TWI748338B - 用於安全介面控制高層級頁面管理之電腦實施方法、電腦系統及電腦程式產品 - Google Patents
用於安全介面控制高層級頁面管理之電腦實施方法、電腦系統及電腦程式產品 Download PDFInfo
- Publication number
- TWI748338B TWI748338B TW109104344A TW109104344A TWI748338B TW I748338 B TWI748338 B TW I748338B TW 109104344 A TW109104344 A TW 109104344A TW 109104344 A TW109104344 A TW 109104344A TW I748338 B TWI748338 B TW I748338B
- Authority
- TW
- Taiwan
- Prior art keywords
- host
- secure
- page
- security
- absolute
- Prior art date
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/14—Protection against unauthorised use of memory or access to memory
- G06F12/1416—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights
- G06F12/145—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights the protection being virtual, e.g. for virtual blocks or segments before a translation mechanism
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/14—Protection against unauthorised use of memory or access to memory
- G06F12/1416—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F12/00—Accessing, addressing or allocating within memory systems or architectures
- G06F12/14—Protection against unauthorised use of memory or access to memory
- G06F12/1416—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights
- G06F12/1425—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights the protection being physical, e.g. cell, word, block
- G06F12/1441—Protection against unauthorised use of memory or access to memory by checking the object accessibility, e.g. type of access defined by the memory independently of subject rights the protection being physical, e.g. cell, word, block for a range
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45583—Memory management, e.g. access or allocation
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45587—Isolation or security of virtual machine instances
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2212/00—Indexing scheme relating to accessing, addressing or allocation within memory systems or architectures
- G06F2212/10—Providing a specific technical effect
- G06F2212/1052—Security improvement
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- Computer Security & Cryptography (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Computer Hardware Design (AREA)
- Storage Device Security (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/296,457 | 2019-03-08 | ||
| US16/296,457 US11347869B2 (en) | 2019-03-08 | 2019-03-08 | Secure interface control high-level page management |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| TW202101265A TW202101265A (zh) | 2021-01-01 |
| TWI748338B true TWI748338B (zh) | 2021-12-01 |
Family
ID=69770912
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| TW109104344A TWI748338B (zh) | 2019-03-08 | 2020-02-12 | 用於安全介面控制高層級頁面管理之電腦實施方法、電腦系統及電腦程式產品 |
Country Status (10)
| Country | Link |
|---|---|
| US (1) | US11347869B2 (https=) |
| EP (1) | EP3935509B1 (https=) |
| JP (1) | JP7393846B2 (https=) |
| KR (1) | KR102774738B1 (https=) |
| CN (1) | CN113544654B (https=) |
| ES (1) | ES3014595T3 (https=) |
| SG (1) | SG11202105433TA (https=) |
| TW (1) | TWI748338B (https=) |
| WO (1) | WO2020182638A1 (https=) |
| ZA (1) | ZA202105809B (https=) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11206128B2 (en) | 2019-03-08 | 2021-12-21 | International Business Machines Corporation | Secure paging with page change detection |
| US11308215B2 (en) * | 2019-03-08 | 2022-04-19 | International Business Machines Corporation | Secure interface control high-level instruction interception for interruption enablement |
| US11347529B2 (en) | 2019-03-08 | 2022-05-31 | International Business Machines Corporation | Inject interrupts and exceptions into secure virtual machine |
