IP Library › Granted Patent US 8,627,456
Granted Patent B2
US 8,627,456 · App. 12/967,348 · Granted Jan 7, 2014

Methods and systems for preventing access to display graphics generated by a trusted virtual machine

Inventors: James McKenzie (Cambridge, GB); Jean Guyader (Cambridge, GB)
Assignee: Citrix Systems, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,627,456
App. No.
12/967,348
Filed
Dec 14, 2010
Granted
Jan 7, 2014
Kind
B2
Art Unit
2437
USPC
726/19
Abstract

The methods and systems provide for preventing a non-trusted virtual machine from reading the graphical output of a trusted virtual machine. A graphics manager receives a request from a trusted virtual machine to render graphical data using a graphics processing unit. The graphics manager assigns, to the trusted virtual machine, a secure section of a memory of the graphics processing unit. The graphics manager renders graphics from the trusted virtual machine graphical data to the secure section of the graphics processing unit memory. The graphics manager receives a request from a non-trusted virtual machine to read graphics rendered from the trusted virtual machine graphical data and stored in the secure section of the graphics processing unit memory, and prevents the non-trusted virtual machine from reading the trusted virtual machine rendered graphics stored in the secure section of the graphics processing unit memory.

Claims (42)

1. In a computing device executing a hypervisor hosting a trusted virtual machine and a non-trusted virtual machine, a method for preventing the non-trusted virtual machine from reading the graphical output of the trusted virtual machine, comprising:

receiving, by a graphics manager executed by a processor of the computing device, a first request from the trusted virtual machine executed by the computing device to render graphical data using a graphics processing unit of the computing device;

assigning, by the graphics manager to the trusted virtual machine, a secure section of a memory of the graphics processing unit;

rendering, by the graphics manager, graphics from the trusted virtual machine graphical data to the secure section of the graphics processing unit memory;

receiving, by the graphics manager, a second request from the non-trusted virtual machine executed by the computing device to read graphics rendered from the trusted virtual machine graphical data and stored in the secure section of the graphics processing unit memory;

preventing, by the graphics manager responsive to receiving the second request, the non- trusted virtual machine from reading the trusted virtual machine rendered graphics stored in the secure section of the graphics processing unit memory;

receiving, by the graphics manager, a third request from an application executing on the non-trusted virtual machine to render a second set of graphical data using the graphics processing unit, the application generating the second set of graphical data; and

rendering, by the graphics manager, graphics from the second set of graphical data to a section of the graphics processing unit memory not comprising the secure section of the graphics processing unit memory.

2. The method of claim 1 , wherein receiving the first request from a trusted virtual machine further comprises receiving, by the graphics manager, a fourth request generated by an application executing on the trusted virtual machine, the application generating the graphical data.

3. The method of claim 1 , wherein assigning the secure section of memory further comprises assigning a policy to a range of memory addresses.

4. The method of claim 1 , wherein preventing the non-trusted virtual machine from reading the secure section of the graphics processing unit memory further comprises:

identifying, by the graphics manager, a security credential of the non-trusted virtual machine; and

determining, by the graphics manager based on the security credential, the non-trusted virtual machine does not have permission to access the secure section of the graphics processing unit memory.

5. The method of claim 4 , wherein determining the non-trusted virtual machine does not have permission further comprises applying a policy of the secure section of the graphics processing unit memory to the security credential.

6. The method of claim 1 , wherein rendering graphics further comprises storing the rendered graphics to the secure section of the graphics processing unit memory.

7. The method of claim 1 , further comprising:

identifying, by the graphics manager, a security credential of the application executing on the non-trusted virtual machine;

determining, by the graphics manager based on the security credential, the non-trusted virtual machine does not have permission to access the secure section of the graphics processing unit memory; and

preventing, by the graphics manager, the graphics processing unit from rendering the graphics to the secure section of the graphics processing unit memory.

8. In a computing device executing a hypervisor hosting a trusted virtual machine and a non-trusted virtual machine, a system for preventing the non-trusted virtual machine from reading the graphical output of the trusted virtual machine, comprising:

the computing device comprising:

a processor executing a graphics manager and the hypervisor hosting the trusted virtual machine and the non-trusted virtual machine, and

a graphics processing unit, comprising a memory; and

wherein the graphics manager is configured to:

receive a first request from the trusted virtual machine to render graphical data using the graphics processing unit,

assign, to the trusted virtual machine, a secure section of the memory of the graphics processing unit,

render graphics from the trusted virtual machine graphical data to the secure section of the graphics processing unit memory,

receive a second request from the non-trusted virtual machine to read graphics rendered from the trusted virtual machine graphical data and stored in the secure section of the graphics processing unit memory,

prevent the non-trusted virtual machine from reading the trusted virtual machine rendered graphics stored in the secure section of the graphics processing unit memory, responsive to receiving the second request,

receive a third request from the application to render a second set of graphical data using the graphics processing unit, the application generating the second set of graphical data, and

render graphics from the second set of graphical data to a section of the graphics processing unit memory not comprising the secure section of the graphics processing unit memory.

9. The system of claim 8 , further comprising an application executing on the trusted virtual machine generating the graphical data, and wherein the graphics manager is further configured to receive a request generated by the application.

10. The system of claim 8 , wherein the graphics manager is further configured to assign a policy to a range of memory addresses.

11. The system of claim 8 , wherein the graphics manager is further configured to:

identify a security credential of the non-trusted virtual machine, and

determine, based on the security credential, the non-trusted virtual machine does not have permission to access the secure section of the graphics processing unit memory.

12. The system of claim 11 , wherein the graphics manager is further configured to apply a policy of the secure section of the graphics processing unit memory to the security credential.

13. The system of claim 8 , wherein the graphics manager is further configured to store the rendered graphics to the secure section of the graphics processing unit memory.

14. The system of claim 8 , wherein the graphics manager is further configured to:

identify a security credential of the application executing on the non-trusted virtual machine,

determine, based on the security credential, the non-trusted virtual machine does not have permission to access the secure section of the graphics processing unit memory, and

prevent the graphics processing unit from rendering the graphics to the secure section of the graphics processing unit memory.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2013
From: MCKENZIE, JAMES; GUYADER, JEAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 030392/0125 →
Continuity (8)
Provisional Application 61286263 · Dec 14, 2009
Provisional Application 61286266 · Dec 14, 2009
Provisional Application 61286215 · Dec 14, 2009
Provisional Application 61286216 · Dec 14, 2009
Provisional Application 61286218 · Dec 14, 2009
Provisional Application 61286636 · Dec 15, 2009
Provisional Application 61286619 · Dec 15, 2009
Related Publication 20110145916A1 · Jun 16, 2011