Analysis of the Intel Pentium's Ability to Support a Secure Virtual Machine Monitor
John S. Robin, Cynthia E. Irvine · 2000
A virtual machine monitor (VMM) allows multiple op-erating systems to run concurrently on virtual machines (VMs) on a single hardware platform. Each VM can be treated as an independent operating system platform. A secure VMM would enforce an overarching security policy on its VMs. The potential benefits of a secure VMM for PCs in-clude: a more secure environment, familiar COTS op-erating systems and applications, and enormous savings resulting from the elimination of the need for separate platforms when both high assurance policy enforcement, and COTS software are required. This paper addresses the problem of implementing se-cure VMMs on the Intel Pentium architecture. The re-quirements for various types of VMMs are reviewed. We report an analysis of the virtualizability of all of the ap-proximately 250 instructions of the Intel Pentium plat-form and address its ability to support a VMM. Cur-rent “virtualization ” techniques for the Intel Pentium ar-chitecture are examined and several security problems are identified. An approach to providing a virtualizable hardware base for a highly secure VMM is discussed. 1