TECHNOLOGIES FOR ENFORCING NETWORK ACCESS CONTROL OF VIRTUAL MACHINES

    公开(公告)号:US20170180325A1

    公开(公告)日:2017-06-22

    申请号:US14979134

    申请日:2015-12-22

    Abstract: Technologies for enforcing virtual machine network access control include a network computing device that includes a plurality of virtual machines. The network computing device is configured to receive an access request from a virtual function assigned to a requesting virtual machine of the network computing device. The network computing device is additionally configured to determine a first privilege level assigned to the requesting machine and a second privilege level assigned to the destination virtual machine, and determine whether the requesting virtual machine is authorized to access the destination virtual machine based on a comparison of the first and second privilege levels. Upon determining the requesting virtual machine is authorized to access the destination virtual machine, the network computing device is additionally configured to allow the requesting virtual machine access to the destination virtual machine. Other embodiments are described herein.

    Technologies for secure inter-virtual-machine shared memory communication
    5.
    发明授权
    Technologies for secure inter-virtual-machine shared memory communication 有权
    安全的虚拟机共享内存通信技术

    公开(公告)号:US09454497B2

    公开(公告)日:2016-09-27

    申请号:US14460530

    申请日:2014-08-15

    Abstract: Technologies for secure inter-virtual-machine shared memory communication include a computing device with hardware virtualization support. A virtual machine monitor (VMM) authenticates a view switch component of a target virtual machine. The VMM adds configures a secure memory view to access a shared memory segment. The shared memory segment may include memory pages of a source virtual machine or the VMM. The view switch component switches to the secure memory view without generating a virtual machine exit event, using the hardware virtualization support. The view switch component may switch to the secure memory view by modifying an extended page table (EPT) pointer. The target virtual machine accesses the shared memory segment via the secure memory view. The target virtual machine and the source virtual machine may coordinate ownership of memory pages using a secure view control structure stored in the shared memory segment. Other embodiments are described and claimed.

    Abstract translation: 用于安全的虚拟机间共享存储器通信的技术包括具有硬件虚拟化支持的计算设备。 虚拟机监视器(VMM)验证目标虚拟机的视图切换组件。 VMM添加配置安全内存视图以访问共享内存段。 共享内存段可以包括源虚拟机或VMM的存储器页面。 视图切换组件切换到安全存储器视图,而不会使用硬件虚拟化支持生成虚拟机退出事件。 视图切换组件可以通过修改扩展页表(EPT)指针来切换到安全存储器视图。 目标虚拟机通过安全内存视图访问共享内存段。 目标虚拟机和源虚拟机可以使用存储在共享存储器段中的安全视图控制结构来协调存储器页的所有权。 描述和要求保护其他实施例。

Patent Agency Ranking