Title :
A Two-Step Execution Mechanism for Thin Secure Hypervisors
Author :
Hirano, Manabu ; Shinagawa, Takahiro ; Eiraku, Hideki ; Hasegawa, Shoichi ; Omote, Kazumasa ; Tanimoto, Koichi ; Horie, Takashi ; Mune, Seiji ; Kato, Kazuhiko ; Okuda, Takeshi ; Kawai, Eiji ; Yamaguchi, Suguru
Author_Institution :
Dept. of Inf. & Comput. Eng., Toyota Nat. Coll. of Technol., Toyota, Japan
Abstract :
Virtual machine monitors (VMMs), also called hypervisors, can be used to construct a trusted computing base (TCB) enhancing the security of existing operating systems. The complexity of a VMM-based TCB causes the high risk of security vulnerabilities. Therefore, this paper proposes a two-step execution mechanism to reduce the complexity of a VMM-based TCB. We propose a method to separate a conventional VMM-based TCB into the following two parts: (1) A thin hypervisor with security services and (2) A special guest OS for security preprocessing. A special guest OS performing security tasks can be executed in advance. After shutting down the special guest OS, a hypervisor obtains preprocessing security data and next boots a target guest OS to be protected. Thus, the proposed two-step execution mechanism can reduce run-time codes of a hypervisor. This paper shows a design, a prototype implementation and measurement results of lines of code using BitVisor, a VMM-based TCB we have developed.
Keywords :
operating systems (computers); security of data; virtual machines; BitVisor; operating system security; security preprocessing; security services; thin secure hypervisors; trusted computing base; two-step execution mechanism; virtual machine monitors; Communication system security; Computer security; Cryptography; Data security; Information security; Isolation technology; Operating systems; Runtime; Secure storage; Virtual machine monitors; Hypervisor; ID management; Security; TCB; Trusted Computing Base; VMM; Virtual machine monitor;
Conference_Titel :
Emerging Security Information, Systems and Technologies, 2009. SECURWARE '09. Third International Conference on
Conference_Location :
Athens, Glyfada
Print_ISBN :
978-0-7695-3668-2
DOI :
10.1109/SECURWARE.2009.27