Invention Grant
- Patent Title: Securing code loading by a guest in a virtual environment
-
Application No.: US15056558Application Date: 2016-02-29
-
Publication No.: US10057069B2Publication Date: 2018-08-21
- Inventor: Paolo Bonzini , Michael Tsirkin
- Applicant: Red Hat Israel, Ltd.
- Applicant Address: IL Ra'anana
- Assignee: Red Hat Israel, Ltd.
- Current Assignee: Red Hat Israel, Ltd.
- Current Assignee Address: IL Ra'anana
- Agency: Haynes and Boone, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32 ; G06F9/455

Abstract:
Methods, systems, and computer program products are included for loading a code module. A method includes verifying, by a guest, a digital signature of a code module stored in an initial guest memory buffer. The guest copies the verified code module stored at the initial guest memory buffer into a target guest memory buffer and applies, using one or more symbol entries, one or more relocations to the verified code module stored at the target guest memory buffer. The guest sends a request to a hypervisor to set the target guest memory buffer to a write-protect mode. In response to a determination that first content stored in the initial guest memory buffer corresponds to second content stored in the target guest memory buffer, the guest sends a request to the hypervisor to set the target guest memory buffer to an executable mode.
Public/Granted literature
- US20170250817A1 SECURING CODE LOADING BY A GUEST IN A VIRTUAL ENVIRONMENT Public/Granted day:2017-08-31
Information query