-
公开(公告)号:US20250130958A1
公开(公告)日:2025-04-24
申请号:US18926087
申请日:2024-10-24
Applicant: Advanced Micro Devices, Inc.
Inventor: Reshma Lal , David A. Kaplan , Jelena Ilic
IPC: G06F12/14 , G06F12/1009
Abstract: Root-trusted guest memory page management is described. A root-trusted guest is loaded by a hardware platform and authenticated. The root-trusted guest is configured to manage memory operations of different guests via special privileges that permit the root-trusted guest to execute memory operations using a guest's private memory page. To do so, a guest page table includes a novel “T-bit” in each entry, which indicates whether the root-trusted guest or a different guest owns the associated memory page. Each entry in the guest page table for the root-trusted guest additionally includes a “C-bit” that indicates whether the corresponding memory page is a protected page. Combined C-bit and T-bit values for a page table entry dictate whether operations performed as part of handling a guest's memory request are offloaded from the hardware platform to the root-trusted guest.
-
公开(公告)号:US20250130844A1
公开(公告)日:2025-04-24
申请号:US18926095
申请日:2024-10-24
Applicant: Advanced Micro Devices, Inc.
Inventor: Reshma Lal , David A. Kaplan , Jelena Ilic
IPC: G06F9/455
Abstract: A security framework for virtual machines is described. In one or more implementations, a hardware platform comprises physical computer hardware, the physical computer hardware including one or more processing units and one or more memories. The system also includes a virtual machine monitor configured to virtualize the physical computer hardware of the hardware platform to instantiate a plurality of framework-secure virtual machines. Further, the system includes a root framework-secure virtual machine instantiated by the virtual machine monitor. In accordance with the described techniques, the root framework-secure virtual machine is configured to control access to the hardware platform by the framework-secure virtual machines instantiated by the virtual machine monitor.
-