Trusted File Indirection
Abstract
Methods and systems for performing file transfers across different domains hosted by a virtualization server are described herein. A trusted domain (Dom 0) may indicate that one or more files, directories, and/or volumes are available to a second domain (guest domain) by updating share information stored in a key value store. The guest domain may enumerate the shared files to appear as if within its own file system structure. The guest domain intercepts calls to its file system, determines whether the requested data is actually stored in its own file system or in trusted domain, and proxies the file system call to the trusted domain when the requested data is shared by the trusted domain. Key value store information and shared data information and contents may be communicated using one or more memories shared between the trusted domain and guest domain.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
providing, by a guest domain, a file system call into a shared memory, the shared memory being accessible by the guest domain and a trusted domain, and the file system call being from an application executable on the guest domain and configured to initiate execution of the file system call on the trusted domain; receiving, from the shared memory, a result of the file system call as executed by the trusted domain; and sending, to the application and based on the result, a response to the file system call.
22 . The method of claim 21 , further comprising intercepting, via a proxy driver of the guest domain, the file system call and determining whether to execute the file system call within a file system of the guest domain or to pass the file system call to the trusted domain.
23 . The method of claim 21 , wherein the providing the file system call into the shared memory comprises passing, via a proxy driver of the guest domain, the file system call to the trusted domain using one or more pages of the shared memory.
24 . The method of claim 21 , further comprising:
intercepting, via a proxy driver of the guest domain, a first file system call for a first data file shared by the trusted domain; sending a first request, which corresponds to the first data file, to the trusted domain by writing the first request to the shared memory; executing, by the trusted domain, the first request on an associated data file in a file system of the trusted domain; writing, by the trusted domain, a response to the first request in the shared memory; and reading, via the proxy driver, the response to the first request from the shared memory.
25 . The method of claim 21 , wherein the receiving the result comprises receiving the result based on storage of metadata for files shared by the trusted domain, and wherein the metadata comprises at least one of a file name, a file type, a file location, a file size, or a file date.
26 . The method of claim 25 , further comprising monitoring, by the guest domain, for a change in memory in which to store the metadata.
27 . The method of claim 21 , wherein the shared memory is configured to prevent an overwrite of data, of the shared memory, that is unread by at least one of the guest domain or the trusted domain.
28 . A method comprising:
instructing, by a guest domain, a hypervisor to grant permission, to a trusted domain, access to one or more pages of memory of the guest domain; providing a file system call, from an application executable on the guest domain, into the one or more pages of memory to initiate execution of the file system call on the trusted domain; receiving, from the one or more pages of memory, a result of the file system call as executed by the trusted domain; and sending, to the application and based on the result, a response to the file system call.
29 . The method of claim 28 , further comprising intercepting, via a proxy driver of the guest domain, the file system call and determining whether to execute the file system call within a file system of the guest domain or to pass the file system call to the trusted domain.
30 . The method of claim 28 , wherein the providing the file system call into the one or more pages of memory comprises passing, via a proxy driver of the guest domain, the file system call to the trusted domain using the one or more pages of memory.
31 . The method of claim 28 , further comprising:
intercepting, via a proxy driver of the guest domain, a first file system call for a first data file shared by the trusted domain; sending a first request, which corresponds to the first data file, to the trusted domain by writing the first request to the one or more pages of memory; executing, by the trusted domain, the first request on an associated data file in a file system of the trusted domain; writing, by the trusted domain, a response to the first request in the one or more pages of memory; and reading, via the proxy driver, the response to the first request from the one or more pages of memory.
32 . The method of claim 28 , wherein the receiving the result comprises receiving the result based on a key value store storing file metadata for each data file shared by the trusted domain, and wherein the file metadata comprises at least one of a file name, a file type, a file location, a file size, or a file date.
33 . The method of claim 32 , wherein the key value store is located within the trusted domain, and the method further comprises monitoring, by the guest domain, for a change in the key value store.
34 . The method of claim 28 , wherein the one or more pages of memory are configured to prevent an overwrite of data, of the one or more pages of memory, that is unread by at least one of the guest domain or the trusted domain.
35 . A computing device comprising:
one or more processors; and memory storing instructions that, when executed by the one or more processors, cause the computing device to:
instruct a hypervisor to grant permission, to a trusted domain, access to one or more pages of memory of the computing device;
provide a file system call, from an application executable on the computing device, into the one or more pages of memory to initiate execution of the file system call on the trusted domain;
receive, from the one or more pages of memory, a result of the file system call as executed by the trusted domain; and
send, to the application and based on the result, a response to the file system call.
36 . The computing device of claim 35 , wherein the instructions, when executed by the one or more processors, cause the computing device to provide the file system call into the one or more pages of memory by passing, via a proxy driver of the computing device, the file system call to the trusted domain using the one or more pages of memory.
37 . The computing device of claim 35 , wherein the instructions, when executed by the one or more processors, further cause the computing device to:
intercept, via a proxy driver of the computing device, a first file system call for a first data file shared by the trusted domain; send a first request, which corresponds to the first data file, to the trusted domain by writing the first request to the one or more pages of memory; execute, by the trusted domain, the first request on an associated data file in a file system of the trusted domain; write, by the trusted domain, a response to the first request in the one or more pages of memory; and read, via the proxy driver, the response to the first request from the one or more pages of memory.
38 . The computing device of claim 35 , wherein the instructions, when executed by the one or more processors, cause the computing device to receive the result based on a key value store storing file metadata for each data file shared by the trusted domain, and wherein the file metadata comprises at least one of a file name, a file type, a file location, a file size, or a file date.
39 . The computing device of claim 38 , wherein the key value store is located within the trusted domain, and the instructions, when executed by the one or more processors, further cause the computing device to monitor, by the computing device, for a change in the key value store.
40 . The computing device of claim 35 , wherein the one or more pages of memory are configured to prevent an overwrite of data, of the one or more pages of memory, that is unread by at least one of the computing device or the trusted domain.Join the waitlist — get patent alerts
Track US2021182239A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.