×

Threat-aware microvisor

  • US 9,740,857 B2
  • Filed: 03/28/2014
  • Issued: 08/22/2017
  • Est. Priority Date: 01/16/2014
  • Status: Active Grant
First Claim
Patent Images

1. A system comprising:

  • a central processing unit (CPU) adapted to execute a process, an operating system kernel and a virtualization module; and

    a memory configured to store the process, the operating system kernel and the virtualization module, the virtualization module including;

    a first protection domain having a plurality of execution contexts and scheduling contexts, each execution context linked to a scheduling context and interacting with capabilities, wherein the capabilities of the first protection domain are configured to specify access control permissions to kernel resources accessible by the process, the first protection domain associated with services provided to the process by the operating system kernel to control the kernel resources accessible by the process; and

    a second protection domain configured as a clone of the first protection domain except for the capabilities, wherein in response to execution of the process, the capabilities of the second protection domain are configured to specify limited access control permissions to the kernel resources accessible by the process, the second protection domain associated with the process, wherein the virtualization module is organized as the first protection domain and the second protection domain for the operating system kernel.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×