JP7436495B2 - セキュア・ストレージの分離 - Google Patents
セキュア・ストレージの分離 Download PDFInfo
- Publication number
- JP7436495B2 JP7436495B2 JP2021550287A JP2021550287A JP7436495B2 JP 7436495 B2 JP7436495 B2 JP 7436495B2 JP 2021550287 A JP2021550287 A JP 2021550287A JP 2021550287 A JP2021550287 A JP 2021550287A JP 7436495 B2 JP7436495 B2 JP 7436495B2
- Authority
- JP
- Japan
- Prior art keywords
- secure
- page
- guest
- access
- hypervisor
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/14—Protection against unauthorised use of memory or access to memory
- G06F12/1458—Protection against unauthorised use of memory or access to memory by checking the subject access rights
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
- G06F21/6281—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database at program execution time, where the protection is within the operating system
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45579—I/O management, e.g. providing access to device drivers or storage
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45583—Memory management, e.g. access or allocation
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45587—Isolation or security of virtual machine instances
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2212/00—Indexing scheme relating to accessing, addressing or allocation within memory systems or architectures
- G06F2212/10—Providing a specific technical effect
- G06F2212/1052—Security improvement
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Databases & Information Systems (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Storage Device Security (AREA)
- Stored Programmes (AREA)
- Circuits Of Receivers In General (AREA)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/296,345 US11531627B2 (en) | 2019-03-08 | 2019-03-08 | Secure storage isolation |
| US16/296,345 | 2019-03-08 | ||
| PCT/EP2020/055468 WO2020182527A1 (en) | 2019-03-08 | 2020-03-02 | Secure storage isolation |
Publications (4)
| Publication Number | Publication Date |
|---|---|
| JP2022522728A JP2022522728A (ja) | 2022-04-20 |
| JPWO2020182527A5 JPWO2020182527A5 (https=) | 2022-08-12 |
| JP2022522728A5 JP2022522728A5 (https=) | 2022-08-12 |
| JP7436495B2 true JP7436495B2 (ja) | 2024-02-21 |
Family
ID=69743235
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2021550287A Active JP7436495B2 (ja) | 2019-03-08 | 2020-03-02 | セキュア・ストレージの分離 |
Country Status (16)
| Country | Link |
|---|---|
| US (1) | US11531627B2 (https=) |
| EP (1) | EP3935495B1 (https=) |
| JP (1) | JP7436495B2 (https=) |
| KR (1) | KR102681250B1 (https=) |
| CN (1) | CN113544646B (https=) |
| AU (1) | AU2020238889B2 (https=) |
| BR (1) | BR112021017786A2 (https=) |
| CA (1) | CA3132781A1 (https=) |
| ES (1) | ES3056857T3 (https=) |
| IL (1) | IL285013B2 (https=) |
| MX (1) | MX2021010586A (https=) |
| PL (1) | PL3935495T3 (https=) |
| SG (1) | SG11202105419PA (https=) |
| TW (1) | TWI801714B (https=) |
| WO (1) | WO2020182527A1 (https=) |
| ZA (1) | ZA202105808B (https=) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11640361B2 (en) | 2019-03-08 | 2023-05-02 | International Business Machines Corporation | Sharing secure memory across multiple security domains |
| US11308215B2 (en) * | 2019-03-08 | 2022-04-19 | International Business Machines Corporation | Secure interface control high-level instruction interception for interruption enablement |
| US11347529B2 (en) | 2019-03-08 | 2022-05-31 | International Business Machines Corporation | Inject interrupts and exceptions into secure virtual machine |
| US20250156551A1 (en) * | 2023-11-14 | 2025-05-15 | Analog Devices, Inc. | Techniques for implementing trusted binaries for microcontrollers |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2016536720A (ja) | 2013-09-24 | 2016-11-24 | インテル・コーポレーション | セキュアなメモリの再パーティショニング |
