US2015278512A1PendingUtilityA1
Virtualization based intra-block workload isolation
Est. expiryMar 28, 2034(~7.6 yrs left)· nominal 20-yr term from priority
Inventors:Prashant DewanUttam SenguptaSiddhartha ChhabraDavid M. DurhamXiaozhu KangUday SavagaonkarAlpa T. Narendra Trivedi
G06F 9/45558G06F 2009/45587G06F 21/84H04L 9/3247G06F 21/53G06F 9/45504G06F 21/554G06F 9/5072G06F 2213/0038G06F 9/5011G06F 2221/2149G06F 9/45533
54
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Generally, this disclosure provides systems, devices, methods and computer readable media for virtualization-based intra-block workload isolation. The system may include a virtual machine manager (VMM) module to create a secure virtualization environment or sandbox. The system may also include a processor block to load data into a first region of the sandbox and to generate a workload package based on the data. The workload package is stored in a second region of the sandbox. The system may further include an operational block to fetch and execute instructions from the workload package.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for intra-block workload isolation, said system comprising:
a virtual machine manager (VMM) module to create a secure virtualization environment (sandbox); a processor block to load data into a first region of said sandbox; said processor block further to generate a workload package, associated with said workload, said workload package based on said data and stored in a second region of said sandbox; and an operational block to fetch and execute instructions from said workload package.
2 . The system of claim 1 , wherein said VMM is further to set access controls of said second region of said sandbox to provide intra-block isolation of code, data and state information associated with said workload.
3 . The system of claim 1 , wherein said VMM is further to set access controls of said second region of said sandbox to a non-executable mode.
4 . The system of claim 3 , wherein said VMM is further to set access controls of said second region of said sandbox to an executable mode for said operational block during a selected period of execution of said workload package.
5 . The system of claim 1 , wherein said operational block is further to write results to a third region of said sandbox, said results based on execution of said workload package.
6 . The system of claim 1 , wherein said processor block is further to cryptographically authenticate said data.
7 . The system of claim 1 , wherein said VMM is further to provide page table based translation between virtual and physical addresses associated with said sandbox and further to provide read/write/execute access control associated with said addresses.
8 . The system of claim 1 , wherein said operational block is selected from the group consisting of a graphics processing unit, a device controller, a wireless communications interface, a digital signal processor and an audio processor.
9 . The system of claim 1 , wherein said system is a system-on-a-chip.
10 . The system of claim 1 , wherein said system is a smart phone, a laptop computing device, a smart TV or a smart tablet.
11 . The system of claim 1 , further comprising a user interface, wherein said user interface is a touch screen.
12 . A method for intra-block workload isolation, said method comprising:
creating a secure virtualization environment (sandbox) associated with a processor block of a system, said sandbox managed by a virtual machine manager (VMM); loading data into said sandbox; authenticating said data; generating a workload package, associated with said workload, said workload package based on said data and stored in a non-executable region of memory in said sandbox; and submitting said workload package to an operational block of said system for execution from said sandbox.
13 . The method of claim 12 , further comprising setting access controls on said sandbox to provide intra-block isolation of code, data and state information associated with said workload.
14 . The method of claim 12 , wherein said submitting further comprises requesting said VMM to enable said operational block to fetch and execute instructions from said workload package.
15 . The method of claim 12 , further comprising receiving results from said operational block, said results based on said execution.
16 . The method of claim 15 , wherein said receiving further comprises requesting said VMM to enable said operational block to write to a region of memory in said sandbox.
17 . The method of claim 12 , wherein said operational block is selected from the group consisting of a graphics processing unit, a device controller, a wireless communications interface, a digital signal processor and an audio processor.
18 . The method of claim 12 , wherein said authenticating further comprises verifying an encryption signature.
19 . The method of claim 12 , wherein said VMM provides page table based translation between virtual and physical addresses associated with said sandbox and further provides read/write/execute access control associated with said addresses.
20 . At least one computer-readable storage medium having instructions stored thereon which when executed by a processor result in the following operations for intra-block workload isolation, said operations comprising:
creating a secure virtualization environment (sandbox) associated with a processor block of a system, said sandbox managed by a virtual machine manager (VMM); loading data into said sandbox; authenticating said data; generating a workload package, associated with said workload, said workload package based on said data and stored in a non-executable region of memory in said sandbox; and submitting said workload package to an operational block of said system for execution from said sandbox.
21 . The computer-readable storage medium of claim 20 , further comprising the operation of setting access controls on said sandbox to provide intra-block isolation of code, data and state information associated with said workload.
22 . The computer-readable storage medium of claim 20 , wherein said submitting further comprises the operation of requesting said VMM to enable said operational block to fetch and execute instructions from said workload package.
23 . The computer-readable storage medium of claim 20 , further comprising the operation of receiving results from said operational block, said results based on said execution.
24 . The computer-readable storage medium of claim 23 , wherein said receiving further comprises the operation of requesting said VMM to enable said operational block to write to a region of memory in said sandbox.
25 . The computer-readable storage medium of claim 18 , wherein said authenticating further comprises the operation of verifying an encryption signature.
26 . The computer-readable storage medium of claim 18 , wherein said VMM provides page table based translation between virtual and physical addresses associated with said sandbox and further provides read/write/execute access control associated with said addresses.Join the waitlist — get patent alerts
Track US2015278512A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.