Invention Grant
- Patent Title: System and method for virtualized process isolation including preventing a kernel from accessing user address space
-
Application No.: US15270231Application Date: 2016-09-20
-
Publication No.: US10459850B2Publication Date: 2019-10-29
- Inventor: David A. Kaplan
- Applicant: Advanced Micro Devices, Inc.
- Applicant Address: US TX Santa Clara
- Assignee: Advanced Micro Devices, Inc.
- Current Assignee: Advanced Micro Devices, Inc.
- Current Assignee Address: US TX Santa Clara
- Agency: Meyertons Hood Kivlin Kowert and Goetzel PC
- Agent Rory D. Rankin
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F9/355 ; G06F12/1009 ; G06F9/455 ; G06F21/62

Abstract:
Systems, apparatuses, and methods for implementing virtualized process isolation are disclosed. A system includes a kernel and multiple guest virtual machines (VMs) executing on the system's processing hardware. Each guest VM includes a vShim layer for managing kernel accesses to user space and guest accesses to kernel space. The vShim layer also maintains a set of page tables separate from the kernel page tables. In one embodiment, data in the user space is encrypted and the kernel goes through the vShim layer to access user space data. When the kernel attempts to access a user space address, the kernel exits and the vShim layer is launched to process the request. If the kernel has permission to access the user space address, the vShim layer copies the data to a region in kernel space and then returns execution to the kernel. The vShim layer prevents the kernel from accessing the user space address if the kernel does not have permission to access the user space address. In one embodiment, the kernel space is unencrypted and the user space is encrypted. A state of a guest VM and the vShim layer may be stored in virtual machine control blocks (VMCBs) when exiting the guest VM or vShim layer.
Public/Granted literature
- US20180081829A1 VIRTUALIZED PROCESS ISOLATION Public/Granted day:2018-03-22
Information query