Thinkstock
Hypervisors Bring Greater Security to Arm Cortex-A

Hypervisors Step Up Security for Arm Cortex-A

Nov. 3, 2017
The Arm TechCon conference spotlighted some of the latest hypervisor advances targeting Arm Cortex-A platforms.

The 64-bit, Arm Cortex-A ARMv8 architecture supports virtual machines (VMs), but it requires hypervisor software to deliver this functionality. Hypervisors, which can provide isolation between VMs, typically support VMs that run operating systems or bare-metal applications.

Seen at this year’s Arm TechCon conference was Lynx Software’s LynxSecure Separation Kernel Hypervisor running on Xilinx’s latest Zynq UltraScale MPSoC, which has quad Arm Cortex-A53s and a pair of Cortex-Rs. The hypervisor runs on the Cortex-A53 complex and supports LynxSecure Applications (LSA). LSA.connect is an LSA that provides secure communication between domains (Fig. 1).

1. Lynx Software’s hypervisor offers isolation between VMs, while LSA.connect provides secure communication between domains.

The system can also utilize private memory communication links between VMs. This approach allows one VM to write data that’s read-only at the other end (Fig. 2). The LynxSecure Separation Kernel Hypervisor is a Type 0 hypervisor designed for safe and secure applications. Lynx Software provides certification artifacts and certification professional services to assist in security system evaluations.

Green Hills Software’s Integrity Multivisor takes advantage of virtualization hardware acceleration built into ARMv8-A architecture platforms as well as Intel Virtualization Technologies (Intel VT-x and VT-d) for both 32- and 64-bit processors.

Integrity Multivisor can also virtualize peripherals like GPUs. This allows multiple displays to support multiple windows associated with different VMs. A crashed or corrupted VM will only affect its own windows and not those of other VMs. Moreover, the system is able to guarantee resource usage so that critical tasks can continue to run even if other VMs want to use more time, memory, or GPU resources.

2. One-way private memory communication links between VMs can be implemented using shared memory, where one VM can write data that’s read-only at the other end.

Red Hat Enterprise Linux (RHEL) is well-known in the cloud and enterprise data centers, but the operating system has features that make it desirable for embedded applications like IoT gateways. It also includes KVM (kernel-based virtual machine) support. Like the other platforms, it supports ARMv8-A architectures as well as Intel Virtualization Technologies.

One of RHEL’s strengths is the VM management support. It’s very scalable, handling up to 288 logical CPUs and 12 TB of memory per host. Guest VMs can support up to 240 virtual CPUs and 6 TB of RAM. RHEL also handles SELinux and sVirt capabilities with mandatory access controls (MAC) for enhanced VM and hypervisor security.

These hypervisors support single-root I/O virtualization (SR-IOV). SR-IOV devices are typically network devices that allow host-level management and pass-through to VMs. This increases network throughput while decreasing latency and CPU overhead for near bare-metal performance.

Arm Cortex-A platforms are being asked to do more. Having secure, high-performance hypervisors allows them to address safety- and security-critical applications from self-driving cars and avionics to IoT infrastructure.

About the Author

William G. Wong | Senior Content Director - Electronic Design and Microwaves & RF

I am Editor of Electronic Design focusing on embedded, software, and systems. As Senior Content Director, I also manage Microwaves & RF and I work with a great team of editors to provide engineers, programmers, developers and technical managers with interesting and useful articles and videos on a regular basis. Check out our free newsletters to see the latest content.

You can send press releases for new products for possible coverage on the website. I am also interested in receiving contributed articles for publishing on our website. Use our template and send to me along with a signed release form. 

Check out my blog, AltEmbedded on Electronic Design, as well as his latest articles on this site that are listed below. 

You can visit my social media via these links:

I earned a Bachelor of Electrical Engineering at the Georgia Institute of Technology and a Masters in Computer Science from Rutgers University. I still do a bit of programming using everything from C and C++ to Rust and Ada/SPARK. I do a bit of PHP programming for Drupal websites. I have posted a few Drupal modules.  

I still get a hand on software and electronic hardware. Some of this can be found on our Kit Close-Up video series. You can also see me on many of our TechXchange Talk videos. I am interested in a range of projects from robotics to artificial intelligence. 

Sponsored Recommendations

Comments

To join the conversation, and become an exclusive member of Electronic Design, create an account today!