- 专利标题: PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS
-
申请号: EP24170687.8申请日: 2018-08-15
-
公开(公告)号: EP4379592A2公开(公告)日: 2024-06-05
- 发明人: Sahita, Ravi L. , Patel, Baiju V. , Huntley, Barry E. , Neiger, Gilbert , Khosravi, Hormuzd M. , Ouziel, Ido , Durham, David M. , Schoinas, Ioannis T. , Chhabra, Siddhartha , Rozas, Carlos V. , Gerzon, Gideon
- 申请人: INTEL Corporation
- 申请人地址: US Santa Clara, CA 95054 2200 Mission College Blvd.
- 专利权人: INTEL Corporation
- 当前专利权人: INTEL Corporation
- 当前专利权人地址: US Santa Clara, CA 95054 2200 Mission College Blvd.
- 代理机构: Samson & Partner Patentanwälte mbB
- 优先权: US 201715705562 2017.09.15
- 分案原申请号: 21175141.7 2021.05.21;20152004.6 2020.01.15;18189207.6 2018.08.15
- 主分类号: G06F21/79
- IPC分类号: G06F21/79
摘要:
Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, an apparatus comprises: a memory encryption engine to protect memory using encryption; and a processor to execute one or more instructions to allow a virtual machine manager (VMM) to manage a trust domain (TD). The processor is to support at least one of a first instruction to add a memory page to the TD, wherein execution of the first instruction is to use an address of TD control structure, an address of a source page, and an address of destination page to: copy the source memory page to the destination page using an encryption key identified in the TD control structure, a second instruction, wherein execution of the second instruction is to initialize the TD control structure for a TD and generate the encryption key, or a third instruction, wherein execution of the third instruction is to enter the TD and load a saved state of the TD from a data structure.
公开/授权文献
信息查询