PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS
Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, an apparatus comprises: a memory encryption engine to protect memory using encryption; and a processor to execute one or more instructions to allow a virtual machine manager (VMM) to manag...
Gespeichert in:
Hauptverfasser: | , , , , , , , , , , |
---|---|
Format: | Patent |
Sprache: | eng ; fre ; ger |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
container_end_page | |
---|---|
container_issue | |
container_start_page | |
container_title | |
container_volume | |
creator | Ouziel, Ido Durham, David M Neiger, Gilbert Rozas, Carlos V Khosravi, Hormuzd M Chhabra, Siddhartha Sahita, Ravi L Schoinas, Ioannis T Gerzon, Gideon Patel, Baiju V Huntley, Barry E |
description | Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, an apparatus comprises: a memory encryption engine to protect memory using encryption; and a processor to execute one or more instructions to allow a virtual machine manager (VMM) to manage a trust domain (TD). The processor is to support at least one of a first instruction to add a memory page to the TD, wherein execution of the first instruction is to use an address of TD control structure, an address of a source page, and an address of destination page to: copy the source memory page to the destination page using an encryption key identified in the TD control structure, a second instruction, wherein execution of the second instruction is to initialize the TD control structure for a TD and generate the encryption key, or a third instruction, wherein execution of the third instruction is to enter the TD and load a saved state of the TD from a data structure. |
format | Patent |
fullrecord | <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_EP4379592A2</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>EP4379592A2</sourcerecordid><originalsourceid>FETCH-epo_espacenet_EP4379592A23</originalsourceid><addsrcrecordid>eNrjZLALCPIP83Tx9HNX8Az293EM8fT3U_D0UwjzDAoJdfTxjHJ1UQiODA5x9Q1WCA0GKQsJCg0OUXDx93X09AvmYWBNS8wpTuWF0twMCm6uIc4euqkF-fGpxQWJyal5qSXxrgEmxuaWppZGjkbGRCgBAFbSKnY</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS</title><source>esp@cenet</source><creator>Ouziel, Ido ; Durham, David M ; Neiger, Gilbert ; Rozas, Carlos V ; Khosravi, Hormuzd M ; Chhabra, Siddhartha ; Sahita, Ravi L ; Schoinas, Ioannis T ; Gerzon, Gideon ; Patel, Baiju V ; Huntley, Barry E</creator><creatorcontrib>Ouziel, Ido ; Durham, David M ; Neiger, Gilbert ; Rozas, Carlos V ; Khosravi, Hormuzd M ; Chhabra, Siddhartha ; Sahita, Ravi L ; Schoinas, Ioannis T ; Gerzon, Gideon ; Patel, Baiju V ; Huntley, Barry E</creatorcontrib><description>Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, an apparatus comprises: a memory encryption engine to protect memory using encryption; and a processor to execute one or more instructions to allow a virtual machine manager (VMM) to manage a trust domain (TD). The processor is to support at least one of a first instruction to add a memory page to the TD, wherein execution of the first instruction is to use an address of TD control structure, an address of a source page, and an address of destination page to: copy the source memory page to the destination page using an encryption key identified in the TD control structure, a second instruction, wherein execution of the second instruction is to initialize the TD control structure for a TD and generate the encryption key, or a third instruction, wherein execution of the third instruction is to enter the TD and load a saved state of the TD from a data structure.</description><language>eng ; fre ; ger</language><subject>CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC DIGITAL DATA PROCESSING ; PHYSICS</subject><creationdate>2024</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&date=20240605&DB=EPODOC&CC=EP&NR=4379592A2$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,776,881,25542,76290</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&date=20240605&DB=EPODOC&CC=EP&NR=4379592A2$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>Ouziel, Ido</creatorcontrib><creatorcontrib>Durham, David M</creatorcontrib><creatorcontrib>Neiger, Gilbert</creatorcontrib><creatorcontrib>Rozas, Carlos V</creatorcontrib><creatorcontrib>Khosravi, Hormuzd M</creatorcontrib><creatorcontrib>Chhabra, Siddhartha</creatorcontrib><creatorcontrib>Sahita, Ravi L</creatorcontrib><creatorcontrib>Schoinas, Ioannis T</creatorcontrib><creatorcontrib>Gerzon, Gideon</creatorcontrib><creatorcontrib>Patel, Baiju V</creatorcontrib><creatorcontrib>Huntley, Barry E</creatorcontrib><title>PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS</title><description>Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, an apparatus comprises: a