TWI806622B - 儲存安全虛擬機器之診斷狀態 - Google Patents

儲存安全虛擬機器之診斷狀態 Download PDF

Info

Publication number
TWI806622B
TWI806622B TW111119202A TW111119202A TWI806622B TW I806622 B TWI806622 B TW I806622B TW 111119202 A TW111119202 A TW 111119202A TW 111119202 A TW111119202 A TW 111119202A TW I806622 B TWI806622 B TW I806622B
Authority
TW
Taiwan
Prior art keywords
memory
encrypted
virtual machine
request
obtaining
Prior art date
Application number
TW111119202A
Other languages
English (en)
Chinese (zh)
Other versions
TW202311945A (zh
Inventor
強納森 D 布瑞布里
托斯頓 韓德爾
雷恩哈得 索迪爾 伯恩俊
克勞迪亞 尹布蘭達
克里斯汀 伯翠格
亞諾士 安德烈斯 法蘭克
Original Assignee
美商萬國商業機器公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 美商萬國商業機器公司 filed Critical 美商萬國商業機器公司
Publication of TW202311945A publication Critical patent/TW202311945A/zh
Application granted granted Critical
Publication of TWI806622B publication Critical patent/TWI806622B/zh

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6209Protecting access to data via a platform, e.g. using keys or access control rules to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/52Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
    • G06F21/53Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • G06F2009/45587Isolation or security of virtual machine instances

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • General Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Health & Medical Sciences (AREA)
  • Storage Device Security (AREA)
  • Memory System Of A Hierarchy Structure (AREA)
  • Magnetic Resonance Imaging Apparatus (AREA)
  • Crushing And Grinding (AREA)
  • Debugging And Monitoring (AREA)
TW111119202A 2021-09-14 2022-05-24 儲存安全虛擬機器之診斷狀態 TWI806622B (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US17/474,220 2021-09-14
US17/474,220 US12019772B2 (en) 2021-09-14 2021-09-14 Storing diagnostic state of secure virtual machines

Publications (2)

Publication Number Publication Date
TW202311945A TW202311945A (zh) 2023-03-16
TWI806622B true TWI806622B (zh) 2023-06-21

Family

ID=83322570

Family Applications (1)

Application Number Title Priority Date Filing Date
TW111119202A TWI806622B (zh) 2021-09-14 2022-05-24 儲存安全虛擬機器之診斷狀態

Country Status (8)

Country Link
US (1) US12019772B2 (https=)
EP (1) EP4402570A1 (https=)
JP (1) JP2024533120A (https=)
KR (1) KR20240038774A (https=)
CN (1) CN117940900A (https=)
CA (1) CA3217891A1 (https=)
TW (1) TWI806622B (https=)
WO (1) WO2023041462A1 (https=)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20230102111A1 (en) * 2021-09-30 2023-03-30 Lenovo Global Technology (United States) Inc. Securing customer sensitive information on private cloud platforms
US12130695B2 (en) * 2023-02-06 2024-10-29 Dell Products L.P. Collecting crash-related information for a secure workspace
US12418423B2 (en) * 2023-04-11 2025-09-16 Hewlett Packard Enterprise Development Lp Binding a virtual security processor to a physical security processor

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107851151A (zh) * 2014-02-28 2018-03-27 超威半导体公司 保护虚拟机的状态信息
TWI622926B (zh) * 2013-03-15 2018-05-01 英特爾股份有限公司 行動運算裝置技術及使用該技術的系統
CN109154903A (zh) * 2016-05-02 2019-01-04 微软技术许可有限责任公司 用于虚拟机的恢复环境
CN112860380A (zh) * 2021-03-04 2021-05-28 中国科学院信息工程研究所 一种基于内置安全芯片的虚拟机可信迁移方法

