US2023315857A1PendingUtilityA1

Providing isolation in virtualized systems using trust domains

Assignee: INTEL CORPPriority: Sep 15, 2017Filed: Apr 5, 2023Published: Oct 5, 2023
Est. expirySep 15, 2037(~11.1 yrs left)· nominal 20-yr term from priority
G06F 21/57G06F 9/45558G06F 21/6245G06F 2221/2149G06F 2221/2107G06F 12/1408G06F 21/53G06F 21/6218H04L 9/0618H04L 63/061G06F 21/71G06F 21/79G06F 2009/45587G06F 21/602G06F 21/64G06F 2212/1052
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, a processing device includes a memory ownership table (MOT) that is access-controlled against software access. The processing device further includes a processing core to execute a trust domain resource manager (TDRM) to manage a trust domain (TD), maintain a trust domain control structure (TDCS) for managing global metadata for each TD, maintain an execution state of the TD in at least one trust domain thread control structure (TD-TCS) that is access-controlled against software accesses, and reference the MOT to obtain at least one key identifier (key ID) corresponding to an encryption key assigned to the TD, the key ID to allow the processing device to decrypt memory pages assigned to the TD responsive to the processing device executing in the context of the TD, the memory pages assigned to the TD encrypted with the encryption key.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . An apparatus comprising:
 a memory to be protected through encryption by a multi-key total memory encryption (MK-TME) engine; and   a processor to execute instructions to invoke a virtual machine manager (VMM) to manage one or more trust domains (TDs), wherein managing a TD includes execution of a first instruction to add a first memory page to the TD, the first instruction is to taken input of an address of the TD and a host physical address of the first memory page assigned to the trust domain, and wherein the execution of the first instruction comprises:
 copying a source memory page to the first memory page using an encryption key assigned to the TD, and 
 updating a first data structure to indicate the addition of the first memory page to the TD. 
   
     
     
         3 . The apparatus of  claim 2 , wherein the address of the TD identifies a location of the TD that stores a key identifier of the TD. 
     
     
         4 . The apparatus of  claim 3 , wherein the key identifier of the TD is assigned to the TD during creation of the TD. 
     
     
         5 . The apparatus of  claim 2 , wherein managing the TD includes execution of a second instruction to create the TD, and wherein the execution of the second instruction comprises:
 assigning a key identifier to the TD for selecting the encryption key;   allocating a second memory page to the TD.   
     
     
         6 . The apparatus of  claim 5 , further comprising a plurality of bytes to store Secure Hash Algorithms (SHA)-384 measurements of initial content of the TD during the creation of the TD. 
     
     
         7 . The apparatus of  claim 2 , wherein managing the TD includes execution a third instruction to enter the TD, and wherein the execution of the third instruction comprises:
 loading a saved state of the TD from a second data structure, and   starting TD execution, wherein execution state of the TD is saved in the second data structure upon TD exit.   
     
     
         8 . The apparatus of  claim 2 , wherein managing the TD further includes allocating a state-save area for the TD, wherein the state-save area is protected by the encryption key assigned to the TD, and wherein upon exiting the TD, execution state of the TD is to be saved in the state-save area for the TD. 
     
     
         9 . A method comprising:
 protecting a memory through encryption by a multi-key total memory encryption (MK-TME) engine;   executing, by a processor, instructions to invoke a virtual machine manager (VMM) to manage one or more trust domains (TDs), wherein managing a TD includes execution of a first instruction to add a first memory page to the TD, the first instruction is to taken input of an address of the TD and a host physical address of the first memory page assigned to the trust domain, and wherein the execution of the first instruction comprises:
 copying a source memory page to the first memory page using an encryption key assigned to the TD, and 
 updating a first data structure to indicate the addition of the first memory page to the TD. 
   
     
     
         10 . The method of  claim 9 , wherein the address of the TD identifies a location of the TD that stores a key identifier of the TD. 
     
     
         11 . The method of  claim 10 , wherein the key identifier of the TD is assigned to the TD during creation of the TD. 
     
     
         12 . The method of  claim 9 , wherein managing the TD includes execution of a second instruction to create the TD, and wherein the execution of the second instruction comprises:
 assigning a key identifier to the TD for selecting the encryption key;   allocating a second memory page to the TD.   
     
     
         13 . The method of  claim 12 , further comprising a plurality of bytes to store Secure Hash Algorithms (SHA)-384 measurements of initial content of the TD during the creation of the TD. 
     
     
         14 . The method of  claim 9 , wherein managing the TD includes execution a third instruction to enter the TD, and wherein the execution of the third instruction comprises:
 loading a saved state of the TD from a second data structure, and   starting TD execution, wherein execution state of the TD is saved in the second data structure upon TD exit.   
     
     
         15 . The method of  claim 9 , wherein managing the TD further includes allocating a state-save area for the TD, wherein the state-save area is protected by the encryption key assigned to the TD, and wherein upon exiting the TD, execution state of the TD is to be saved in the state-save area for the TD. 
     
     
         16 . A non-transitory computer-readable storage medium storing instructions that when executed by a processor of a computing system, causes the computing system to perform:
 protecting a memory through encryption by a multi-key total memory encryption (MK-TME) engine;   executing, by a processor, instructions to invoke a virtual machine manager (VMM) to manage one or more trust domains (TDs), wherein managing a TD includes execution of a first instruction to add a first memory page to the TD, the first instruction is to taken input of an address of the TD and a host physical address of the first memory page assigned to the trust domain, and wherein the execution of the first instruction comprises:
 copying a source memory page to the first memory page using an encryption key assigned to the TD, and 
 updating a first data structure to indicate the addition of the first memory page to the TD. 
   
     
     
         17 . The non-transitory computer-readable storage medium of  claim 16 , wherein the address of the TD identifies a location of the TD that stores a key identifier of the TD. 
     
     
         18 . The non-transitory computer-readable storage medium of  claim 17 , wherein the key identifier of the TD is assigned to the TD during creation of the TD. 
     
     
         19 . The non-transitory computer-readable storage medium of  claim 16 , wherein managing the TD includes execution of a second instruction to create the TD, and wherein the execution of the second instruction comprises:
 assigning a key identifier to the TD for selecting the encryption key;   allocating a second memory page to the TD.   
     
     
         20 . The non-transitory computer-readable storage medium of  claim 16 , wherein managing the TD includes execution a third instruction to enter the TD, and wherein the execution of the third instruction comprises:
 loading a saved state of the TD from a second data structure, and   starting TD execution, wherein execution state of the TD is saved in the second data structure upon TD exit.   
     
     
         21 . The non-transitory computer-readable storage medium of  claim 16 , wherein managing the TD further includes allocating a state-save area for the TD, wherein the state-save area is protected by the encryption key assigned to the TD, and wherein upon exiting the TD, execution state of the TD is to be saved in the state-save area for the TD.

Join the waitlist — get patent alerts

Track US2023315857A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.