| US20190042463A1 (en) | 2018-09-28 | 2019-02-07 | Vedvyas Shanbhogue | Apparatus and method for secure memory access using trust domains |
Family Cites Families (47)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US4787031A (en) | 1985-01-04 | 1988-11-22 | Digital Equipment Corporation | Computer with virtual machine mode and multiple protection rings |
| JP3657665B2 (ja) | 1995-02-14 | 2005-06-08 | 富士通株式会社 | 共用メモリに結合される複数の計算機システム及び共用メモリに結合される複数の計算機システムの制御方法 |
| US6314501B1 (en) | 1998-07-23 | 2001-11-06 | Unisys Corporation | Computer system and method for operating multiple operating systems in different partitions of the computer system and for allowing the different partitions to communicate with one another through shared memory |
| JP4220476B2 (ja) | 2002-11-18 | 2009-02-04 | エイアールエム リミテッド | 安全ドメインおよび非安全ドメインを有するシステム内での仮想−物理メモリアドレスマッピング |
| WO2005036367A2 (en) | 2003-10-08 | 2005-04-21 | Unisys Corporation | Virtual data center that allocates and manages system resources across multiple nodes |
| US20050102670A1 (en) | 2003-10-21 | 2005-05-12 | Bretl Robert F. | Shared object memory with object management for multiple virtual machines |
| US10768958B2 (en) | 2004-11-17 | 2020-09-08 | Vmware, Inc. | Using virtual local area networks in a virtual computer system |
| US7886126B2 (en) | 2005-01-14 | 2011-02-08 | Intel Corporation | Extended paging tables to map guest physical memory addresses from virtual memory page tables to host physical memory addresses in a virtual machine system |
| US7814307B2 (en) | 2006-03-16 | 2010-10-12 | Microsoft Corporation | Fast booting a computing device to a specialized experience |
| US7610481B2 (en) | 2006-04-19 | 2009-10-27 | Intel Corporation | Method and apparatus to support independent systems in partitions of a processing system |
| JP4952308B2 (ja) | 2007-03-09 | 2012-06-13 | 日本電気株式会社 | メモリ共有システム、方法、及び、プログラム |
| US8261265B2 (en) * | 2007-10-30 | 2012-09-04 | Vmware, Inc. | Transparent VMM-assisted user-mode execution control transfer |
| US8527715B2 (en) | 2008-02-26 | 2013-09-03 | International Business Machines Corporation | Providing a shared memory translation facility |
| GB2460393B (en) | 2008-02-29 | 2012-03-28 | Advanced Risc Mach Ltd | A data processing apparatus and method for controlling access to secure memory by virtual machines executing on processing circuitry |
| US8041877B2 (en) | 2008-06-09 | 2011-10-18 | International Business Machines Corporation | Distributed computing utilizing virtual memory having a shared paging space |
| US8006043B2 (en) | 2008-10-06 | 2011-08-23 | Vmware, Inc. | System and method for maintaining memory page sharing in a virtual environment |
| US20100161879A1 (en) | 2008-12-18 | 2010-06-24 | Lsi Corporation | Efficient and Secure Main Memory Sharing Across Multiple Processors |
| US8738932B2 (en) | 2009-01-16 | 2014-05-27 | Teleputers, Llc | System and method for processor-based security |
| US9405700B2 (en) | 2010-11-04 | 2016-08-02 | Sonics, Inc. | Methods and apparatus for virtualization in an integrated circuit |
| US8984478B2 (en) | 2011-10-03 | 2015-03-17 | Cisco Technology, Inc. | Reorganization of virtualized computer programs |
| AU2013297064B2 (en) | 2012-08-03 | 2016-06-16 | North Carolina State University | Methods, systems, and computer readable medium for active monitoring, memory protection and integrity verification of target devices |
| US10198572B2 (en) | 2013-09-17 | 2019-02-05 | Microsoft Technology Licensing, Llc | Virtual machine manager facilitated selective code integrity enforcement |
| US9117081B2 (en) | 2013-12-20 | 2015-08-25 | Bitdefender IPR Management Ltd. | Strongly isolated malware scanning using secure virtual containers |
| US10599565B2 (en) | 2013-12-24 | 2020-03-24 | Hewlett-Packard Development Company, L.P. | Hypervisor managing memory addressed above four gigabytes |
