US2015278512A1PendingUtilityA1

Virtualization based intra-block workload isolation

Assignee: INTEL CORPPriority: Mar 28, 2014Filed: Mar 28, 2014Published: Oct 1, 2015
Est. expiryMar 28, 2034(~7.6 yrs left)· nominal 20-yr term from priority
G06F 9/45558G06F 2009/45587G06F 21/84H04L 9/3247G06F 21/53G06F 9/45504G06F 21/554G06F 9/5072G06F 2213/0038G06F 9/5011G06F 2221/2149G06F 9/45533
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Generally, this disclosure provides systems, devices, methods and computer readable media for virtualization-based intra-block workload isolation. The system may include a virtual machine manager (VMM) module to create a secure virtualization environment or sandbox. The system may also include a processor block to load data into a first region of the sandbox and to generate a workload package based on the data. The workload package is stored in a second region of the sandbox. The system may further include an operational block to fetch and execute instructions from the workload package.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for intra-block workload isolation, said system comprising:
 a virtual machine manager (VMM) module to create a secure virtualization environment (sandbox);   a processor block to load data into a first region of said sandbox;   said processor block further to generate a workload package, associated with said workload, said workload package based on said data and stored in a second region of said sandbox; and   an operational block to fetch and execute instructions from said workload package.   
     
     
         2 . The system of  claim 1 , wherein said VMM is further to set access controls of said second region of said sandbox to provide intra-block isolation of code, data and state information associated with said workload. 
     
     
         3 . The system of  claim 1 , wherein said VMM is further to set access controls of said second region of said sandbox to a non-executable mode. 
     
     
         4 . The system of  claim 3 , wherein said VMM is further to set access controls of said second region of said sandbox to an executable mode for said operational block during a selected period of execution of said workload package. 
     
     
         5 . The system of  claim 1 , wherein said operational block is further to write results to a third region of said sandbox, said results based on execution of said workload package. 
     
     
         6 . The system of  claim 1 , wherein said processor block is further to cryptographically authenticate said data. 
     
     
         7 . The system of  claim 1 , wherein said VMM is further to provide page table based translation between virtual and physical addresses associated with said sandbox and further to provide read/write/execute access control associated with said addresses. 
     
     
         8 . The system of  claim 1 , wherein said operational block is selected from the group consisting of a graphics processing unit, a device controller, a wireless communications interface, a digital signal processor and an audio processor. 
     
     
         9 . The system of  claim 1 , wherein said system is a system-on-a-chip. 
     
     
         10 . The system of  claim 1 , wherein said system is a smart phone, a laptop computing device, a smart TV or a smart tablet. 
     
     
         11 . The system of  claim 1 , further comprising a user interface, wherein said user interface is a touch screen. 
     
     
         12 . A method for intra-block workload isolation, said method comprising:
 creating a secure virtualization environment (sandbox) associated with a processor block of a system, said sandbox managed by a virtual machine manager (VMM);   loading data into said sandbox;   authenticating said data;   generating a workload package, associated with said workload, said workload package based on said data and stored in a non-executable region of memory in said sandbox; and   submitting said workload package to an operational block of said system for execution from said sandbox.   
     
     
         13 . The method of  claim 12 , further comprising setting access controls on said sandbox to provide intra-block isolation of code, data and state information associated with said workload. 
     
     
         14 . The method of  claim 12 , wherein said submitting further comprises requesting said VMM to enable said operational block to fetch and execute instructions from said workload package. 
     
     
         15 . The method of  claim 12 , further comprising receiving results from said operational block, said results based on said execution. 
     
     
         16 . The method of  claim 15 , wherein said receiving further comprises requesting said VMM to enable said operational block to write to a region of memory in said sandbox. 
     
     
         17 . The method of  claim 12 , wherein said operational block is selected from the group consisting of a graphics processing unit, a device controller, a wireless communications interface, a digital signal processor and an audio processor. 
     
     
         18 . The method of  claim 12 , wherein said authenticating further comprises verifying an encryption signature. 
     
     
         19 . The method of  claim 12 , wherein said VMM provides page table based translation between virtual and physical addresses associated with said sandbox and further provides read/write/execute access control associated with said addresses. 
     
     
         20 . At least one computer-readable storage medium having instructions stored thereon which when executed by a processor result in the following operations for intra-block workload isolation, said operations comprising:
 creating a secure virtualization environment (sandbox) associated with a processor block of a system, said sandbox managed by a virtual machine manager (VMM);   loading data into said sandbox;   authenticating said data;   generating a workload package, associated with said workload, said workload package based on said data and stored in a non-executable region of memory in said sandbox; and   submitting said workload package to an operational block of said system for execution from said sandbox.   
     
     
         21 . The computer-readable storage medium of  claim 20 , further comprising the operation of setting access controls on said sandbox to provide intra-block isolation of code, data and state information associated with said workload. 
     
     
         22 . The computer-readable storage medium of  claim 20 , wherein said submitting further comprises the operation of requesting said VMM to enable said operational block to fetch and execute instructions from said workload package. 
     
     
         23 . The computer-readable storage medium of  claim 20 , further comprising the operation of receiving results from said operational block, said results based on said execution. 
     
     
         24 . The computer-readable storage medium of  claim 23 , wherein said receiving further comprises the operation of requesting said VMM to enable said operational block to write to a region of memory in said sandbox. 
     
     
         25 . The computer-readable storage medium of  claim 18 , wherein said authenticating further comprises the operation of verifying an encryption signature. 
     
     
         26 . The computer-readable storage medium of  claim 18 , wherein said VMM provides page table based translation between virtual and physical addresses associated with said sandbox and further provides read/write/execute access control associated with said addresses.

Join the waitlist — get patent alerts

Track US2015278512A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.