首页> 外国专利> Virtualization system with hypervisor embedded in bios or using extensible firmware interface

Virtualization system with hypervisor embedded in bios or using extensible firmware interface

机译:带有虚拟机监控程序的虚拟化系统,该虚拟化程序嵌入到BIOS中或使用可扩展的固件接口

摘要

A computer system includes a first portion of a Hypervisor is loaded into the memory as a part of an Extensible Firmware Interface upon start up and prior to loading of an operating system. The first portion is responsible for context switching, at least some interrupt handling, and memory protection fault handling. The first portion runs on a root level. An operating system is loaded into a highest privilege level. A second portion of the Hypervisor is loaded into operating system space together with the operating system, and runs on the highest privilege level, and is responsible for (a) servicing the VMM, (b) servicing the VMs, (c) enabling communication between code launched on non-root level with the second portion of the Hypervisor to perform security checks of trusted code portions and to enable root mode for the code portions if allowable. The VMM runs on the highest privilege level. A Virtual Machine is running under control of the VMM. Trusted code runs on non-root level. The first portion of the Hypervisor verifies trusted code portions during their loading or launch time, and the trusted code is executed on root level.
机译:包括系统管理程序的第一部分的计算机系统在启动时以及在加载操作系统之前作为可扩展固件接口的一部分被加载到存储器中。第一部分负责上下文切换,至少一些中断处理以及内存保护故障处理。第一部分在根级别上运行。操作系统已加载到最高特权级别。系统管理程序的第二部分与操作系统一起被加载到操作系统空间中,并以最高特权级别运行,并负责(a)服务VMM,(b)服务VM,(c)允许在使用Hypervisor的第二部分在非root用户级别启动的安全代码,以对受信任代码部分执行安全检查,并在允许的情况下为代码部分启用root模式。 VMM以最高特权级别运行。虚拟机在VMM的控制下运行。受信任的代码在非根级别上运行。系统管理程序的第一部分在加载或启动期间验证受信任的代码部分,然后在根级别执行受信任的代码。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号