| CN118503993A (zh) * | 2023-02-16 | 2024-08-16 | 华为技术有限公司 | 权限管理方法、相关装置及系统 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2015178987A2 (en) * | 2014-02-28 | 2015-11-26 | Advanced Micro Devices, Inc. | Cryptographic protection of information in a processing system |
| EP2630608B1 (en) * | 2010-10-20 | 2016-01-20 | Advanced Micro Devices, Inc. | Method and apparatus including architecture for protecting multi-user sensitive code and data |
| TWI556107B (zh) * | 2014-08-15 | 2016-11-01 | 英特爾股份有限公司 | 用於安全虛擬機器間共用記憶體通訊之技術 |
| TW201729136A (zh) * | 2015-08-18 | 2017-08-16 | 英特爾股份有限公司 | 安全區之平台遷移 |
| CN107667350A (zh) * | 2015-06-15 | 2018-02-06 | 英特尔公司 | 基于虚拟化的平台保护技术 |
Family Cites Families (53)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US4456954A (en) * | 1981-06-15 | 1984-06-26 | International Business Machines Corporation | Virtual machine system with guest architecture emulation using hardware TLB's for plural level address translations |
| US5343527A (en) | 1993-10-27 | 1994-08-30 | International Business Machines Corporation | Hybrid encryption method and system for protecting reusable software components |
| US5757919A (en) | 1996-12-12 | 1998-05-26 | Intel Corporation | Cryptographically protected paging subsystem |
| US6021201A (en) | 1997-01-07 | 2000-02-01 | Intel Corporation | Method and apparatus for integrated ciphering and hashing |
| US6983365B1 (en) | 2000-05-05 | 2006-01-03 | Microsoft Corporation | Encryption systems and methods for identifying and coalescing identical objects encrypted with different keys |
| US20020049878A1 (en) * | 2000-10-23 | 2002-04-25 | Giora Biran | Data communications interfaces |
| US6996748B2 (en) * | 2002-06-29 | 2006-02-07 | Intel Corporation | Handling faults associated with operation of guest software in the virtual-machine architecture |
| WO2005036367A2 (en) | 2003-10-08 | 2005-04-21 | Unisys Corporation | Virtual data center that allocates and manages system resources across multiple nodes |
| EP1870814B1 (en) | 2006-06-19 | 2014-08-13 | Texas Instruments France | Method and apparatus for secure demand paging for processor devices |
| US7653819B2 (en) | 2004-10-01 | 2010-01-26 | Lenovo Singapore Pte Ltd. | Scalable paging of platform configuration registers |
| US7886363B2 (en) | 2006-05-24 | 2011-02-08 | Noam Camiel | System and method for virtual memory and securing memory in programming languages |
| EP1870813B1 (en) | 2006-06-19 | 2013-01-30 | Texas Instruments France | Page processing circuits, devices, methods and systems for secure demand paging and other operations |
| US20080077767A1 (en) | 2006-09-27 | 2008-03-27 | Khosravi Hormuzd M | Method and apparatus for secure page swapping in virtual memory systems |
| US8261265B2 (en) | 2007-10-30 | 2012-09-04 | Vmware, Inc. | Transparent VMM-assisted user-mode execution control transfer |
| US8176280B2 (en) * | 2008-02-25 | 2012-05-08 | International Business Machines Corporation | Use of test protection instruction in computing environments that support pageable guests |
| GB2460393B (en) | 2008-02-29 | 2012-03-28 | Advanced Risc Mach Ltd | A data processing apparatus and method for controlling access to secure memory by virtual machines executing on processing circuitry |
| US8833437B2 (en) | 2009-05-06 | 2014-09-16 | Holtec International, Inc. | Heat exchanger apparatus for converting a shell-side liquid into a vapor |
| US20120185699A1 (en) | 2011-01-14 | 2012-07-19 | International Business Machines Corporation | Space-efficient encryption with multi-block binding |
| WO2012164721A1 (ja) | 2011-06-02 | 2012-12-06 | 三菱電機株式会社 | 鍵情報生成装置及び鍵情報生成方法 |
| KR101323858B1 (ko) | 2011-06-22 | 2013-11-21 | 한국과학기술원 | 가상화 시스템에서 메모리 접근을 제어하는 장치 및 방법 |
| US8681813B2 (en) | 2011-11-29 | 2014-03-25 | Wyse Technology L.L.C. | Bandwidth optimization for remote desktop protocol |