| US9483639B2 (en) | 2014-03-13 | 2016-11-01 | Unisys Corporation | Service partition virtualization system and method having a secure application |
| US9652631B2 (en) | 2014-05-05 | 2017-05-16 | Microsoft Technology Licensing, Llc | Secure transport of encrypted virtual machines with continuous owner access |
| KR20150128328A (ko) | 2014-05-09 | 2015-11-18 | 한국전자통신연구원 | 증거 수집 도구 제공 방법, 도메인 분리 기반 모바일 기기에서 증거 자료 확보 장치 및 방법 |
| US9792222B2 (en) | 2014-06-27 | 2017-10-17 | Intel Corporation | Validating virtual address translation by virtual machine monitor utilizing address validation structure to validate tentative guest physical address and aborting based on flag in extended page table requiring an expected guest physical address in the address validation structure |
| US9454497B2 (en) | 2014-08-15 | 2016-09-27 | Intel Corporation | Technologies for secure inter-virtual-machine shared memory communication |
| US9436619B2 (en) * | 2014-09-08 | 2016-09-06 | Raytheon Company | Multi-level, hardware-enforced domain separation using a separation kernel on a multicore processor with a shared cache |
| US10599458B2 (en) | 2015-01-23 | 2020-03-24 | Unisys Corporation | Fabric computing system having an embedded software defined network |
| US10503405B2 (en) | 2015-02-10 | 2019-12-10 | Red Hat Israel, Ltd. | Zero copy memory reclaim using copy-on-write |
| US9870324B2 (en) | 2015-04-09 | 2018-01-16 | Vmware, Inc. | Isolating guest code and data using multiple nested page tables |
| KR102327782B1 (ko) | 2015-05-29 | 2021-11-18 | 한국과학기술원 | 전자 장치 및 커널 데이터 접근 방법 |
| GB2539435B8 (en) | 2015-06-16 | 2018-02-21 | Advanced Risc Mach Ltd | Data processing memory access control, in which an owning process for a region of memory is specified independently of privilege level |
| US20170063544A1 (en) | 2015-08-26 | 2017-03-02 | Rubicon Labs, Inc. | System and method for sharing data securely |
| US9792143B1 (en) | 2015-10-23 | 2017-10-17 | Amazon Technologies, Inc. | Platform secure execution modes |
| CN107203722B (zh) * | 2016-03-16 | 2020-01-14 | 中国电子科技集团公司电子科学研究院 | 一种虚拟化数据隔离交换方法及装置 |
| US20170357592A1 (en) | 2016-06-09 | 2017-12-14 | Vmware, Inc. | Enhanced-security page sharing in a virtualized computer system |
| US10585805B2 (en) | 2016-07-29 | 2020-03-10 | Advanced Micro Devices, Inc. | Controlling access to pages in a memory in a computing device |
| US10303899B2 (en) | 2016-08-11 | 2019-05-28 | Intel Corporation | Secure public cloud with protected guest-verified host control |
| US10713177B2 (en) | 2016-09-09 | 2020-07-14 | Intel Corporation | Defining virtualized page attributes based on guest page attributes |
| KR102511451B1 (ko) | 2016-11-09 | 2023-03-17 | 삼성전자주식회사 | 리치 실행 환경에서 보안 어플리케이션을 안전하게 실행하는 컴퓨팅 시스템 |
| US10169088B2 (en) | 2016-11-29 | 2019-01-01 | Red Hat Israel, Ltd. | Lockless free memory ballooning for virtual machines |
| US10447717B2 (en) | 2017-01-28 | 2019-10-15 | Qualcomm Incorporated | Network attack detection using multi-path verification |
| CN120448113A (zh) * | 2018-11-08 | 2025-08-08 | 英特尔公司 | 功能即服务(faas)系统增强 |
| US11461244B2 (en) * | 2018-12-20 | 2022-10-04 | Intel Corporation | Co-existence of trust domain architecture with multi-key total memory encryption technology in servers |
-
2019
- 2019-03-08 US US16/296,345 patent/US11531627B2/en active Active
-
2020
- 2020-02-11 TW TW109104167A patent/TWI801714B/zh active
- 2020-03-02 SG SG11202105419PA patent/SG11202105419PA/en unknown
- 2020-03-02 WO PCT/EP2020/055468 patent/WO2020182527A1/en not_active Ceased
- 2020-03-02 PL PL20709159.6T patent/PL3935495T3/pl unknown
- 2020-03-02 MX MX2021010586A patent/MX2021010586A/es unknown
- 2020-03-02 BR BR112021017786A patent/BR112021017786A2/pt active Search and Examination
- 2020-03-02 IL IL285013A patent/IL285013B2/en unknown
- 2020-03-02 AU AU2020238889A patent/AU2020238889B2/en active Active
- 2020-03-02 JP JP2021550287A patent/JP7436495B2/ja active Active
