• DocumentCode
    738165
  • Title

    H-SVM: Hardware-Assisted Secure Virtual Machines under a Vulnerable Hypervisor

  • Author

    Jin, Seongwook ; Ahn, Jeongseob ; Seol, Jinho ; Cha, Sanghoon ; Huh, Jaehyuk ; Maeng, Seungryoul

  • Author_Institution
    Computer Science Department, KAIST, 335 Gwahak-ro (373-1 Guseong-dong), Yuseong-Gu, Daejeon, Republic of Korea
  • Volume
    64
  • Issue
    10
  • fYear
    2015
  • Firstpage
    2833
  • Lastpage
    2846
  • Abstract
    With increasing demands on cloud computing, protecting guest virtual machines (VMs) from malicious attackers has become critical to provide secure services. The current cloud security model with software-based virtualization relies on the invulnerability of the software hypervisor and its trustworthy administrator with the root permission. However, compromising the hypervisor with remote attacks or root permission grants the attackers with a full access capability to the memory and context of a guest VM. This paper proposes a HW-based approach to protect guest VMs even under an untrusted hypervisor. With the proposed mechanism, memory isolation is provided by the secure hardware, which is much less vulnerable than the software hypervisor. The proposed mechanism extends the current hardware support for memory virtualization based on nested paging with a small extra hardware cost. The hypervisor can still flexibly allocate physical memory pages to virtual machines for efficient resource management. In addition to the system design for secure virtualization, this paper presents a prototype implementation using system management mode. Although the current system management mode is not intended for security functions and thus limits the performance and complete protection, the prototype implementation proves the feasibility of the proposed design.
  • Keywords
    Context; Hardware; Memory management; Registers; Virtual machine monitors; Virtual machining; Virtualization; Cloud Computing; Cloud computing; Security; Virtualization; security; virtualization;
  • fLanguage
    English
  • Journal_Title
    Computers, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    0018-9340
  • Type

    jour

  • DOI
    10.1109/TC.2015.2389792
  • Filename
    7005439