• DocumentCode
    3069346
  • Title

    A Two-Step Execution Mechanism for Thin Secure Hypervisors

  • Author

    Hirano, Manabu ; Shinagawa, Takahiro ; Eiraku, Hideki ; Hasegawa, Shoichi ; Omote, Kazumasa ; Tanimoto, Koichi ; Horie, Takashi ; Mune, Seiji ; Kato, Kazuhiko ; Okuda, Takeshi ; Kawai, Eiji ; Yamaguchi, Suguru

  • Author_Institution
    Dept. of Inf. & Comput. Eng., Toyota Nat. Coll. of Technol., Toyota, Japan
  • fYear
    2009
  • fDate
    18-23 June 2009
  • Firstpage
    129
  • Lastpage
    135
  • Abstract
    Virtual machine monitors (VMMs), also called hypervisors, can be used to construct a trusted computing base (TCB) enhancing the security of existing operating systems. The complexity of a VMM-based TCB causes the high risk of security vulnerabilities. Therefore, this paper proposes a two-step execution mechanism to reduce the complexity of a VMM-based TCB. We propose a method to separate a conventional VMM-based TCB into the following two parts: (1) A thin hypervisor with security services and (2) A special guest OS for security preprocessing. A special guest OS performing security tasks can be executed in advance. After shutting down the special guest OS, a hypervisor obtains preprocessing security data and next boots a target guest OS to be protected. Thus, the proposed two-step execution mechanism can reduce run-time codes of a hypervisor. This paper shows a design, a prototype implementation and measurement results of lines of code using BitVisor, a VMM-based TCB we have developed.
  • Keywords
    operating systems (computers); security of data; virtual machines; BitVisor; operating system security; security preprocessing; security services; thin secure hypervisors; trusted computing base; two-step execution mechanism; virtual machine monitors; Communication system security; Computer security; Cryptography; Data security; Information security; Isolation technology; Operating systems; Runtime; Secure storage; Virtual machine monitors; Hypervisor; ID management; Security; TCB; Trusted Computing Base; VMM; Virtual machine monitor;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Emerging Security Information, Systems and Technologies, 2009. SECURWARE '09. Third International Conference on
  • Conference_Location
    Athens, Glyfada
  • Print_ISBN
    978-0-7695-3668-2
  • Type

    conf

  • DOI
    10.1109/SECURWARE.2009.27
  • Filename
    5211032