- 2020-03-02 KR KR1020217026276A patent/KR102681250B1/ko active Active
- 2020-03-02 EP EP20709159.6A patent/EP3935495B1/en active Active
- 2020-03-02 ES ES20709159T patent/ES3056857T3/es active Active
- 2020-03-02 CA CA3132781A patent/CA3132781A1/en active Pending
- 2020-03-02 CN CN202080020115.0A patent/CN113544646B/zh active Active
-
2021
- 2021-08-13 ZA ZA2021/05808A patent/ZA202105808B/en unknown
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2016536720A (ja) | 2013-09-24 | 2016-11-24 | インテル・コーポレーション | セキュアなメモリの再パーティショニング |
| US20190042463A1 (en) | 2018-09-28 | 2019-02-07 | Vedvyas Shanbhogue | Apparatus and method for secure memory access using trust domains |
Non-Patent Citations (2)
| Title |
|---|
| SEONGWOOK JIN; ET AL,ARCHITECTURAL SUPPORT FOR SECURE VIRTUALIZATION UNDER A VULNERABLE HYPERVISOR,PROCEEDINGS OF THE 44TH ANNUAL IEEE/ACM INTERNATIONAL SYMPOSIUM ON MICROARCHITECTURE,米国,2011年,PAGE(S):272-283,http://dx.doi.org/10.1145/2155620.2155652 |
| SEONGWOOK JIN; ET AL,H-SVM: HARDWARE-ASSISTED SECURE VIRTUAL MACHINES UNDER A VULNERABLE HYPERVISOR,IEEE TRANSACTIONS ON COMPUTERS,米国,IEEE,2015年10月,VOL:64, NR:10,PAGE(S):2833-2846,http://dx.doi.org/10.1109/TC.2015.2389792 |
Also Published As
| Publication number | Publication date |
|---|---|
| TWI801714B (zh) | 2023-05-11 |
| EP3935495C0 (en) | 2025-11-12 |
| AU2020238889A1 (en) | 2021-06-17 |
| CN113544646A (zh) | 2021-10-22 |
| EP3935495B1 (en) | 2025-11-12 |
| BR112021017786A2 (pt) | 2021-11-23 |
| KR20210118122A (ko) | 2021-09-29 |
| IL285013B1 (en) | 2023-12-01 |
| IL285013A (en) | 2021-09-30 |
| IL285013B2 (en) | 2024-04-01 |
| KR102681250B1 (ko) | 2024-07-04 |
| MX2021010586A (es) | 2021-10-13 |
| WO2020182527A1 (en) | 2020-09-17 |
| TW202038104A (zh) | 2020-10-16 |
| CA3132781A1 (en) | 2020-09-17 |
| US11531627B2 (en) | 2022-12-20 |
| PL3935495T3 (pl) | 2026-02-23 |
| CN113544646B (zh) | 2024-01-23 |
| SG11202105419PA (en) | 2021-06-29 |
| US20200285595A1 (en) | 2020-09-10 |
| ZA202105808B (en) | 2023-02-22 |
| AU2020238889B2 (en) | 2022-12-01 |
| EP3935495A1 (en) | 2022-01-12 |
| JP2022522728A (ja) | 2022-04-20 |
| ES3056857T3 (en) | 2026-02-25 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7379512B2 (ja) | セキュア・ドメインと非セキュア・エンティティとの間のストレージ共用 | |
| JP7350868B2 (ja) | 複数のセキュリティ・ドメインにわたるセキュア・メモリの共用 | |
| JP7410161B2 (ja) | ページ変更検出によるセキュアなページング | |
| CN113544680B (zh) | 用于页导入/导出的程序中断 | |
| JP7379516B2 (ja) | セキュア・インターフェース制御ストレージのためのホスト仮想アドレス空間使用方法、システム、プログラム | |
| CN113544655B (zh) | 安全接口控件安全存储硬件标记 | |
| CN113544645B (zh) | 在安全虚拟机环境中测试存储保护硬件 | |
| US11182192B2 (en) | Controlling access to secure storage of a virtual machine | |
| JP7436495B2 (ja) | セキュア・ストレージの分離 | |
| JP7393846B2 (ja) | セキュア・インターフェイス制御の高レベルのページ管理 | |
| CN113544664B (zh) | 用于中断使能的安全接口控件高级指令拦截 | |
| JP2022522679A (ja) | セキュア・インターフェース・コントロールの通信インターフェース | |
| HK40057847B (zh) | 安全存储隔离 | |
| HK40057847A (en) | Secure storage isolation |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| RD04 | Notification of resignation of power of attorney |
Free format text: JAPANESE INTERMEDIATE CODE: A7424 Effective date: 20220512 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20220803 |
|
| A621 | Written request for application examination |
Free format text: JAPANESE INTERMEDIATE CODE: A621 Effective date: 20220824 |
|
| A131 | Notification of reasons for refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A131 Effective date: 20231017 |
|
| A521 | Request for written amendment filed |
Free format text: JAPANESE INTERMEDIATE CODE: A523 Effective date: 20240109 |
|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20240123 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20240208 |
|
| R150 | Certificate of patent or registration of utility model |
Ref document number: 7436495 Country of ref document: JP Free format text: JAPANESE INTERMEDIATE CODE: R150 |