US2022121471A1PendingUtilityA1

Device virtualization security layer

Assignee: AT & T IP I LPPriority: Sep 26, 2019Filed: Dec 27, 2021Published: Apr 21, 2022
Est. expirySep 26, 2039(~13.2 yrs left)· nominal 20-yr term from priority
G06F 9/45558G06F 21/53G06F 21/562G06F 2009/45587G06F 9/45533G06F 9/44505G06F 40/284G06F 40/242G06F 2009/45562G06F 9/45545H04L 63/0428G06F 21/602H04L 63/18G06F 2009/45583G06F 40/289
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A processing system of a device having at least one processor may obtain a set of codes from a virtual machine orchestrator via a virtualization security controller of the processing system, obtain a first virtual machine configuration file from the virtual machine orchestrator via a hypervisor of the processing system, and pass at least one code of the set of codes from the virtualization security controller to the hypervisor. The processing system may then apply, via the hypervisor, a decryption to the first virtual machine configuration file using the at least one code, determine that a threshold percentage of content of the first virtual machine configuration file comprises dictionary-recognizable words in accordance with the decryption, and instantiate, via the hypervisor, a first virtual machine in accordance with the first virtual machine configuration file when it is determined that the threshold percentage of the content comprises dictionary-recognizable words.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 obtaining, by a processing system of a device including at least one processor, an indication of available memory resources of the device, wherein the indication of available memory resources is obtained via a virtualization security controller of the processing system from a hypervisor of the processing system;   writing, by the processing system, via the virtualization security controller, a set of data to at least a portion of the available memory resources of the device;   determining, by the processing system via the virtualization security controller, that a memory conflict exists in response to the writing;   generating, by the processing system via the virtualization security controller, an alert of a possible unauthorized memory usage in response to determining the memory conflict.   
     
     
         2 . The method of  claim 1 , wherein the virtualization security controller operates in a logical layer of the device that is between a hardware layer of the device and the hypervisor. 
     
     
         3 . The method of  claim 1 , wherein the indication of available memory resources of the device includes information regarding memory allocations of one or more virtual machines that are installed on the device and that are managed via the hypervisor. 
     
     
         4 . The method of  claim 3 , wherein the indication of available memory resources of the device further includes memory allocations of one or more authorized processes that are operating in accordance with a host operating system of the device. 
     
     
         5 . The method of  claim 1 , wherein the memory conflict is determined by a failure of the writing of the set of data. 
     
     
         6 . The method of  claim 1 , wherein the memory conflict is determined by inspecting the at least the portion of the available memory resources of the device, after the writing, and detecting that the set of data is changed. 
     
     
         7 . The method of  claim 1 , further comprising:
 identifying a virtual machine that is operating on at least the portion of the available memory.   
     
     
         8 . The method of  claim 7 , further comprising:
 terminating the virtual machine that is identified.   
     
     
         9 . A non-transitory computer-readable medium storing instructions which, when executed by a processing system of a device including at least one processor, cause the processor to perform operations comprising:
 obtaining an indication of available memory resources of the device, wherein the indication of available memory resources is obtained via a virtualization security controller of the processing system from a hypervisor of the processing system;   writing via the virtualization security controller, a set of data to at least a portion of the available memory resources of the device;   determining, via the virtualization security controller, that a memory conflict exists in response to the writing;   generating, via the virtualization security controller, an alert of a possible unauthorized memory usage in response to determining the memory conflict.   
     
     
         10 . The non-transitory computer-readable medium of  claim 9 , wherein the virtualization security controller operates in a logical layer of the device that is between a hardware layer of the device and the hypervisor. 
     
     
         11 . The non-transitory computer-readable medium of  claim 9 , wherein the indication of available memory resources of the device includes information regarding memory allocations of one or more virtual machines that are installed on the device and that are managed via the hypervisor. 
     
     
         12 . The non-transitory computer-readable medium of  claim 11 , wherein the indication of available memory resources of the device further includes memory allocations of one or more authorized processes that are operating in accordance with a host operating system of the device. 
     
     
         13 . The non-transitory computer-readable medium of  claim 9 , wherein the memory conflict is determined by a failure of the writing of the set of data. 
     
     
         14 . The non-transitory computer-readable medium of  claim 9 , wherein the memory conflict is determined by inspecting the at least the portion of the available memory resources of the device, after the writing, and detecting that the set of data is changed. 
     
     
         15 . The non-transitory computer-readable medium of  claim 9 , the operations further comprising:
 identifying a virtual machine that is operating on at least the portion of the available memory.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , the operations further comprising:
 terminating the virtual machine that is identified.   
     
     
         17 . An apparatus comprising:
 a processing system of a device including at least one processor; and   a non-transitory computer-readable medium storing instructions which, when executed by the processing system, cause the processing system to perform operations, the operations comprising:
 obtaining an indication of available memory resources of the device, wherein the indication of available memory resources is obtained via a virtualization security controller of the processing system from a hypervisor of the processing system; 
 writing via the virtualization security controller, a set of data to at least a portion of the available memory resources of the device; 
 determining, via the virtualization security controller, that a memory conflict exists in response to the writing; 
 generating, via the virtualization security controller, an alert of a possible unauthorized memory usage in response to determining the memory conflict. 
   
     
     
         18 . The apparatus of  claim 17 , wherein the virtualization security controller operates in a logical layer of the device that is between a hardware layer of the device and the hypervisor. 
     
     
         19 . The apparatus of  claim 17 , wherein the indication of available memory resources of the device includes information regarding memory allocations of one or more virtual machines that are installed on the device and that are managed via the hypervisor. 
     
     
         20 . The apparatus of  claim 19 , wherein the indication of available memory resources of the device further includes memory allocations of one or more authorized processes that are operating in accordance with a host operating system of the device.

Join the waitlist — get patent alerts

Track US2022121471A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.