IP Library Granted Patent US 9,069,591
Granted Patent B1
US 9,069,591 · App. 12/879,677 · Granted Jun 30, 2015

Patching host OS structures for hardware isolation of virtual machines

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,069,591
App. No.
12/879,677
Granted
Jun 30, 2015
Kind
B1
Abstract

A system and method for implementing direct attachment of VMs, implemented on a computer system, to hardware devices attached to the computer system. Direct attachment architecture is implemented. The direct attachment is an exclusive dedication of a hardware device to a VM, where a particular hardware device is assigned to a particular VM. When the VM is not activated, the hardware device can be re-assigned to another VM. At system start up, hardware devices are masked from a host OS of a computer system and are automatically attached to the assigned VMs.

Claims (46)

1. A method for assigning a dedicated hardware device to a Virtual Machine (VM), the method comprising:

implementing at least one VM with a guest OS, running under control of a Virtual Machine Monitor (VMM) on a computer system with a host operating system (OS);

isolating a hardware device from the host OS;

assigning the hardware device to the VM,

wherein the VM takes exclusive control of the hardware device by bypassing the VMM when interfacing with the hardware device;

the isolation of the hardware device comprising allocation of devices of the computer system so that the host OS operative access to the hardware device is essentially limited,

wherein the isolation of the hardware device is provided at boot time by a hypervisor (a) patching of BIOS of the computer system or (b) patching an EFI of the computer system, and

wherein the hardware device is visible to the host OS, but becomes inactive for the host OS.

2. The method of claim 1 , further comprising shutting down the VM to which the hardware device is dedicated, and making the hardware device visible to the host OS.

3. The method of claim 1 , wherein the hardware device is a plug-and-play device, and wherein the guest OS installs plug-and-play drivers for connecting the VM to the hardware device.

4. The method of claim 1 , wherein the access to hardware device for detection existence of the hardware device is allowed to the host OS.

5. A method for assigning a dedicated hardware device to a Virtual Machine (VM), the method comprising:

implementing at least one VM with a guest OS on a host OS of a computer system;

isolating a hardware device from the host OS;

assigning the hardware device to the VM,

wherein the VM takes exclusive control of the hardware device;

the isolation of the hardware device comprising allocation of devices of the computer system so that the host OS operative access to the hardware device is essentially limited,

wherein the isolation of the hardware device is provided by (a) patching of BIOS of the computer system or (b) patching an EFI of the computer system, and

wherein the hardware device is visible to the host OS, but becomes inactive for the host OS,

wherein, after the patching of the BIOS or the patching of the EFI, structures of the host operating system are patched, including a table of devices or a registry of the host operating system, thereby making the hardware device absent or inactive.

6. A virtualization system for allocating dedicated hardware devices, the system comprising:

a computer system having a host OS and a Virtual Machine Monitor (VMM);

at least one Virtual Machine (VM) implemented under control of the VMM;

at least one hardware device connected to the computer system,

wherein the hardware device is masked out from the host OS and the VM takes exclusive control of the hardware device at start up by bypassing the VMM when interfacing with the hardware device;

the hardware device is masked by allocation of address space of the computer system so that the host OS does not have access to an address of the hardware device,

wherein the masking of the hardware device is provided at boot time by a hypervisor (a) patching of BIOS of the computer system or (b) dynamically patching an EFI of the computer system.

7. A method for assigning a dedicated hardware device to a Virtual Machine (VM), the method comprising:

implementing at least one VM with a guest OS on a host OS of a computer system;

isolating a hardware device from the host OS;

assigning the hardware device to the VM,

wherein the VM takes exclusive control of the hardware device;

the isolation of the hardware device comprising allocation of the device's address space so that the host OS does not have access to the hardware device, including patching structures of the host operating system at boot time, including patching a table of devices or a registry of the host operating system, thereby making the hardware device absent or inactive to the host OS,

wherein the isolation of the hardware device is provided by a stopper driver which makes device non-accessible to the host OS processes.

8. The method of claim 7 , further comprising using a dedicated driver to make the hardware device inaccessible to the host OS.

9. The method of claim 8 , wherein, upon attempting to access the hardware device, the host OS receives a “busy” indication from the dedicated driver.

10. The method of claim 7 , wherein the exclusive control is given to the VM at start up.

11. The method of claim 7 , wherein the exclusive control is given to the VM on-the-fly, while both the host OS and the VM are running.

12. The method of claim 7 , wherein the isolation comprises masking the hardware device from the host OS.

13. A method for assigning a dedicated hardware device to a Virtual Machine (VM), the method comprising:

implementing at least one VM with a guest OS on a host OS of a computer system;

masking a hardware device from the host OS;

assigning the hardware device to the VM for direct access,

wherein the VM takes exclusive control of the hardware device at start up and bypasses access verification procedures enforced by the host OS;

the masking of the hardware device comprising allocation of address space of the computer system so that a device access procedure of the host OS is unaware of the hardware device,

wherein the hardware device is excluded from a list of visible devices used for mounting the devices at the host OS launch by boot-time patching structures of the host operating system, including patching a table of devices or a registry of the host operating system, thereby making the hardware device absent or inactive to the host OS.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jul 18, 2019
From: UBS AG, STAMFORD BRANCH, AS ADMINISTRATIVE AND COLLATERAL AGENT
To: COREL CORPORATION; CLEARSLIDE, INC.; PARALLELS INTERNATIONAL GMBH
Reel/Frame 049787/0073 →
RELEASE OF SECURITY INTEREST RECORDED AT : REEL 047973 FRAME 0797 Recorded Jul 17, 2019
From: UBS AG, STAMFORD BRANCH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 049773/0590 →
SECURITY INTEREST Recorded Dec 21, 2018
From: PARALLELS INTERNATIONAL GMBH
To: UBS AG, STAMFORD BRANCH
Reel/Frame 047973/0797 →
MERGER Recorded Jan 30, 2018
From: PARALLELS IP HOLDINGS GMBH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 045193/0679 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2012
From: PARALLELS HOLDINGS, LTD.
To: PARALLELS IP HOLDINGS GMBH
Reel/Frame 027916/0689 →