IP Library Granted Patent US 12675566
Granted Patent B2
US 12675566 · App. 18/090,831 · Granted Jul 7, 2026

Secure virtualized performance monitoring counters

Inventors: David Kaplan (Austin, TX); Ruchir Dalal (Austin, TX)
Assignee: Advanced Micro Devices, Inc.
G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12675566
App. No.
18/090,831
Granted
Jul 7, 2026
Kind
B2
Abstract

A processing system includes a memory configured to store encrypted information representing state and control information for a guest virtual machine. The processing system further includes a processor configured to selectively reserve exclusive use of a set of performance monitoring counters by the guest virtual machine during execution of the guest virtual machine based on a state of a first control field accessed from the encrypted information for the guest virtual machine. The processor further is configured to permit or deny use of the set of performance monitoring counters by the guest virtual machine based on a state of a second control field set by a hypervisor and accessed from the decryption of the encrypted information for the guest virtual machine accessed from the memory.

Claims (58)

1 . A processing system comprising:

a memory configured to store encrypted information representing state and control information for a guest virtual machine; and

a processor configured to:

decrypt the encrypted information to access a first control field associated with the guest virtual machine; and

selectively reserve exclusive use of a set of performance monitoring counters by:

reserving exclusive use of the set of performance monitoring counters by the guest virtual machine during execution of the guest virtual machine responsive to the first control field having a first state; and

permitting exclusive use of the set of performance monitoring counters by a hypervisor during the execution of the guest virtual machine responsive to the first control field having a second state different than the first state.

2 . The processing system of claim 1 , wherein the guest virtual machine configures the state of the first control field prior to the execution of the guest virtual machine.

3 . The processing system of claim 1 , wherein the processor further is configured to:

encrypt information that includes the first control field to generate the encrypted information; and

store the encrypted information at the memory prior to the execution of the guest virtual machine.

4 . A processing system comprising:

a memory configured to store encrypted information representing state and control information for a guest virtual machine; and

a processor configured to:

decrypt the encrypted information to access a first control field and a second control field associated with the guest virtual machine;

selectively reserve exclusive use of a set of performance monitoring counters for the guest virtual machine based on the encrypted information; and

selectively permit use of the set of performance monitoring counters by the guest virtual machine based on a state of the second control field that is set by a hypervisor and is accessed from a decryption of the encrypted information for the guest virtual machine accessed from the memory.

5 . The processing system of claim 4 , wherein the processor further is configured to:

encrypt information that includes the first control field and the second control field to generate the encrypted information; and

store the encrypted information at the memory prior to an execution of the guest virtual machine.

6 . The processing system of claim 4 , wherein the processor is configured to disable use of the set of performance monitoring counters by either of the guest virtual machine and the hypervisor during execution of the guest virtual machine responsive to the state of the first control field indicating the guest virtual machine is requesting to reserve exclusive use of the set of performance monitoring counters and the state of the second control field indicating denial of use of the set of performance monitoring counters by the guest virtual machine.

7 . A method comprising:

accessing, from a memory, first encrypted information associated with a guest virtual machine at a processor; and

based on a state of a first control field of the first encrypted information, selectively reserving exclusive use of a set of performance monitoring counters by:

reserving exclusive use of the set of performance monitoring counters by the guest virtual machine during a first execution of the guest virtual machine responsive to the first control field having a first state; and

permitting exclusive use of the set of performance monitoring counters by a hypervisor during the first execution of the guest virtual machine responsive to the first control field having a second state different than the first state.

8 . The method of claim 7 , further comprising:

during a second execution of the guest virtual machine prior to the first execution, configuring the state of the first control field;

encrypting, at the processor, first state information associated with the guest virtual machine, including the state of the first control field, to generate the first encrypted information; and

storing the first encrypted information to the memory.

9 . The method of claim 8 , wherein:

the first state information includes a state of each of one or more performance monitoring counters of the set of performance monitoring counters at a suspension of the second execution; and

the method further includes:

decrypting the first encrypted information includes decrypting the first encrypted information to obtain the state of each of the one or more performance monitoring counters from the first state information at the processor; and

updating the one or more performance monitoring counters with a corresponding state obtained from the first encrypted information.

10 . The method of claim 8 , further comprising:

accessing, from the memory, second encrypted information associated with the guest virtual machine; and

wherein selectively reserving exclusive use of the set of performance monitoring counters by the guest virtual machine is further based on a state of a second control field accessed from the second encrypted information.

11 . The method of claim 10 , further comprising:

setting, by a hypervisor, a state of the second control field prior to the first execution.

12 . The method of claim 11 , wherein selectively reserving exclusive use of the set of performance monitoring counters by the guest virtual machine comprises:

reserving exclusive use of the set of performance monitoring counters by the guest virtual machine during the first execution responsive to the first control field having a first state and the second control field having a second state;

reserving exclusive use of the set of performance monitoring counters by the hypervisor during the first execution responsive to the first control field having a third state different than the first state; and

disabling use of the set of performance monitoring counters by either of the guest virtual machine and the hypervisor responsive to the first control field having the first state and the second control field having a fourth state different than the second state.

13 . A non-transitory computer-readable medium embodying a set of executable instructions, the set of executable instructions to manipulate at least one processor to:

access, from a memory, encrypted information associated with a guest virtual machine;

decrypt the encrypted information to access a first control field associated with the guest virtual machine; and

selectively reserve exclusive use of a set of performance monitoring counters by:

reserving exclusive use of the set of performance monitoring counters by the guest virtual machine during execution of the guest virtual machine responsive to the first control field having a first state; and

permitting exclusive use of the set of performance monitoring counters by a hypervisor during the execution of the guest virtual machine responsive to the first control field having a second state different than the first state.

14 . The non-transitory computer-readable medium of claim 13 , wherein the guest virtual machine is configured to configure a state of the first control field prior to the execution of the guest virtual machine.

15 . The non-transitory computer-readable medium of claim 14 , wherein the set of executable instructions further manipulate the at least one processor to:

encrypt information that includes the first control field to generate the encrypted information; and

store the encrypted information at the memory prior to the execution of the guest virtual machine.

16 . The non-transitory computer-readable medium of claim 13 , wherein the set of executable instructions manipulate the at least one processor to selectively permit use of the set of performance monitoring counters by the guest virtual machine based on a state of a second control field that is set by a hypervisor and is accessed from the decryption of the encrypted information for the guest virtual machine accessed from the memory.

17 . The non-transitory computer-readable medium of claim 16 , wherein the set of executable instructions further manipulate the at least one processor to:

encrypt information that includes the first control field and the second control field to generate the encrypted information; and

store the encrypted information at the memory prior to an execution of the guest virtual machine.