Invention Grant
- Patent Title: Providing isolation in virtualized systems using trust domains
-
Application No.: US15705562Application Date: 2017-09-15
-
Publication No.: US11687654B2Publication Date: 2023-06-27
- Inventor: Ravi L. Sahita , Baiju V. Patel , Barry E. Huntley , Gilbert Neiger , Hormuzd M. Khosravi , Ido Ouziel , David M. Durham , Ioannis T. Schoinas , Siddhartha Chhabra , Carlos V. Rozas , Gideon Gerzon
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Nicholson De Vos Webster & Elliott LLP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/62 ; G06F12/14 ; H04L9/06 ; H04L9/40 ; G06F21/53 ; G06F21/71 ; G06F21/79 ; G06F9/455

Abstract:
Implementations describe providing isolation in virtualized systems using trust domains. In one implementation, a processing device includes a memory ownership table (MOT) that is access-controlled against software access. The processing device further includes a processing core to execute a trust domain resource manager (TDRM) to manage a trust domain (TD), maintain a trust domain control structure (TDCS) for managing global metadata for each TD, maintain an execution state of the TD in at least one trust domain thread control structure (TD-TCS) that is access-controlled against software accesses, and reference the MOT to obtain at least one key identifier (key ID) corresponding to an encryption key assigned to the TD, the key ID to allow the processing device to decrypt memory pages assigned to the TD responsive to the processing device executing in the context of the TD, the memory pages assigned to the TD encrypted with the encryption key.
Public/Granted literature
- US20190087575A1 PROVIDING ISOLATION IN VIRTUALIZED SYSTEMS USING TRUST DOMAINS Public/Granted day:2019-03-21
Information query