Invention Grant
US07975117B2 Enforcing isolation among plural operating systems 有权
在多个操作系统之间实现隔离

Enforcing isolation among plural operating systems
Abstract:
Plural guest operating systems run on a computer, where a security kernel enforces a policy of isolation among the guest operating systems. An exclusion vector defines a set of pages that cannot be accessed by direct memory access (DMA) devices. The security kernel enforces an isolation policy by causing certain pages to be excluded from direct access. Thus, device drivers in guest operating systems are permitted to control DMA devices directly without virtualization of those devices, while each guest is prevented from using DMA devices to access pages that the guest is not permitted to access under the policy.
Public/Granted literature
Information query
Patent Agency Ranking
0/0