memory encryption engine to protect memory using encryption; and a processor to execute one or more instructions to allow a virtual machine manager (VMM) to manage a trust domain (TD). The processor is to support at least one of a first instruction to add a memory page to the TD, wherein execution of the first instruction is to use an address of TD control structure, an address of a source page, and an address of destination page to: copy the source memory page to the destination page using an encryption key identified in the TD control structure, a second instruction, wherein execution of the second instruction is to initialize the TD control structure for a TD and generate the encryption key, or a third instruction, wherein execution of the third instruction is to enter the TD and load a saved state of the TD from a data structure.</description><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>PHYSICS</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2024</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZLALCPIP83Tx9HNX8Az293EM8fT3U_D0UwjzDAoJdfTxjHJ1UQiODA5x9Q1WCA0GKQsJCg0OUXDx93X09AvmYWBNS8wpTuWF0twMCm6uIc4euqkF-fGpxQWJyal5qSXxrgEmxuaWppZGjkbGRCgBAFbSKnY</recordid><startdate>20240605</startdate><enddate>20240605</enddate><creator>Ouziel, Ido</creator><creator>Durham, David M</creator><creator>Neiger, Gilbert</creator><creator>Rozas, Carlos V</creator><creator>Khosravi, Hormuzd M</creator><creator>Chhabra, Siddhartha</creator><creator>Sahita, Ravi L</creator><creator>Schoinas, Ioannis T</creator><creator>Gerzon, Gideon</creator><creator>Patel, Baiju V</creator><creator>Huntley, Barry E</creator><scope>EVB</scope></search><sort><creationdate>20240605</creationdate><title>PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS</title><author>Ouziel, Ido ; Durham, David M ; Neiger, Gilbert ; Rozas, Carlos V ; Khosravi, Hormuzd M ; Chhabra, Siddhartha ; Sahita, Ravi L ; Schoinas, Ioannis T ; Gerzon, Gideon ; Patel, Baiju V ; Huntley, Barry E</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_EP4379592A23</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng ; fre ; ger</language><creationdate>2024</creationdate><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>PHYSICS</topic><toplevel>online_resources</toplevel><creatorcontrib>Ouziel, Ido</creatorcontrib><creatorcontrib>Durham, David M</creatorcontrib><creatorcontrib>Neiger, Gilbert</creatorcontrib><creatorcontrib>Rozas, Carlos V</creatorcontrib><creatorcontrib>Khosravi, Hormuzd M</creatorcontrib><creatorcontrib>Chhabra, Siddhartha</creatorcontrib><creatorcontrib>Sahita, Ravi L</creatorcontrib><creatorcontrib>Schoinas, Ioannis T</creatorcontrib><creatorcontrib>Gerzon, Gideon</creatorcontrib><creatorcontrib>Patel, Baiju V</creatorcontrib><creatorcontrib>Huntley, Barry E</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>Ouziel, Ido</au><au>Durham, David M</au><au>Neiger, Gilbert</au><au>Rozas, Carlos V</au><au>Khosravi, Hormuzd M</au><au>Chhabra, Siddhartha</au><au>Sahita, Ravi L</au><au>Schoinas, Ioannis T</au><au>Gerzon, Gideon</au><au>Patel, Baiju V</au><au>Huntley, Barry E</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS</title><date>2024-06-05</date><risdate>2024</risdate><abstract>Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, an apparatus comprises: a memory encryption engine to protect memory using encryption; and a processor to execute one or more instructions to allow a virtual machine manager (VMM) to manage a trust domain (TD). The processor is to support at least one of a first instruction to add a memory page to the TD, wherein execution of the first instruction is to use an address of TD control structure, an address of a source page, and an address of destination page to: copy the source memory page to the destination page using an encryption key identified in the TD control structure, a second instruction, wherein execution of the second instruction is to initialize the TD control structure for a TD and generate the encryption key, or a third instruction, wherein execution of the third instruction is to enter the TD and load a saved state of the TD from a data structure.</abstract><oa>free_for_read</oa></addata></record> |
fulltext | fulltext_linktorsrc |
identifier | |
ispartof | |
issn | |
language | eng ; fre ; ger |
recordid | cdi_epo_espacenet_EP4379592A2 |
source | esp@cenet |
subjects | CALCULATING COMPUTING COUNTING ELECTRIC DIGITAL DATA PROCESSING PHYSICS |
title | PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS |
url | https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-02-02T01%3A44%3A30IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=Ouziel,%20Ido&rft.date=2024-06-05&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EEP4379592A2%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true |