首页> 外文OA文献 >Analysis of Intel IA-64 processor support for a secure virtual machine monitor
【2h】

Analysis of Intel IA-64 processor support for a secure virtual machine monitor

机译:分析英特尔IA-64处理器对安全虚拟机监视器的支持

摘要

This thesis explores the Intel IA-64 architecture's capability to support a secure virtual machine monitor. The major mission of a virtual machine monitor is to provide an execution environment identical to the real machine environment for virtual machines. A VMM duplicates the real resources of a processor for virtual machines while making a virtual machine think that it is running on a real machine. As a result, a virtual machine monitor allows multiple virtual machines to run concurrently on the same machine. A secure VMM on the Intel IA-64 architecture would offer several benefits. A secure VMM would ensure that security policy is enforced by constraining information flow between the supported virtual machines. This would provide PC users with a more secure environment in which to run COTS operating systems. The Intel IA-64 architecture was analyzed to determine if it is virtualizable. Three types of virtual machine monitors and their hardware requirements have been defined. The IA-64 architecture was mapped to these hardware requirements. Analysis showed that the IA-64 architecture meets three main hardware requirements. However, IA-64 instruction set contains 18 sensitive unprivileged instructions. These instructions prevent the IA-64 architecture from being used for a Type I VMM. Several virtualization techniques used in some architectures are discussed to determine if these techniques could be applicable to virtualization of the IA-64 architecture.
机译:本文探讨了Intel IA-64架构支持安全虚拟机监视器的功能。虚拟机监视器的主要任务是为虚拟机提供与真实计算机环境相同的执行环境。 VMM为虚拟机复制处理器的实际资源,同时使虚拟机认为它在真实计算机上运行。结果,虚拟机监视器允许多个虚拟机在同一台计算机上同时运行。英特尔IA-64架构上的安全VMM将带来许多好处。安全的VMM将通过限制受支持的虚拟机之间的信息流来确保实施安全策略。这将为PC用户提供运行COTS操作系统的更安全的环境。对英特尔IA-64架构进行了分析,以确定其是否可虚拟化。已经定义了三种类型的虚拟机监视器及其硬件要求。 IA-64体系结构已映射到这些硬件要求。分析表明,IA-64体系结构满足三个主要硬件要求。但是,IA-64指令集包含18个敏感的非特权指令。这些指令可防止IA-64体系结构用于I型VMM。讨论了某些体系结构中使用的几种虚拟化技术,以确定这些技术是否适用于IA-64体系结构的虚拟化。

著录项

  • 作者

    Karadeniz Kadir.;

  • 作者单位
  • 年度 2001
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号