| EP4036721B1 (en) | 2012-06-26 | 2025-03-26 | Lynx Software Technologies Inc. | Systems and methods involving features of hardware virtualization such as separation kernel hypervisors, hypervisors, hypervisor guest context, hypervisor context, rootkit detection prevention and further features |
| US8910238B2 (en) | 2012-11-13 | 2014-12-09 | Bitdefender IPR Management Ltd. | Hypervisor-based enterprise endpoint protection |
| WO2014081611A2 (en) | 2012-11-20 | 2014-05-30 | Unisys Corporation | Error recovery in securely partitioned virtualization system with dedicated resources |
| US8931108B2 (en) | 2013-02-18 | 2015-01-06 | Qualcomm Incorporated | Hardware enforced content protection for graphics processing units |
| US9483639B2 (en) | 2014-03-13 | 2016-11-01 | Unisys Corporation | Service partition virtualization system and method having a secure application |
| US9390267B2 (en) | 2014-05-15 | 2016-07-12 | Lynx Software Technologies, Inc. | Systems and methods involving features of hardware virtualization, hypervisor, pages of interest, and/or other features |
| US9251090B1 (en) * | 2014-06-03 | 2016-02-02 | Amazon Technologies, Inc. | Hypervisor assisted virtual memory obfuscation |
| US9672354B2 (en) * | 2014-08-18 | 2017-06-06 | Bitdefender IPR Management Ltd. | Systems and methods for exposing a result of a current processor instruction upon exiting a virtual machine |
| US9305661B2 (en) | 2014-09-03 | 2016-04-05 | Microsemi Storage Solutions (U.S.), Inc. | Nonvolatile memory system that uses programming time to reduce bit errors |
| CN105512559B (zh) | 2014-10-17 | 2019-09-17 | 阿里巴巴集团控股有限公司 | 一种用于提供访问页面的方法与设备 |
| US9703720B2 (en) * | 2014-12-23 | 2017-07-11 | Intel Corporation | Method and apparatus to allow secure guest access to extended page tables |
| US10599458B2 (en) | 2015-01-23 | 2020-03-24 | Unisys Corporation | Fabric computing system having an embedded software defined network |
| US10157146B2 (en) * | 2015-02-12 | 2018-12-18 | Red Hat Israel, Ltd. | Local access DMA with shared memory pool |
| US9870324B2 (en) * | 2015-04-09 | 2018-01-16 | Vmware, Inc. | Isolating guest code and data using multiple nested page tables |
| US9875047B2 (en) * | 2015-05-27 | 2018-01-23 | Red Hat Israel, Ltd. | Exit-less host memory locking in a virtualized environment |
| US9720721B2 (en) | 2015-07-01 | 2017-08-01 | International Business Machines Corporation | Protected guests in a hypervisor controlled system |
| US9734088B2 (en) * | 2015-08-12 | 2017-08-15 | International Business Machines Corporation | Memory management unit and method for accessing data |
| US10742603B2 (en) | 2015-08-26 | 2020-08-11 | B. G. Negev Technologies And Applications Ltd., At Ben-Gurion University | System and method for monitoring and protecting an untrusted operating system by means of a trusted operating system |
| US9841987B2 (en) | 2015-12-17 | 2017-12-12 | International Business Machines Corporation | Transparent secure interception handling |
| US20170277898A1 (en) * | 2016-03-25 | 2017-09-28 | Advanced Micro Devices, Inc. | Key management for secure memory address spaces |
| US10116630B2 (en) * | 2016-04-04 | 2018-10-30 | Bitdefender IPR Management Ltd. | Systems and methods for decrypting network traffic in a virtualized environment |
| WO2017211651A1 (en) | 2016-06-08 | 2017-12-14 | Thomson Licensing | Devices and methods for core dump deduplication |
| US10671542B2 (en) * | 2016-07-01 | 2020-06-02 | Intel Corporation | Application execution enclave memory method and apparatus |
| US10237245B2 (en) | 2016-07-15 | 2019-03-19 | International Business Machines Corporation | Restricting guest instances in a shared environment |
| US10303899B2 (en) | 2016-08-11 | 2019-05-28 | Intel Corporation | Secure public cloud with protected guest-verified host control |
| US10176122B2 (en) * | 2016-10-19 | 2019-01-08 | Advanced Micro Devices, Inc. | Direct memory access authorization in a processing system |
