renders graphics from the trusted virtual machine graphical data to the secure section of the graphics processing unit memory. The graphics manager receives a request from a non-trusted virtual machine executed by the computing device to read graphics rendered from the trusted virtual machine graphical data and stored in the secure section of the graphics processing unit memory. The graphics manager prevents the non-trusted virtual machine from reading the trusted virtual machine rendered graphics stored in the secure section of the graphics processing unit memory.
信息查询
0/0