- 专利标题: SECURE PUBLIC CLOUD WITH PROTECTED GUEST-VERIFIED HOST CONTROL
-
申请号: EP18152856.3申请日: 2018-01-22
-
公开(公告)号: EP3367287A1公开(公告)日: 2018-08-29
- 发明人: DURHAM, David M. , NEIGER, Gilbert , HUNTLEY, Barry E. , SAHITA, Ravi L. , PATEL, Baiju V.
- 申请人: INTEL Corporation
- 申请人地址: 2200 Mission College Blvd. Santa Clara, CA 95054 US
- 专利权人: INTEL Corporation
- 当前专利权人: INTEL Corporation
- 当前专利权人地址: 2200 Mission College Blvd. Santa Clara, CA 95054 US
- 代理机构: Maiwald Patent- und Rechtsanwaltsgesellschaft mbH
- 优先权: US201715444771 20170228
- 主分类号: G06F21/53
- IPC分类号: G06F21/53 ; G06F9/455 ; G06F21/57 ; G06F21/78
摘要:
A host Virtual Machine Monitor (VMM) operates "blindly," without the host VMM having the ability to access data within a guest virtual machine (VM) or the ability to access directly control structures that control execution flow of the guest VM. Guest VMs execute within a protected region of memory (called a key domain) that even the host VMM cannot access. Virtualization data structures that pertain to the execution state (e.g., a Virtual Machine Control Structure (VMCS)) and memory mappings (e.g., Extended Page Tables (EPTs)) of the guest VM are also located in the protected memory region and are also encrypted with the key domain key. The host VMM and other guest VMs, which do not possess the key domain key for other key domains, cannot directly modify these control structures nor access the protected memory region. The host VMM, however, can verify correctness of the control structures of guest VMs.
公开/授权文献
信息查询