| US10169577B1 (en) * | 2017-03-28 | 2019-01-01 | Symantec Corporation | Systems and methods for detecting modification attacks on shared physical memory |
| KR102257320B1 (ko) * | 2017-03-29 | 2021-05-27 | 어드밴스드 마이크로 디바이시즈, 인코포레이티드 | 하이퍼바이저 및 가상 머신 간 메모리 페이지 이행의 모니터링 |
| US20180341529A1 (en) | 2017-05-26 | 2018-11-29 | Microsoft Technology Licensing, Llc | Hypervisor-based secure container |
| US10693844B2 (en) | 2017-08-24 | 2020-06-23 | Red Hat, Inc. | Efficient migration for encrypted virtual machines by active page copying |
| US11206128B2 (en) | 2019-03-08 | 2021-12-21 | International Business Machines Corporation | Secure paging with page change detection |
| US11403409B2 (en) | 2019-03-08 | 2022-08-02 | International Business Machines Corporation | Program interruptions for page importing/exporting |
-
2019
- 2019-03-08 US US16/296,457 patent/US11347869B2/en active Active
-
2020
- 2020-02-12 TW TW109104344A patent/TWI748338B/zh active
- 2020-03-06 WO PCT/EP2020/055966 patent/WO2020182638A1/en not_active Ceased
- 2020-03-06 EP EP20709564.7A patent/EP3935509B1/en active Active
- 2020-03-06 JP JP2021549895A patent/JP7393846B2/ja active Active
- 2020-03-06 KR KR1020217026451A patent/KR102774738B1/ko active Active
- 2020-03-06 SG SG11202105433TA patent/SG11202105433TA/en unknown
- 2020-03-06 ES ES20709564T patent/ES3014595T3/es active Active
- 2020-03-06 CN CN202080019537.6A patent/CN113544654B/zh active Active
-
2021
- 2021-08-13 ZA ZA2021/05809A patent/ZA202105809B/en unknown
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2630608B1 (en) * | 2010-10-20 | 2016-01-20 | Advanced Micro Devices, Inc. | Method and apparatus including architecture for protecting multi-user sensitive code and data |
| WO2015178987A2 (en) * | 2014-02-28 | 2015-11-26 | Advanced Micro Devices, Inc. | Cryptographic protection of information in a processing system |
| TWI556107B (zh) * | 2014-08-15 | 2016-11-01 | 英特爾股份有限公司 | 用於安全虛擬機器間共用記憶體通訊之技術 |
| CN107667350A (zh) * | 2015-06-15 | 2018-02-06 | 英特尔公司 | 基于虚拟化的平台保护技术 |
| TW201729136A (zh) * | 2015-08-18 | 2017-08-16 | 英特爾股份有限公司 | 安全區之平台遷移 |
Non-Patent Citations (1)
| Title |
|---|
| Seongwook Jin, Jeongseob Ahn, Sanghoon Cha, and Jaehyuk Huh, Architectural Support for Secure Virtualization under a Vulnerable Hypervisor, 2011 44th Annual IEEE/ACM International Symposium on Microarchitecture (MICRO), 2017/2/13 * |
Also Published As
| Publication number | Publication date |
|---|---|
| ES3014595T3 (en) | 2025-04-23 |
| CN113544654A (zh) | 2021-10-22 |
| JP2022523522A (ja) | 2022-04-25 |
| US11347869B2 (en) | 2022-05-31 |
| SG11202105433TA (en) | 2021-06-29 |
| ZA202105809B (en) | 2023-02-22 |
| CN113544654B (zh) | 2025-06-03 |
| TW202101265A (zh) | 2021-01-01 |
| EP3935509A1 (en) | 2022-01-12 |
| EP3935509C0 (en) | 2025-02-12 |
| US20200285758A1 (en) | 2020-09-10 |
| EP3935509B1 (en) | 2025-02-12 |
| JP7393846B2 (ja) | 2023-12-07 |
| KR102774738B1 (ko) | 2025-02-27 |
| KR20210118877A (ko) | 2021-10-01 |
| WO2020182638A1 (en) | 2020-09-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7379512B2 (ja) | セキュア・ドメインと非セキュア・エンティティとの間のストレージ共用 | |
| KR102738488B1 (ko) | 여러 보안 도메인들에 걸친 보안 메모리의 공유 | |
| KR102551936B1 (ko) | 보안 인터페이스 컨트롤 스토리지를 위한 호스트 가상 주소 공간 | |
| JP7410161B2 (ja) | ページ変更検出によるセキュアなページング | |
| KR102789374B1 (ko) | 보안 인터페이스 컨트롤 보안 스토리지 하드웨어 태깅 | |
| CN113544645B (zh) | 在安全虚拟机环境中测试存储保护硬件 | |
| CN113544642B (zh) | 安全存储查询和捐献 | |
| TWI748338B (zh) | 用於安全介面控制高層級頁面管理之電腦實施方法、電腦系統及電腦程式產品 | |
| CN113544664B (zh) | 用于中断使能的安全接口控件高级指令拦截 | |
| CN113544646B (zh) | 安全存储隔离 | |
| TWI838460B (zh) | 用於安全介面控制件之通信介面之電腦實施的方法、電腦系統及電腦程式產品 | |
| HK40057847B (zh) | 安全存储隔离 | |
| HK40057848B (zh) | 安全接口控件的通信接口 | |
| HK40057638A (en) | Secure interface control secure storage hardware tagging | |
| HK40057638B (zh) | 安全接口控件安全存储硬件标记 |