×

Systems and Methods Involving Features of Hardware Virtualization, Hypervisor, APIs of Interest, and/or Other Features

  • US 20150332048A1
  • Filed: 05/15/2015
  • Published: 11/19/2015
  • Est. Priority Date: 05/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method for processing information securely, the method comprising:

  • partitioning hardware platform resources via a separation kernel hypervisor into a plurality of guest operating system virtual machine protection domains;

    providing a dedicated virtualization assistance layer (VAL) including a virtual representation of the hardware platform that is a virtual machine in each of the guest operating system virtual machine protection domains such that the dedicated VAL security processing is not performed in the separation kernel hypervisor;

    processing the virtual machine via another guest;

    hosting at least one detection mechanism that executes within the virtual hardware platform in each of the plurality of guest operating system virtual machine protection domains via the separation kernel hypervisor;

    upon detection of suspect behavior, securely transitioning execution to the detection mechanism within the VAL in a manner isolated from the guest operating system;

    securely determining, via the detection mechanism, a policy decision regarding the suspect behavior; and

    transitioning execution back to the separation kernel hypervisor to continue processing regarding enforcement of or taking action in connection with the policy decision.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×