Family Cites Families (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5224206A (en) * 1989-12-01 1993-06-29 Digital Equipment Corporation System and method for retrieving justifiably relevant cases from a case library
US5699505A (en) * 1994-08-08 1997-12-16 Unisys Corporation Method and system for automatically collecting diagnostic information from a computer system
US6738928B1 (en) * 2000-06-19 2004-05-18 Hewlett-Packard Development Company, L.P. Method and expert system for analysis of crash dumps
US6671687B1 (en) * 2000-09-29 2003-12-30 Ncr Corporation Method and apparatus for protecting data retrieved from a database
US8375386B2 (en) * 2005-06-29 2013-02-12 Microsoft Corporation Failure management for a virtualized computing environment
US9354927B2 (en) * 2006-12-21 2016-05-31 Vmware, Inc. Securing virtual machine data
JP5255348B2 (ja) * 2007-07-16 2013-08-07 ヒューレット−パッカード デベロップメント カンパニー エル.ピー. クラッシュダンプ用のメモリアロケーション
US9251339B2 (en) * 2007-12-29 2016-02-02 International Business Machines Corporation Core dump privacy during application failure
US20090240953A1 (en) 2008-03-19 2009-09-24 Safenet, Inc. On-disk software image encryption
US9383970B2 (en) * 2009-08-13 2016-07-05 Microsoft Technology Licensing, Llc Distributed analytics platform
US9286152B2 (en) 2013-06-14 2016-03-15 Microsoft Technology Licensing, Llc Securely obtaining memory content after device malfunction
KR102584506B1 (ko) * 2015-06-24 2023-10-04 어드밴스드 마이크로 디바이시즈, 인코포레이티드 가상 기계들을 위한 상태 정보 보호
US10270596B2 (en) 2016-09-16 2019-04-23 International Business Machnines Corporation Generating memory dumps
US10366227B2 (en) 2016-11-15 2019-07-30 International Business Machines Corporation Secure debugging in a trustable computing environment
US10496425B2 (en) 2017-02-21 2019-12-03 Red Hat, Inc. Systems and methods for providing processor state protections in a virtualized environment
US9892256B1 (en) 2017-04-10 2018-02-13 Bracket Computing, Inc. Threat defense techniques
US20180341768A1 (en) * 2017-05-26 2018-11-29 Microsoft Technology Licensing, Llc Virtual machine attestation
US10848474B2 (en) 2018-02-26 2020-11-24 Red Hat, Inc. Firmware validation for encrypted virtual machines
US10698716B2 (en) * 2018-03-15 2020-06-30 Nutanix, Inc. Virtual machine state recorder
US11308215B2 (en) * 2019-03-08 2022-04-19 International Business Machines Corporation Secure interface control high-level instruction interception for interruption enablement

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
TWI622926B (zh) * 2013-03-15 2018-05-01 英特爾股份有限公司 行動運算裝置技術及使用該技術的系統
CN107851151A (zh) * 2014-02-28 2018-03-27 超威半导体公司 保护虚拟机的状态信息
CN109154903A (zh) * 2016-05-02 2019-01-04 微软技术许可有限责任公司 用于虚拟机的恢复环境
US10296413B2 (en) * 2016-05-02 2019-05-21 Microsoft Technology Licensing, Llc Recovery environment for a virtual machine
CN112860380A (zh) * 2021-03-04 2021-05-28 中国科学院信息工程研究所 一种基于内置安全芯片的虚拟机可信迁移方法

Also Published As

Publication number Publication date
TW202311945A (zh) 2023-03-16
US12019772B2 (en) 2024-06-25
EP4402570A1 (en) 2024-07-24
CN117940900A (zh) 2024-04-26
WO2023041462A1 (en) 2023-03-23
KR20240038774A (ko) 2024-03-25
US20230083083A1 (en) 2023-03-16
JP2024533120A (ja) 2024-09-12
CA3217891A1 (en) 2023-03-23

Similar Documents

Publication Publication Date Title
JP7546675B2 (ja) セキュア・ゲストへのセキュリティ・モジュールのセキュア・オブジェクトのバインディング
CN113544679B (zh) 安全操作系统映像的增量解密和完整性验证
TWI806622B (zh) 儲存安全虛擬機器之診斷狀態
US11755721B2 (en) Trusted workload execution
US11120140B2 (en) Secure operations on encrypted data
JP2023551527A (ja) 準同型暗号化を使用したセキュアなコンピューティング・リソース配置
TWI808749B (zh) 用於安全客體映像及後設資料更新之電腦程式產品、電腦系統及電腦實施方法
TWI868448B (zh) 用於促進一運算環境內之處理的電腦程式產品、電腦系統及電腦實施方法
TWI827045B (zh) 關於透過元資料提供至安全客戶之機密資料之電腦程式產品、電腦系統及電腦實施方法
TWI840804B (zh) 相關於安全客體資源之延後取回之電腦程式產品、電腦系統及電腦實施方法
JP2024522818A (ja) ローカルバッファを含む暗号化データ処理設計
US11201730B2 (en) Generating a protected key for selective use
US11372983B2 (en) Employing a protected key in performing operations
HK40104309A (zh) 存储安全虚拟机的诊断状态
TW202309743A (zh) 虛擬機器執行期間無法存取之前綴頁面
HK40057636B (zh) 安全操作系统影像的增量解密和完整性验证
HK40057636A (en) Incremental decryption and integrity verification of a secure operating system image